Your AI agents connect through MCP servers — endpoints exposing file access, database queries, internal APIs. Leave one reachable without auth and anyone can reach those tools. Your cloud sees this from inside; Flaw.co finds it from outside, like an attacker would, with just your domain.
It's part of a free passive scan across MCP/AI exposure, TLS, headers, exposed ports, and disclosure. Every finding maps to a PCI requirement. No account for your first scan. Free means free.