Quick reminder: because flatpak hides your installation state from the system, part of flatpaks could be wildly out of date or toxic releases and your system will.not.care nor even show you anything about it.
Enterprise tools - or normal stuff that acts like them - that check remotely what you have installed and let you know you're potentially out of date (like tenable but not junk) will not learn anything about flatpak content.
Good luck. Every good thing about enterprise packaging is thrown out the window. Flatpaks are toxic.