//Pricing
Finding out is free.
Every check runs on the free tier. You never have to pay to learn where you stand. Pro is for the work that follows.
Free
$0
forever
A full external scan of your live app, with every check we run.
- One free scan per website
- Every check runs, nothing is skipped
- Your worst finding in full, with proof and the fix
- Grade, severity counts and headline
- CWE, OWASP and CVSS on every finding
- Live-key verification status
no account · no card
Pro
$19 / mo
billed monthly
Everything in Free, plus the part that comes after finding out.
- Every finding in full, evidence and the exact fix
- Unlimited rescans, so you can confirm a fix worked
- Toxic combinations: how your findings compound
- Scan history across every project you own
- Markdown export for issues, docs and agents
- Connect your database for a live schema & RLS audit
- Scheduled rescans & drift alerts
- Git-history secret scan (flare-deep CLI)
- Private, password-protected reportssoon
Enterprise
Custom pricing.
For orgs scanning many apps, wiring Flare into CI at scale, or needing SSO and a contract. We price to the footprint, not a seat multiplier.
- Volume pricing across many apps and teams
- SSO, invoice billing and a named contact
- Custom SLAs, retention and data residency
- Priority support for CI and MCP rollouts
usually a same-week reply
If the free scan comes back clean, you don’t need Pro. That’s a good outcome, and we’d rather you reached it than paid us for reassurance.
Every difference, in full
| Feature | Free | Pro |
|---|---|---|
| // scanning | ||
| Scans per website | 1 | Unlimited |
| Rescan to confirm a fix | Not included | Included |
| Every detection runs | Included | Included |
| Scheduled rescans & drift alerts | Not included | Included |
| // results | ||
| Grade, headline and severity counts | Included | Included |
| CWE · OWASP · CVSS on every finding | Included | Included |
| Live-key verification status | Included | Included |
| Findings shown in full | Worst one | All |
| Evidence and fix for every finding | Not included | Included |
| Toxic-combination analysis | Count only | Included |
| // detection | ||
| Secrets in client bundles | Included | Included |
| Live-key verification | Included | Included |
| Server-to-client (RSC) leaks | Included | Included |
| NEXT_PUBLIC_ secret detection | Included | Included |
| Shadow API routes | Included | Included |
| Tokens in URLs | Included | Included |
| Supabase & Firebase exposure | Included | Included |
| Security headers, CORS & cookies | Included | Included |
| Exposed .env / .git / backups | Included | Included |
| SPF & DMARC | Included | Included |
| Per-table RLS & policy audit (live schema) | Not included | Included |
| Migration-history review | Included | Included |
| Git-history secret scan (flare-deep CLI) | Included | Included |
| Dependency CVE lookup (OSV) | Included | Included |
| // workflow | ||
| JSON API | Included | Included |
| MCP server (Cursor, Claude Code, Windsurf) | Included | Included |
| Markdown export | Not included | Included |
| Scan history & dashboard | Not included | Included |
| Private, password-protected reports | Not included | Planned |
| CLI & GitHub Action (runs locally) | Included | Included |
| Fail the build on critical findings | Included | Included |
Questions
What does “one free scan per website” mean?+
You can scan any number of different websites for free, once each. Rescanning the same site after a fix is a Pro feature, because that fix-and-confirm loop is the part teams use day to day.
Is the free tier limited in what it detects?+
No. Every external check runs on free, including live-key verification, you see your grade, every severity count, and your worst finding in full. Pro adds the evidence and fix for the rest, the compound-risk analysis, unlimited rescans, history and Markdown export. Connected scanning of your live database (per-table RLS & policy audit) is available today; full git-history secret scanning is still on the roadmap and marked as such above.
Do I need an account to scan?+
No. Paste a public URL and you get a report, no login, no repo access, no card. An account only matters once you want scan history and rescans.
How does billing work?+
Monthly, on a card, through Stripe Checkout, so we never see or store your card details. Cancel any time from the billing portal, and you keep Pro until the end of the period you’ve paid for.
Can I use it on client work?+
Yes, on apps you own or are authorised to test. Every check is read-only, but permission is about intent, not just impact.
Not sure yet? Run your free scan and decide with a real report in front of you.