• Agents
  • Docs
  • Pricing
  • Blog
Log in
Get started

Security for apps built with AI. Paste a URL, get a report, fix what matters.

Product

  • How it works
  • What we find
  • Pricing
  • Agents
  • MCP Server
  • CLI
  • GitHub Action

Resources

  • Blog
  • Docs
  • FAQ
  • Glossary

Security

  • Supabase Security
  • Next.js Security
  • Lovable Security
  • Cursor Security
  • Bolt Security

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Imprint
© 2026 Flowpatrol. All rights reserved.
Pricing

Probe for free.
Scan when you're ready.

Start with free security probes. Upgrade to Builder for $19/mo to unlock full scans with auth testing, access control checks, and detailed fix guidance.

Prices shown are billed annually.

Free

$0forever

See what's exposed. Zero commitment.

3 security probes per month
1 scan target
Vulnerability summary
Fix guidance for top issues
Try it free
Most Popular

Builder

$19/mo

$25/mo if billed monthly

Full security scans for builders shipping to real users.

30 credits per month
5 scan targets
All scan modes (Probe, Standard, Deep)
Auth & IDOR testing
Screenshot evidence
Detailed vulnerability reports
3 team members
API access
Get started

Pro

$49/mo

$65/mo if billed monthly

For teams and agentic pipelines that scan often.

120 credits per month
20 scan targets
Everything in Builder
10 team members
Full API access
Priority support
Get started

Enterprise

Custom

For teams and agencies shipping at scale.

Unlimited credits
Unlimited scan targets
Unlimited team members
SSO / SAML
Audit log
Priority scan queue
Dedicated support
Talk to us

Simple, fixed credit costs

You always know what a scan costs before you click. No variable pricing, no surprises.

Probe~2 min
1credit

Headers, secrets, fingerprints, exposed paths, Supabase RLS

Standard Scan~15 min
5credits

Auth testing, IDOR, injection, XSS, screenshot evidence

Deep Scan~30 min
8credits

Multi-user IDOR, chained attacks, aggressive mode

Need more credits?

Running out mid-month? Top up instantly. One-time purchase, available immediately, valid through the end of your billing period.

10 credits

$0.50 per credit

$5

one-time

Buy in multiples of 10, up to 60 at a time

Builder & Pro

Feature Comparison

Scroll for more →

FeatureFreeBuilderProEnterprise
Monthly allowance3 probes30 credits120 creditsUnlimited
All scan modes (Probe, Standard, Deep)—
Scan targets1520Unlimited
Team members1310Unlimited
Auth & IDOR testing—
Screenshot evidence—
Detailed vulnerability reports—
API access—
Priority support——
SSO / SAML———
Audit log———
Priority scan queue———

Frequently Asked Questions

Do I need to know about security?

Not at all. Flowpatrol is built for builders, not security engineers. Every finding comes with a plain-English explanation and a fix you can copy-paste into your AI coding tool.

What are the three scan modes?

Probe (1 credit) does a surface-level check — headers, secrets, fingerprints, and Supabase RLS gaps. Standard (5 credits) logs in as a test user and tests auth flows, IDOR, injection, and takes screenshot evidence. Deep (8 credits) runs multi-user IDOR testing, chained attacks, and has an optional aggressive mode.

What can Flowpatrol scan?

Anything you can reach in a browser. SPAs, server-rendered apps, REST APIs — if it's live on the web, we can test it. Works with any stack, any framework.

How do credits work?

Credits are included with your Builder or Pro plan. Each scan costs a fixed number of credits depending on the mode: Probes cost 1 credit, Standard scans cost 5, and Deep scans cost 8. All paid plans get the same capabilities — the difference is how many credits you get each month. If you run out mid-month, you can buy extra credits as a one-time top-up starting at $5 for 10 credits. You always know the cost before you click.

Can I change plans later?

Anytime. Upgrade, downgrade, or cancel — changes take effect at the start of your next billing cycle. No lock-in.

Is my data safe with you?

Flowpatrol never touches your codebase. No repo access, no GitHub integration, no source code upload — we only interact with your live, deployed URL. All scan data is encrypted at rest and in transit, and we use Row-Level Security to keep every organization's data completely isolated.