Our company

Security tooling built for builders, not auditors.

Chalo started in September 2025 to make public-facing website security easier to inspect and explain. The product turns passive HTTP and DNS observations into prioritized findings, evidence, and practical remediation guidance.

Founded

Sep 2025

Assessment style

Read-only

Scan categories

8

Our mission

Truth over theater

Findings include observed evidence and remediation guidance. Scores summarize the scanner's checks; they are not certifications or penetration-test results.

Fix, don't lecture

Each detected issue explains why the control matters and gives practical next steps that a development or operations team can review.

Safe by design

The scanner uses read-only public requests. It does not log in, brute-force credentials, fuzz inputs, or attempt exploitation.

The story so far

Sep 2025

Chalo begins

Work started on a clearer way for builders to inspect public website security controls.

Available

Scanner and reports

Anyone can run a public scan. Signed-in users can save scans and optionally publish a report link.

Available

API and badges

The public JSON endpoint and dynamic SVG badge support lightweight automation and sharing.

Planned

Monitoring, teams, integrations

Scheduled monitoring, collaborative workspaces, managed keys, and native integrations remain on the roadmap.

Who we build for

Solo founders shipping fast

You don't have a security team. You have a Friday afternoon before launch. Chalo tells you what to fix before Hacker News tells you first.

Platform + DevOps teams

Call the public JSON endpoint from a shell step to check internet-visible controls. Managed CI integrations are planned.

Agencies & consultancies

Run individual client-site assessments, share public reports when appropriate, and turn findings into scoped remediation work.

Open-source maintainers

Free public badges for OSS projects. Show visitors your site takes security seriously, and link straight to the live report.

Get in touch

Product questions, partnerships, responsible-disclosure reports, or feedback are welcome through the channels below.