Our company
Security tooling built for builders, not auditors.
Chalo started in September 2025 as an internal tool for shipping teams tired of 80-page PDF audits that landed six weeks after the vulnerability shipped. We rebuilt the scanner from scratch to surface the findings that actually break production — with copy-paste fixes for the config files you already edit. No consultants, no retainers, no waiting.
Founded
Sep 2025
Scans run
1.4M+
Avg. scan time
18s
Checks per scan
40+
Our mission
Truth over theater
Every finding is reproducible, evidence-backed, and mapped to a real remediation. No inflated severities, no marketing-driven scores, no 'critical' labels on informational headers.
Fix, don't lecture
A finding without a fix is just anxiety. Every issue we surface comes with the exact Nginx block, Cloudflare rule, or DNS record you need. Security should shorten your day, not your patience.
Fast enough to run before deploy
Our scanner completes in under 30 seconds so it belongs in CI, not in a quarterly review. If we can't tell you before you ship, we're too late.
The story so far
Sep 2025
The internal tool
Chalo started as a weekend hack to stop shipping apps with missing HSTS and expired TLS. The first version circulated inside three startups within a month.
Nov 2025
Chalo goes public
Anonymous public scans launched. First 100k reports run in eight weeks — mostly from indie hackers auditing their own launches before Product Hunt day.
Jan 2026
Deep scan + accounts
Authenticated deep scans landed with DNS, DMARC, MTA-STS, and per-cookie audits. Reports became shareable with signed public URLs.
May 2026
API + badges
Public REST API and embeddable score badges shipped. Chalo grades started showing up on OSS project READMEs and agency portfolios.
Today
Monitoring, teams, CI
Scheduled monitoring, GitHub Action, and team dashboards are in active development. If it belongs in your deploy pipeline, we're building it.
Who we build for
Solo founders shipping fast
You don't have a security team. You have a Friday afternoon before launch. Chalo tells you what to fix before Hacker News tells you first.
Platform + DevOps teams
Wire Chalo into CI to catch header regressions, cert misconfigurations, and DNS drift the moment a PR merges — not the week after production breaks.
Agencies & consultancies
Run scans across every client site on a schedule, share branded reports, and turn findings into scoped remediation work.
Open-source maintainers
Free public badges for OSS projects. Show visitors your site takes security seriously, and link straight to the live report.
Get in touch
Partnerships, enterprise scans, responsible-disclosure reports, or just want to say hi — pick a channel below. We reply to real humans within one business day.
