Find, Prove, and Fix.
Fleuret runs pentests on your web apps and APIs with agentic AI. €4,000 instead of €15,000–€30,000. Audit-ready for your compliance.

A pentest that ends with evidence, not a PDF of maybes.
vs €15,000–€30,000 for a firm
every finding ships a PoC
Findings hosted on Scaleway, Paris. A European provider, not a US hyperscaler's EU region.
The report is the platform
Findings you can assign, fix and re-test. Not a 60-page PDF.
A traditional pentest ends with a document. Fleuret ends with a workspace: every finding is a ticket with a replayable PoC, an owner and a remediation. Push it to Jira, Linear or Slack, patch it, re-test in one click. The signed audit PDF is generated on demand.
- Replayable PoC on every finding
- Synced to your tooling: Jira, Linear, Slack
- Signed export, mapped to your framework
From first request to signed report.
Find
Émile maps your app and API the way an attacker would, then chains what it finds. Every step is executed, never inferred from a scanner signature.
- 142 routes mapped
- IDOR → export
- JWT → admin
Prove
Every finding carries a replayable PoC and a severity you can defend. If it is in the report, it was exploited.
- 0 false positives
- Ed25519-signed PDF
- DORA / NIS2 mapping
Fix
Each finding lands as a ticket, not a paragraph: the exact request, the affected path, a remediation.
- Jira · Linear · Slack
- 1-click re-test
- fix history exported
The depth of a firm. The speed of a scanner.
Deep, but slow and expensive.
- Cost€15,000–€30,000
- Time to report2–4 weeks
- False positivesrare
- Depthdeep
Both. On every release.
- Cost€4,000
- Time to reporthours
- False positiveszero, PoC on every finding
- Depthdeep
Fast, but shallow and noisy.
- Costcheap, noisy
- Time to reportminutes
- False positivesmany
- Depthshallow
Transparent pentest pricing
A pentest on demand, or continuous coverage when you are ready.
Pentest
The depth of a 2-week manual pentest, delivered in hours.
For an application with a simple scope.
- Reproducible PoC, zero false positives
- DORA / NIS2 PDF report
- Delivered in hours, not weeks
Advanced Pentest
The depth of a 4-week manual pentest, delivered in hours.
Complex apps: business logic, authentication, large scope.
- Everything in Pentest, extended scope
- REST / GraphQL APIs + external infra
- Multi-step exploitation chains
Continuous
Automated rescan, unlimited surfaces.
Pentest becomes a habit, not a once-a-year event.
- Weekly automated rescan
- Jira tickets with re-test link
- Signed DORA / NIS2 audit PDF
- Board-deck export for quarterly review
- Dedicated CSM
€4,000 against €15,000 to €30,000 for a consulting firm. Your first test is credited if you go continuous.
0 findings, 0 invoice.
If Fleuret finds nothing exploitable on your first test, you pay nothing.
Are you a GRC platform or a pentest marketplace?
Fleuret resells under your brand. Clear channel margins.
Become a partner →Run your first pentest this week.
15 minutes with the team. We scope it on your real perimeter.
