//Pricing
Finding out is free.
Every check runs on the free tier. You never pay to learn where you stand. Pro is ongoing monitoring: rescans after every fix, 15-minute drift detection, and evidence for every finding.
Free
$0
forever
A full external scan of your live app, with every check we run.
- One free scan per website
- One saved site, delete it to scan another
- Every check runs, nothing is skipped
- Your worst finding in full, with proof and the fix
- Titles for every other finding, you know what is wrong
- Toxic combination count (path detail is Pro)
- Grade, severity counts and headline
- Industry-standard risk ratings on every finding
- See which leaked keys still work (on the worst finding)
no account · no card
Pro
$49 / mo
billed monthly
Everything in Free, plus the part that comes after finding out.
- Every finding in full, evidence and the exact fix
- Unlimited rescans, so you can confirm a fix worked
- Toxic combinations: how small issues add up to a big one
- Scan history across up to 10 sites
- Up to 10 connected repos and databases
- Per-project security checklist
- Export your report to share or hand to an AI
- Connect your database to check who can read your data
- Connect GitHub or GitLab for continuous repo audits
- Flare Guard firewall on your verified sites
- Automatic re-checks every 15 minutes on your tracked sites
- Drift alerts to Slack or PagerDuty when configured
- Connected git-history secret scan (also free via flare-deep locally)
- Private, password-protected reportssoon
Enterprise
Custom pricing.
For orgs scanning many apps or wiring Flare into CI at scale. We price to the footprint, not a seat multiplier.
- Volume pricing across many apps and teams
- Invoice billing and a named contact
- Help wiring CI, MCP, and the scan API
usually a same-week reply
If the free scan comes back clean, you don’t need Pro. That’s a good outcome, and we’d rather you reached it than paid us for reassurance.
Every difference, in full
| Feature | Free | Pro |
|---|---|---|
| // scanning | ||
| Scans per website | 1 | Unlimited |
| Projects tracked at once | 1 | 10 |
| Rescan to confirm a fix | Not included | Included |
| Every detection runs | Included | Included |
| Scheduled rescans & drift alerts | Not included | Included |
| // results | ||
| Grade, headline and severity counts | Included | Included |
| CWE · OWASP · CVSS on every finding | Included | Included |
| Live-key verification status | On the worst finding | Every key |
| Finding titles (what is wrong) | Included | Included |
| Findings shown in full | Worst one | All |
| Evidence and fix for every finding | Not included | Included |
| Toxic-combination analysis | Count only | Included |
| // detection | ||
| Secrets in client bundles | Included | Included |
| Live-key verification | Included | Included |
| Server-to-client (RSC) leaks | Included | Included |
| NEXT_PUBLIC_ secret detection | Included | Included |
| Shadow API routes | Included | Included |
| Tokens in URLs | Included | Included |
| Supabase & Firebase exposure | Included | Included |
| Security headers, CORS & cookies | Included | Included |
| Exposed .env / .git / backups | Included | Included |
| SPF & DMARC | Included | Included |
| Per-table RLS & policy audit (live schema) | Not included | Included |
| Migration-history review | CLI | CLI + Connect |
| Git-history secret scan | CLI | CLI + Connect |
| Dependency CVE lookup (OSV) | CLI | CLI + Connect |
| Connected GitHub / GitLab repos | Not included | Up to 10 |
| Flare Guard firewall | Not included | Included |
| // workflow | ||
| JSON API | Included | Included |
| MCP server (Cursor, Claude Code, Windsurf) | Included | Included |
| Markdown export | Not included | Included |
| Scan history & dashboard | Not included | Included |
| Per-project security checklist | Not included | Included |
| Private, password-protected reports | Not included | Planned |
| CLI & GitHub Action (runs locally) | Included | Included |
| Fail the build on critical findings | Included | Included |
Questions
What does “one free scan per website” mean?+
Without an account you get one free scan per website (per network). Signed in on free, each site you scan is saved as a project and you get one project at a time, delete it to scan a different site, or go Pro for up to 10. Rescanning the same site after a fix (to confirm it worked) is Pro, because that fix-and-confirm loop is what teams use day to day.
Is the free tier limited in what it detects?+
No. Every external URL check runs on free, including live-key verification. You see your grade, severity counts, titles for every finding, and your worst finding in full with proof and the fix. Pro opens evidence and fixes for the rest, toxic-combination paths, unlimited rescans, history, Markdown export, and connected GitHub/GitLab or database audits. Repo checks also ship in the free flare-deep CLI on your machine if you prefer to run them locally.
Do I need an account to scan?+
No. Paste a public URL and you get a report, no login, no repo access, no card. An account only matters once you want scan history and rescans.
How does billing work?+
Monthly, on a card, through Stripe Checkout, so we never see or store your card details. Cancel any time from the billing portal, and you keep Pro until the end of the period you’ve paid for.
Can I use it on client work?+
Yes, on apps you own or are authorised to test. Every check is read-only, but permission is about intent, not just impact.
Not sure yet? Run your free scan and decide with a real report in front of you.