Capabilities
What Raksha tests
Everything the platform can do, in plain language, with the plan that includes it. Anything we can prove is reported as a confirmed issue with the evidence attached; anything we can only observe as a missing safeguard is reported as hardening, never inflated into a vulnerability.
Website and API testing
Everything reachable from the public internet, checked without touching your data.
Vulnerability scan
Free and every paid planEncryption, browser protections, cookies, exposed files, leaked keys, information disclosure and email spoofing on any site you own.
OpenContinuous monitoring
Solo and aboveRe-runs the scan on a schedule for the sites you add and alerts you when something new appears.
OpenAPI testing
Team and aboveReads your API description, then checks authentication, permissions and exposed operations endpoint by endpoint.
OpenPenetration testing
Active testing that actually tries the attack. Only ever against a target you have signed an engagement for and proved you own.
Guided live pentest
Business and aboveFourteen attack classes tried for real: injection, cross-site scripting, template and command injection, path traversal, request smuggling, forged requests, token weaknesses and access between accounts.
OpenAutonomous pentest
Business PlusThe same tests driven by an agent that follows leads on its own and writes up each step it took.
OpenEngagements and authorisation
Business and aboveSigned scope, ownership proof by DNS record, file, page tag or approval, and an audit trail of every request sent.
OpenTesting skills library
All plans (running them follows your plan)The individual techniques behind each test, so you can see exactly what a run covers.
OpenCode, containers and cloud
The build side of your estate.
Repository scanning
Team and aboveConnected code repositories checked for committed secrets, risky settings and unsafe workflow configuration.
OpenInfrastructure as code
Team and aboveTerraform, CloudFormation, Azure templates, Kubernetes, Helm and Dockerfiles reviewed against hardening baselines.
OpenDependencies
Solo and aboveKnown-vulnerable packages in your project files, with the fix version where one exists.
OpenContainer images
Team and aboveImage metadata and configuration reviewed: how it runs, what it exposes, how it was built.
OpenCloud posture
Business and aboveRead-only review of an AWS account: public storage, permissive access, logging and encryption gaps.
OpenAI systems
The part of your product that talks to a model.
AI surface review
Included with every scanFinds model endpoints and chat surfaces on your site and checks how they are exposed.
OpenAI endpoint probes
Business and aboveGuarded prompts sent to an endpoint you register, looking for instruction override and data leakage.
OpenAI visibility
All plansWhether search and AI assistants can reach, understand and cite your pages.
OpenResults, compliance and governance
What you hand to a customer, a board or an auditor.
Findings workspace
All plansEvery issue in one list, grouped by cause, with owner, status, notes and an estimate of the time to fix.
OpenReports
Solo and aboveTechnical, executive, compliance and client-facing write-ups, fixed at the moment you generate them.
OpenCompliance packs
Team and aboveFindings mapped to SOC 2, ISO 27001, PCI DSS v4, HIPAA and NIST CSF 2.0.
OpenEvidence and governance
Business and aboveTamper-evident evidence retention, legal holds and exportable auditor packs.
OpenAlerts, API and audit log
Team and aboveSlack and webhook alerts, a read API for your own tooling, and a record of who did what.
Open