Security at Chalo

Read-only scanning with clear boundaries.

Chalo is designed to inspect public configuration without exploiting targets. This page describes the operating model, data boundaries, account controls, and disclosure channel.

Read-only scanning

Checks use HTTP requests and DNS lookups. Chalo does not brute-force credentials, fuzz parameters, or change target data.

Public targets only

The scanner blocks private, loopback, and local network targets to reduce server-side request abuse.

Account isolation

Saved scans and findings are restricted to their owner unless that owner explicitly enables a public report.

Transport and authentication

The website uses encrypted transport and managed authentication for signed-in product areas.

Data retention

Saved authenticated reports remain available until the owner deletes them. Anonymous results are not saved as account history.

Vulnerability reporting

Security issues affecting Chalo should follow the responsible disclosure channel.