//Pricing

Finding out is free.

Every check runs on the free tier. You never pay to learn where you stand. Pro is ongoing monitoring: rescans after every fix, 15-minute drift detection, and evidence for every finding.

Free

$0

forever

A full external scan of your live app, with every check we run.

  • One free scan per website
  • One saved site, delete it to scan another
  • Every check runs, nothing is skipped
  • Your worst finding in full, with proof and the fix
  • Titles for every other finding, you know what is wrong
  • Toxic combination count (path detail is Pro)
  • Grade, severity counts and headline
  • Industry-standard risk ratings on every finding
  • See which leaked keys still work (on the worst finding)
Run your free scan

no account · no card

Pro

$49 / mo

billed monthly

Everything in Free, plus the part that comes after finding out.

  • Every finding in full, evidence and the exact fix
  • Unlimited rescans, so you can confirm a fix worked
  • Toxic combinations: how small issues add up to a big one
  • Scan history across up to 10 sites
  • Up to 10 connected repos and databases
  • Per-project security checklist
  • Export your report to share or hand to an AI
  • Connect your database to check who can read your data
  • Connect GitHub or GitLab for continuous repo audits
  • Flare Guard firewall on your verified sites
  • Automatic re-checks every 15 minutes on your tracked sites
  • Drift alerts to Slack or PagerDuty when configured
  • Connected git-history secret scan (also free via flare-deep locally)
  • Private, password-protected reportssoon
Sign in to upgrade

free account · takes 20 seconds

Enterprise

Custom pricing.

For orgs scanning many apps or wiring Flare into CI at scale. We price to the footprint, not a seat multiplier.

  • Volume pricing across many apps and teams
  • Invoice billing and a named contact
  • Help wiring CI, MCP, and the scan API
Talk to us

usually a same-week reply

If the free scan comes back clean, you don’t need Pro. That’s a good outcome, and we’d rather you reached it than paid us for reassurance.

Every difference, in full

FeatureFreePro
// scanning
Scans per website1Unlimited
Projects tracked at once110
Rescan to confirm a fixNot includedIncluded
Every detection runsIncludedIncluded
Scheduled rescans & drift alertsNot includedIncluded
// results
Grade, headline and severity countsIncludedIncluded
CWE · OWASP · CVSS on every findingIncludedIncluded
Live-key verification statusOn the worst findingEvery key
Finding titles (what is wrong)IncludedIncluded
Findings shown in fullWorst oneAll
Evidence and fix for every findingNot includedIncluded
Toxic-combination analysisCount onlyIncluded
// detection
Secrets in client bundlesIncludedIncluded
Live-key verificationIncludedIncluded
Server-to-client (RSC) leaksIncludedIncluded
NEXT_PUBLIC_ secret detectionIncludedIncluded
Shadow API routesIncludedIncluded
Tokens in URLsIncludedIncluded
Supabase & Firebase exposureIncludedIncluded
Security headers, CORS & cookiesIncludedIncluded
Exposed .env / .git / backupsIncludedIncluded
SPF & DMARCIncludedIncluded
Per-table RLS & policy audit (live schema)Not includedIncluded
Migration-history reviewCLICLI + Connect
Git-history secret scanCLICLI + Connect
Dependency CVE lookup (OSV)CLICLI + Connect
Connected GitHub / GitLab reposNot includedUp to 10
Flare Guard firewallNot includedIncluded
// workflow
JSON APIIncludedIncluded
MCP server (Cursor, Claude Code, Windsurf)IncludedIncluded
Markdown exportNot includedIncluded
Scan history & dashboardNot includedIncluded
Per-project security checklistNot includedIncluded
Private, password-protected reportsNot includedPlanned
CLI & GitHub Action (runs locally)IncludedIncluded
Fail the build on critical findingsIncludedIncluded

Questions

What does “one free scan per website” mean?+

Without an account you get one free scan per website (per network). Signed in on free, each site you scan is saved as a project and you get one project at a time, delete it to scan a different site, or go Pro for up to 10. Rescanning the same site after a fix (to confirm it worked) is Pro, because that fix-and-confirm loop is what teams use day to day.

Is the free tier limited in what it detects?+

No. Every external URL check runs on free, including live-key verification. You see your grade, severity counts, titles for every finding, and your worst finding in full with proof and the fix. Pro opens evidence and fixes for the rest, toxic-combination paths, unlimited rescans, history, Markdown export, and connected GitHub/GitLab or database audits. Repo checks also ship in the free flare-deep CLI on your machine if you prefer to run them locally.

Do I need an account to scan?+

No. Paste a public URL and you get a report, no login, no repo access, no card. An account only matters once you want scan history and rescans.

How does billing work?+

Monthly, on a card, through Stripe Checkout, so we never see or store your card details. Cancel any time from the billing portal, and you keep Pro until the end of the period you’ve paid for.

Can I use it on client work?+

Yes, on apps you own or are authorised to test. Every check is read-only, but permission is about intent, not just impact.

read-only checksno repo accesscancel any time

Not sure yet? Run your free scan and decide with a real report in front of you.

Terms · Privacy