Skip to main content
FAQ · 22 QUESTIONS

Straight answers, with proof.

What Fleuret tests, what it costs, how it stays safe in production, and what it does for DORA and NIS2. Every answer links to the page or the regulation behind it.

Written by Augustin Ponsin, Co-founder & CTO · Reviewed by Salomé Bourrouilh, Offensive Security Engineer ·

01 · 6 QUESTIONS

Product

What is Fleuret?

Fleuret is an offensive security platform. It combines AI agents with human offensive expertise to deliver pentests with the depth of a manual engagement in hours, where a traditional pentest firm takes two to four weeks.

It tests web applications, their REST and GraphQL APIs and the external infrastructure behind them. Every finding ships with a proof of concept you can replay.

VerifyHow the platform works

Who is Fleuret built for?

European companies of 50 to 1,000 people with a real web and API attack surface (SaaS, fintech, healthtech) and a compliance deadline: NIS2, DORA, a first SOC 2 or ISO 27001.

The typical buyer is a CISO, head of security or CTO who needs audit-ready proof, fast, without a four-week consulting engagement.

VerifyBook a scoping call

How is this different from a vulnerability scanner?

A scanner matches signatures and reports what might be vulnerable. Fleuret executes each step of an attack and reports what it actually exploited.

Every finding comes with a proof you can replay yourself. That is why a Fleuret report carries fewer false positives than a scanner export, and why it is usually shorter.

VerifyPlatform principles

Who, or what, is Émile?

Émile supervises every engagement. It maps your app and API the way an attacker would, then dispatches specialist agents (authentication, access control, injection, business logic, privilege escalation) that each run one mission and are retired afterwards.

A separate validator turns a suspicion into a confirmed finding through a controlled, non-destructive challenge. The orchestration itself is deterministic code, not a free-running model.

VerifyArchitecture

What can you test today, and what can't you?

Today: web applications, REST and GraphQL APIs, and external infrastructure.

Not yet: Active Directory, mobile applications and cloud pentests are on the roadmap. If your audit needs them this quarter, say so on the first call and you will get a straight answer on whether we can cover it.

VerifyPlatform scope

How long does an engagement take?

Setup takes minutes: the target, test accounts for each role and the rules of engagement. Reconnaissance and testing run in hours, so the first confirmed findings arrive the same day.

Complex business logic and multi-step attack chains are part of the same engagement. They are not sold as an upgrade.

VerifyEngagement timeline

02 · 4 QUESTIONS

Method & safety

Is it safe to test our production environment?

Yes, by design. Proofs of concept are read-only and non-destructive: the validator demonstrates access (for example, reading one record across a tenant boundary) without writing, deleting or degrading anything.

Every request is traced and the trace ships with the report, so your team can see exactly what was sent and when. If you prefer, we test a staging environment that mirrors production.

VerifyValidation model

What do you need from us to start?

Three things: the scope (URLs, and an API specification if you have one), test accounts for each role you want tested, and a signed authorisation that defines what is in and out of scope and the testing window.

We never test a system without written authorisation from its owner. That is a legal requirement, not a formality.

VerifyBook a scoping call

What exactly is in the report?

Each finding reads as a ticket, not a paragraph: the exact request, the affected path, a severity you can defend, a replayable proof of concept and a remediation. The one-off pentest includes a PDF report mapped to DORA and NIS2.

On Enterprise, the audit PDF is signed and a board-deck export is added. On Platform and Enterprise, findings also open as Jira tickets.

VerifyPricing

Do you re-test after we fix?

Yes. A re-test once your fixes ship is included in the one-off pentest, and the report is updated with the new status of each finding.

VerifyPricing

03 · 3 QUESTIONS

Pricing

How much does a pentest cost?

€4,000 per web application, flat. That covers the app, its REST or GraphQL API and the external infrastructure behind it, business logic and multi-step chains, replayable proofs of concept, the DORA and NIS2 report and a re-test once your fixes ship.

For comparison, a consulting firm typically quotes €15,000–€30,000 for the same surface.

Scanners on your code are the Platform plan, free to start, then €200 a month per organization. Plans and billing are in the pricing section. Scope your app with an engineer

VerifyPricing

Why does a complex scope cost the same as a simple one?

Deliberately. A flat price removes the scoping negotiation that usually delays a pentest by weeks. Most of the work is compute plus a bounded amount of expert time, so complexity is absorbed rather than billed.

The unit is the web application, not the day and not the number of findings.

VerifyPricing

What does Enterprise add?

Enterprise is priced on quote, per web app per year. It includes everything in Platform, plus a quota of pentests per web app that you launch whenever you want, several web apps under one contract, the signed DORA and NIS2 audit PDF, a board-deck export, a dedicated customer success manager, and invoicing with a custom DPA and procurement.

