Straight answers, with proof.
What Fleuret tests, what it costs, how it stays safe in production, and what it does for DORA and NIS2. Every answer links to the page or the regulation behind it.
Written by Augustin Ponsin, Co-founder & CTO · Reviewed by Salomé Bourrouilh, Offensive Security Engineer ·
Product
What is Fleuret?
Fleuret is an offensive security platform. It combines AI agents with human offensive expertise to deliver pentests with the depth of a manual engagement in hours, where a traditional pentest firm takes two to four weeks.
It tests web applications, their REST and GraphQL APIs and the external infrastructure behind them. Every finding ships with a proof of concept you can replay.
VerifyHow the platform works
Who is Fleuret built for?
European companies of 50 to 1,000 people with a real web and API attack surface (SaaS, fintech, healthtech) and a compliance deadline: NIS2, DORA, a first SOC 2 or ISO 27001.
The typical buyer is a CISO, head of security or CTO who needs audit-ready proof, fast, without a four-week consulting engagement.
VerifyBook a scoping call
How is this different from a vulnerability scanner?
A scanner matches signatures and reports what might be vulnerable. Fleuret executes each step of an attack and reports what it actually exploited.
Every finding comes with a proof you can replay yourself. That is why a Fleuret report carries fewer false positives than a scanner export, and why it is usually shorter.
VerifyPlatform principles
Who, or what, is Émile?
Émile supervises every engagement. It maps your app and API the way an attacker would, then dispatches specialist agents (authentication, access control, injection, business logic, privilege escalation) that each run one mission and are retired afterwards.
A separate validator turns a suspicion into a confirmed finding through a controlled, non-destructive challenge. The orchestration itself is deterministic code, not a free-running model.
VerifyArchitecture
What can you test today, and what can't you?
Today: web applications, REST and GraphQL APIs, and external infrastructure.
Not yet: Active Directory, mobile applications and cloud pentests are on the roadmap. If your audit needs them this quarter, say so on the first call and you will get a straight answer on whether we can cover it.
VerifyPlatform scope
How long does an engagement take?
Setup takes minutes: the target, test accounts for each role and the rules of engagement. Reconnaissance and testing run in hours, so the first confirmed findings arrive the same day.
Complex business logic and multi-step attack chains are part of the same engagement. They are not sold as an upgrade.
VerifyEngagement timeline
Method & safety
Is it safe to test our production environment?
Yes, by design. Proofs of concept are read-only and non-destructive: the validator demonstrates access (for example, reading one record across a tenant boundary) without writing, deleting or degrading anything.
Every request is traced and the trace ships with the report, so your team can see exactly what was sent and when. If you prefer, we test a staging environment that mirrors production.
VerifyValidation model
What do you need from us to start?
Three things: the scope (URLs, and an API specification if you have one), test accounts for each role you want tested, and a signed authorisation that defines what is in and out of scope and the testing window.
We never test a system without written authorisation from its owner. That is a legal requirement, not a formality.
VerifyBook a scoping call
What exactly is in the report?
Each finding reads as a ticket, not a paragraph: the exact request, the affected path, a severity you can defend, a replayable proof of concept and a remediation. The one-off pentest includes a PDF report mapped to DORA and NIS2.
On Enterprise, the audit PDF is signed and a board-deck export is added. On Platform and Enterprise, findings also open as Jira tickets.
VerifyPricing
Do you re-test after we fix?
Yes. A re-test once your fixes ship is included in the one-off pentest, and the report is updated with the new status of each finding.
VerifyPricing
Pricing
How much does a pentest cost?
€4,000 per web application, flat. That covers the app, its REST or GraphQL API and the external infrastructure behind it, business logic and multi-step chains, replayable proofs of concept, the DORA and NIS2 report and a re-test once your fixes ship.
For comparison, a consulting firm typically quotes €15,000–€30,000 for the same surface.
Scanners on your code are the Platform plan, free to start, then €200 a month per organization. Plans and billing are in the pricing section. Scope your app with an engineer
VerifyPricing
Why does a complex scope cost the same as a simple one?
Deliberately. A flat price removes the scoping negotiation that usually delays a pentest by weeks. Most of the work is compute plus a bounded amount of expert time, so complexity is absorbed rather than billed.
The unit is the web application, not the day and not the number of findings.
