Your AI agents connect through MCP servers — endpoints exposing file access, database queries, internal APIs. Leave one reachable without auth and anyone can reach those tools. Your cloud sees this from inside; Flaw.co finds it from outside, like an attacker would, with just your domain. It's part of a free passive scan across MCP/AI exposure, TLS, headers, exposed ports, and disclosure. Every finding maps to a PCI requirement. No account for your first scan. Free means free.
No reviews yetBe the first to leave a review for flaw.co
Maker
📌
We run payments-security certifications for a living, and over and over we wanted a quick outside-in read on a domain before doing the deep work — is the TLS sane, are the headers there, is anything exposed that shouldn't be. Nothing free did it well.
And nothing checked the thing that started keeping us up at night: exposed MCP endpoints. Once everyone started wiring AI agents into their infrastructure, that became real attack surface — and it's invisible from the runtime platforms most teams rely on, because it only shows from the outside. So we built the scanner we wanted.
The passive scan is free and stays free. No account to run your first one, real findings written out in full, and every finding mapped to the PCI requirement it touches — not a letter grade and a shrug.
Would genuinely love the hard feedback. If it misses something on your domain, or flags something it shouldn't, tell us — that's the stuff we most want to hear on launch day.