Fleuret AI (FLEURET AI SAS) · Fleuret: EU-Hosted AI Pentesting Agents for Web Apps and APIs
Fleuret is a Paris-based AI pentesting service whose agents map a web application you own or are authorised to test, its REST or GraphQL API and its external infrastructure, try to exploit what they find, and report only issues they can prove with a replayable, non-destructive proof of concept. It suits European SaaS, fintech and healthtech companies that need audit-ready pentest evidence for NIS2, DORA, ISO 27001 or SOC 2 at a flat €4,000 per web app.
Best for
European companies of roughly 50 to 1,000 people with a real web and API attack surface (SaaS, fintech, healthtech) and a NIS2, DORA, SOC 2 or ISO 27001 deadline, especially those that want pentest data and model inference kept on EU infrastructure
Not ideal for
Teams that need Active Directory, mobile or cloud pentests today, organisations that require a self-hosted or open-source tool, financial entities looking for a DORA TLPT under TIBER-EU, and developers who want a free CLI to run security tests in CI themselves
Who it's for
CISOs, heads of security and CTOs at European SaaS, fintech and healthtech companies that need audit-ready pentest evidence
Fleuret is less a tool you operate than a priced pentest engagement delivered by agents: you hand over scope, test accounts and an authorisation, and get back proven findings in a ticketing workflow plus a report your auditor can file. That suits European mid-market teams whose real problem is compliance evidence on a deadline, and the EU hosting and open-weight models matter to regulated buyers. The open-source agents in this category give engineers more control and run in CI, but leave the reporting, scoping and re-testing to you. Before buying, check that your audit only needs web, API and external infrastructure coverage, and ask how much human review sits behind each engagement.
Who should use it
Security leads and CTOs at European SaaS, fintech and healthtech companies who need a credible, re-testable pentest of a web app and its API for NIS2, DORA, SOC 2 or ISO 27001, and who prefer a flat price and EU-hosted data over a multi-week consulting engagement.
Who should skip it
Teams needing internal network, Active Directory, mobile or cloud pentests now, organisations that must self-host security tooling, financial entities that need a TIBER-EU TLPT, and developers who want to run open-source security agents in their own CI.
Platform
Free to start
Pentest one-off
€4,000 per web app
Billed one-time
Enterprise
On quote, per web app per year
Billed annual
Free tier limits: The Platform plan covers 2 users and 10 repositories per organization and includes no pentest. The homepage pricing section lists it as free per organization, but Fleuret's FAQ says it is free to start and then €200 a month per organization, so confirm the ongoing cost with Fleuret.
Note: Fleuret compares its €4,000 pentest with the €15,000–€30,000 it says a consulting firm typically quotes for the same surface. If you move to Enterprise within six months of a one-off pentest, that pentest is credited in full. The free exposure check (Cassini) is passive and is not a pentest.
Available models
First SOC 2 or ISO 27001 audit at a SaaS company
A flat-priced pentest with a dated report and re-test gives the auditor vulnerability-testing evidence without scheduling a multi-week engagement.
NIS2 or DORA evidence for an EU-regulated company
The report is mapped to both frameworks, and findings, reports and model inference stay on Scaleway infrastructure in France.
Closing the loop on access-control bugs
A cross-tenant IDOR arrives as a ticket with the exact request and a replayable PoC, and the one-click re-test shows whether the fix holds.
Fleuret vs. Strix
Strix is an Apache-2.0 open-source pentesting tool you run yourself in Docker with your own LLM, built for CLI and CI use, with a paid cloud platform and self-hosted enterprise options on top. Fleuret is a hosted commercial service only: you supply scope, test accounts and a signed authorisation, and get a flat-priced pentest per web app with a DORA/NIS2-mapped report, re-test, and data kept on EU infrastructure.
Fleuret vs. Shannon
Shannon is an AGPL-3.0 white-box pentester that needs both the source code and a running copy of the app, and that you run against staging with your own model. Fleuret does not ask for source code: it tests the running web app, its API and external infrastructure from the scope and per-role test accounts you provide, as a managed service with validated findings, a ticketing workflow and a compliance-mapped report.
What is Fleuret?
Fleuret is a French AI pentesting platform. Its orchestrator, Émile, maps a web application and its API, dispatches specialist agents to attack it, and reports only findings it can confirm with a replayable, non-destructive proof of concept. Findings go into a workspace you can push to Jira, Linear or Slack, and the pentest ends with a report mapped to DORA and NIS2.
How much does Fleuret cost?