VerifyPricing
What does Enterprise add?
Enterprise is priced on quote, per web app per year. It includes everything in Platform, plus a quota of pentests per web app that you launch whenever you want, several web apps under one contract, the signed DORA and NIS2 audit PDF, a board-deck export, a dedicated customer success manager, and invoicing with a custom DPA and procurement.
Moving to Enterprise within 6 months of a one-off pentest? That first pentest is credited in full. Scope your app with an engineer
VerifyPricing
Compliance
Does a Fleuret pentest satisfy DORA?
DORA (Regulation (EU) 2022/2554 (opens external site)) requires financial entities to run a digital operational resilience testing programme (Articles 24 and 25), which explicitly includes penetration tests. The report is mapped to that requirement.
What we do not claim: threat-led penetration testing (TLPT, Article 26) is a separate exercise for significant entities, run under the TIBER-EU (opens external site) framework with its own threat intelligence and red team requirements. A Fleuret pentest does not replace a TLPT.
And NIS2?
NIS2 (Directive (EU) 2022/2555 (opens external site)) Article 21(2)(f) requires policies and procedures to assess the effectiveness of your cybersecurity risk-management measures. A dated pentest report is direct evidence for that obligation.
National transpositions differ in detail: the report maps to the directive, and your auditor maps it to the national text.
Does it work for ISO 27001 or SOC 2?
Yes. For ISO 27001:2022 the report supports Annex A controls 8.8 (management of technical vulnerabilities) and 8.29 (security testing in development and acceptance). For SOC 2 it is evidence for the monitoring and vulnerability management criteria.
The report is evidence, not a certificate: your auditor decides what it proves. If you are budgeting a first certification, the compliance cost calculator separates the platform, audit and pentest lines.
What we will not claim
- A Fleuret pentest does not replace a DORA threat-led penetration test (TLPT) under TIBER-EU.
- The report is audit evidence, not a certification. Your auditor decides what it proves.
- Cassini, the free exposure check, is not a pentest. A clean result means a clean facade, nothing more.
- Active Directory, mobile and cloud pentests are not available yet.
Data & security
Where is our data hosted?
Findings, reports and workspace data are hosted by Scaleway in Paris: a European provider, not the EU region of a US hyperscaler.
Every sub-processor, what it handles and where, is listed on the sub-processors page.
VerifySub-processors
Is our data sent to OpenAI or another US model provider?
No. The models are open-weight (gpt-oss, Kimi K2.5) and run on H100 GPUs at Scaleway in Paris. Engagement data does not leave that environment to reach a third-party model API.
How long do you keep engagement data?
Vulnerabilities, exploitation evidence and reports are kept for 18 months in a European environment segmented per client, then deleted. You have full access throughout and can request early deletion at any time.
VerifySecurity policy
How do you protect our data?
TLS 1.2 or higher in transit with HSTS on every domain, AES-256 at rest with regular key rotation, least-privilege access to production with mandatory multi-factor authentication, and strict isolation between clients.
In case of a personal data breach, we notify the CNIL within 72 hours, in line with Articles 33 and 34 of the GDPR.
VerifySecurity policy
We found a vulnerability in Fleuret. What do we do?
Write to security@fleuret.ai with reproduction steps and impact. We acknowledge within 48 business hours and respond within 5 business days. We will not pursue researchers acting in good faith under responsible disclosure.
VerifyDisclosure policy
Company
Who is behind Fleuret?
FLEURET AI is a French SAS headquartered in Paris, founded by Yanis Grigy (CEO) and Augustin Ponsin (CTO). The team includes AI engineers and offensive security engineers.
The team and its backers are on the about page.
VerifyAbout·Legal notice
Company facts
- Legal name
- FLEURET AI SAS
- SIREN
- 999 515 604
- Registered office
- 60 Rue François 1er, 75008 Paris
- Security contact
- security@fleuret.ai
- Data hosting
- Scaleway, Paris
Change log
Every change to this page is dated below.
- Page published, checked against the live pricing, security policy and sub-processor list.
- Pricing moved to three plans: Platform, Pentest one-off and Enterprise.
- The Advanced Pentest tier was retired. Its scope is part of the one-off pentest.
Still a question? Ask an engineer.
Thirty minutes with the team that runs the engagements. We scope your app and tell you what a pentest would cover.