Pricing

Start free. Go deep when you need to.

Every plan includes the full passive external scan. Upgrade for the active deep scan, unlimited runs, and continuous monitoring — or buy a single deep scan for one domain.

Free
$0
always free
Detect Single Deep Scan
$19.99
one-time, one domain
Code
$15
per month, up to 5 users
QA Basic
$10
per month, up to 25 URL sessions
Compare Detect plans
Free
Detect
Single scan
Passive external scan (TLS, headers, exposed services, disclosure)
Security grade + category scores
Full findings, unredacted
Scans per month
5
Unlimited
1 scan
Scan history retention
90 days
Indefinite
90 days
Deep gated scan — active testing (verified domains only)
Scheduled monitoring (weekly → semiannual)
Change alerts — emailed only when something changes
Grade-over-time trend
Branded PDF report
Team seats
1
1
1
Compare Code plans
Code
Detect + Code
Security review on every pull request
Secrets, injection, auth/session & dependency CVE checks
GitHub App integration
External domain scanning (TLS, headers, exposure, disclosure, MCP)
PCI readiness grade & letter score
Continuous monitoring & change-only alerts
Compare QA plans
QA Basic
QA Pro
URL sessions per month
25
125
Autonomous exploration (broken flows, console errors, network failures)
Screenshot evidence on every finding
Generated Playwright script per run
roomwork.co alerts

Prices in USD. Detect is billed monthly; the single deep scan is a one-time charge for one domain. Code is billed monthly, flat per organization for up to 5 users. QA is billed monthly, metered by URL sessions per month. All plans include the passive external scan at no cost. The deep scan adds active checks — CVE, exposure, and misconfiguration testing — and runs only on domains you have verified you control. A flaw.co security service by Paying.co.

flaw.co
Security, inside and out