A one-off pentest is €4,000 per web application, flat regardless of scope, and includes the app, its REST or GraphQL API, the external infrastructure behind it, the DORA/NIS2 report and a re-test once your fixes ship. The Platform plan for code and domain scanners is free to start (2 users, 10 repositories) and does not include a pentest; the homepage lists it as free per organization, while Fleuret's FAQ says it is free to start and then €200 a month per organization. Enterprise is priced on quote per web app per year.
What can Fleuret test?
Web applications, REST and GraphQL APIs, and external infrastructure. Fleuret lists Active Directory, mobile application and cloud pentests as not yet available.
Is it safe to run Fleuret against production?
Fleuret says its proofs of concept are read-only and non-destructive, demonstrating access without writing, deleting or degrading anything, and that every request is traced and shipped with the report. It also offers to test a staging environment instead. You must provide a signed authorisation covering the scope and testing window before any test.
Where is Fleuret's data hosted, and which AI models does it use?
Findings, reports and workspace data are hosted by Scaleway in Paris. Fleuret says it uses open-weight models (gpt-oss and Kimi K2.5) running on Scaleway GPUs in France, and that engagement data is not sent to a third-party model API such as OpenAI's.
Does a Fleuret pentest satisfy DORA or NIS2?
The report is mapped to DORA's resilience testing requirements (Articles 24 and 25) and to NIS2, and Fleuret describes it as evidence for ISO 27001 and SOC 2 as well. Fleuret says the report is audit evidence rather than a certification, and that it does not replace a DORA threat-led penetration test (TLPT) under TIBER-EU.
Is Fleuret open source or self-hostable?
No. Fleuret is a hosted commercial service, and no self-hosted deployment is documented. Teams that want an open-source pentesting agent they run themselves can look at Strix or Shannon.

Strix (OmniSecure, Inc.)
Engineering and AppSec teams that want open-source, AI-driven pentesting of their own apps and APIs in the CLI or CI, with an option to move to a managed platform
FreemiumKeygraph
Engineering teams with access to both the source code and a staging copy of their web app or API who want open-source, evidence-backed security testing in CI
FreemiumFleuret sits between a traditional pentest firm and an automated scanner. You hand it a scope (URLs, plus an API specification if you have one), test accounts for each role you want tested, and a signed authorisation that defines what is in and out of scope and the testing window; Fleuret says it never tests a system without written authorisation from its owner, and its terms limit the service to assets you own or are authorised to test. An orchestrator called Émile then maps the attack surface and dispatches short-lived specialist agents, each focused on one attack vector such as authentication, access control (IDOR), injection, business logic or privilege escalation, and retired after its mission. A separate validation engine turns a suspicion into a finding only after a controlled, read-only challenge confirms it is exploitable, and a Coverage Graph tracks which endpoints, parameters and auth contexts have been tested so the system can decide when the pentest is complete. Fleuret's launch announcement names a second agent, Champollion, alongside Émile, but the platform documentation only describes Émile's architecture. Fleuret describes the service as AI agents combined with human offensive expertise, and says a flat price works because most of the work is compute plus a bounded amount of expert time. Results land in a findings workspace rather than only a PDF: each finding has the exact request, the affected path, a severity, a replayable PoC and a remediation, can be pushed to Jira, Linear or Slack, and can be re-tested after a fix. The one-off pentest report is mapped to DORA and NIS2, and Fleuret's FAQ explains how it also serves as evidence for ISO 27001 and SOC 2, while stating that it is audit evidence, not a certification, and that it does not replace a DORA threat-led penetration test (TLPT). Data residency is a central part of the pitch: findings and reports are hosted by Scaleway in Paris, and the open-weight models (gpt-oss and Kimi K2.5) run on Scaleway GPUs in France, with no calls to third-party model APIs. Fleuret's funding announcement names Brevo, Stoïk and Yogosha among its customers. The tradeoffs: it is a hosted commercial service with no open-source or self-hosted option, scope today is limited to web apps, APIs and external infrastructure (Active Directory, mobile and cloud pentests are on the roadmap), there is no public product documentation beyond the website and FAQ, and the €4,000 price is per web app, so teams with many applications move to Enterprise pricing on quote.
Fleuret announced a €4M pre-seed round led by RAISE Ventures, with Auriga Cyber Ventures, Wind Capital, Better Angle and cybersecurity business angels. It says the money will fund hires in AI, software engineering and offensive security and a faster build-out of the platform, with the aim of moving pentesting from one-off audits to continuous testing.
Fleuret moved to three plans: a free-to-start Platform plan for scanners, a flat €4,000 one-off pentest per web app, and Enterprise on quote. The separate Advanced Pentest tier was retired on September 21, with its scope folded into the one-off pentest.
Are you the founder? Claim this listing →