Deep security scanning
for any website.
Chalo audits TLS, security headers, exposed files, DNS, and email posture — then grades your site A–F with fixes for every finding. Free to try, no signup.
Try · ·
Eight categories. One grade.
Chalo runs every scan against a real HTTP stack from an edge worker — no browser plug-in, no local install.
HTTPS reachability, HTTP→HTTPS redirect, HSTS enforcement.
CSP, X-Frame-Options, XCTO, Referrer-Policy, Permissions-Policy.
Secure, HttpOnly, and SameSite flags on every Set-Cookie.
Probes .env, .git, config backups, phpinfo, server-status, .DS_Store.
A/AAAA/NS, CAA restrictions, IPv6 availability via DoH.
SPF strength, DMARC policy, MX visibility.
Detect leaked Server / X-Powered-By banners.
Mixed-content sweep, robots.txt review.
From URL to A-grade in under 10 seconds.
Any public hostname. No agent, no install, no permissions.
Edge workers hit TLS, headers, DNS, and known-risky paths concurrently.
You get an A–F grade, per-category breakdown, and copy-pasteable remediation.
Teams shipping with Chalo.
"Chalo caught an exposed .env on a staging host we forgot about. Fixed in ten minutes. Cheaper than any pentest we've bought."
"The DMARC + SPF breakdown alone is worth Pro. Our deliverability team stopped guessing."
"We run Chalo on every deploy via the API. Feels like having a security engineer on the CI pipeline."
Answers, before you ask.
Simple, honest pricing.
Public one-off scans. Lite categories only.
- Instant lite scan
- No signup required
- Sample findings
Deep scans, history, shareable reports.
- Unlimited deep scans
- Scan history
- DNS + email security
- Shareable reports
Everything in Pro, plus team seats and API.
- 5 team seats
- REST API
- Scheduled scans
- Slack alerts (soon)
Grade your site in seconds.
No install. No signup for the lite scan. Just paste a URL and watch Chalo work.
Run a scan