Moving to Enterprise within 6 months of a one-off pentest? That first pentest is credited in full. Scope your app with an engineer

VerifyPricing

04 · 3 QUESTIONS

Compliance

Does a Fleuret pentest satisfy DORA?

DORA (Regulation (EU) 2022/2554 (opens external site)) requires financial entities to run a digital operational resilience testing programme (Articles 24 and 25), which explicitly includes penetration tests. The report is mapped to that requirement.

What we do not claim: threat-led penetration testing (TLPT, Article 26) is a separate exercise for significant entities, run under the TIBER-EU (opens external site) framework with its own threat intelligence and red team requirements. A Fleuret pentest does not replace a TLPT.

VerifyDORA on EUR-Lex (opens external site)·DORA guides

And NIS2?

NIS2 (Directive (EU) 2022/2555 (opens external site)) Article 21(2)(f) requires policies and procedures to assess the effectiveness of your cybersecurity risk-management measures. A dated pentest report is direct evidence for that obligation.

National transpositions differ in detail: the report maps to the directive, and your auditor maps it to the national text.

VerifyNIS2 on EUR-Lex (opens external site)·NIS2 guides

Does it work for ISO 27001 or SOC 2?

Yes. For ISO 27001:2022 the report supports Annex A controls 8.8 (management of technical vulnerabilities) and 8.29 (security testing in development and acceptance). For SOC 2 it is evidence for the monitoring and vulnerability management criteria.

The report is evidence, not a certificate: your auditor decides what it proves. If you are budgeting a first certification, the compliance cost calculator separates the platform, audit and pentest lines.

VerifyISO/IEC 27001 (opens external site)·Compliance cost

What we will not claim

  • A Fleuret pentest does not replace a DORA threat-led penetration test (TLPT) under TIBER-EU.
  • The report is audit evidence, not a certification. Your auditor decides what it proves.
  • Cassini, the free exposure check, is not a pentest. A clean result means a clean facade, nothing more.
  • Active Directory, mobile and cloud pentests are not available yet.
05 · 5 QUESTIONS

Data & security

Where is our data hosted?

Findings, reports and workspace data are hosted by Scaleway in Paris: a European provider, not the EU region of a US hyperscaler.

Every sub-processor, what it handles and where, is listed on the sub-processors page.

VerifySub-processors

Is our data sent to OpenAI or another US model provider?

No. The models are open-weight (gpt-oss, Kimi K2.5) and run on H100 GPUs at Scaleway in Paris. Engagement data does not leave that environment to reach a third-party model API.

VerifySub-processors·Platform architecture

How long do you keep engagement data?

Vulnerabilities, exploitation evidence and reports are kept for 18 months in a European environment segmented per client, then deleted. You have full access throughout and can request early deletion at any time.

VerifySecurity policy

How do you protect our data?

TLS 1.2 or higher in transit with HSTS on every domain, AES-256 at rest with regular key rotation, least-privilege access to production with mandatory multi-factor authentication, and strict isolation between clients.

In case of a personal data breach, we notify the CNIL within 72 hours, in line with Articles 33 and 34 of the GDPR.

VerifySecurity policy

We found a vulnerability in Fleuret. What do we do?

Write to security@fleuret.ai with reproduction steps and impact. We acknowledge within 48 business hours and respond within 5 business days. We will not pursue researchers acting in good faith under responsible disclosure.

VerifyDisclosure policy

06 · 1 QUESTION

Company

Who is behind Fleuret?

FLEURET AI is a French SAS headquartered in Paris, founded by Yanis Grigy (CEO) and Augustin Ponsin (CTO). The team includes AI engineers and offensive security engineers.

The team and its backers are on the about page.

VerifyAbout·Legal notice

Company facts

Legal name
FLEURET AI SAS
SIREN
999 515 604
Registered office
60 Rue François 1er, 75008 Paris
Security contact
security@fleuret.ai
Data hosting
Scaleway, Paris

Change log

Every change to this page is dated below.

  1. Page published, checked against the live pricing, security policy and sub-processor list.
  2. Pricing moved to three plans: Platform, Pentest one-off and Enterprise.
  3. The Advanced Pentest tier was retired. Its scope is part of the one-off pentest.
NEXT

Still a question? Ask an engineer.

Thirty minutes with the team that runs the engagements. We scope your app and tell you what a pentest would cover.

Privacy Settings

This site uses third-party website tracking technologies to provide and continually improve our services, and to display information according to users' interests. I agree and may revoke or change my consent at any time with effect for the future.