Capabilities

What Raksha tests

Everything the platform can do, in plain language, with the plan that includes it. Anything we can prove is reported as a confirmed issue with the evidence attached; anything we can only observe as a missing safeguard is reported as hardening, never inflated into a vulnerability.

Website and API testing

Everything reachable from the public internet, checked without touching your data.

Vulnerability scan

Free and every paid plan

Encryption, browser protections, cookies, exposed files, leaked keys, information disclosure and email spoofing on any site you own.

Open

Continuous monitoring

Solo and above

Re-runs the scan on a schedule for the sites you add and alerts you when something new appears.

Open

API testing

Team and above

Reads your API description, then checks authentication, permissions and exposed operations endpoint by endpoint.

Open

Penetration testing

Active testing that actually tries the attack. Only ever against a target you have signed an engagement for and proved you own.

Guided live pentest

Business and above

Fourteen attack classes tried for real: injection, cross-site scripting, template and command injection, path traversal, request smuggling, forged requests, token weaknesses and access between accounts.

Open

Autonomous pentest

Business Plus

The same tests driven by an agent that follows leads on its own and writes up each step it took.

Open

Engagements and authorisation

Business and above

Signed scope, ownership proof by DNS record, file, page tag or approval, and an audit trail of every request sent.

Open

Testing skills library

All plans (running them follows your plan)

The individual techniques behind each test, so you can see exactly what a run covers.

Open

Code, containers and cloud

The build side of your estate.

Repository scanning

Team and above

Connected code repositories checked for committed secrets, risky settings and unsafe workflow configuration.

Open

Infrastructure as code

Team and above

Terraform, CloudFormation, Azure templates, Kubernetes, Helm and Dockerfiles reviewed against hardening baselines.

Open

Dependencies

Solo and above

Known-vulnerable packages in your project files, with the fix version where one exists.

Open

Container images

Team and above

Image metadata and configuration reviewed: how it runs, what it exposes, how it was built.

Open

Cloud posture

Business and above

Read-only review of an AWS account: public storage, permissive access, logging and encryption gaps.

Open

AI systems

The part of your product that talks to a model.

AI surface review

Included with every scan

Finds model endpoints and chat surfaces on your site and checks how they are exposed.

Open

AI endpoint probes

Business and above

Guarded prompts sent to an endpoint you register, looking for instruction override and data leakage.

Open

AI visibility

All plans

Whether search and AI assistants can reach, understand and cite your pages.

Open

Results, compliance and governance

What you hand to a customer, a board or an auditor.

Findings workspace

All plans

Every issue in one list, grouped by cause, with owner, status, notes and an estimate of the time to fix.

Open

Reports

Solo and above

Technical, executive, compliance and client-facing write-ups, fixed at the moment you generate them.

Open

Compliance packs

Team and above

Findings mapped to SOC 2, ISO 27001, PCI DSS v4, HIPAA and NIST CSF 2.0.

Open

Evidence and governance

Business and above

Tamper-evident evidence retention, legal holds and exportable auditor packs.

Open

Alerts, API and audit log

Team and above

Slack and webhook alerts, a read API for your own tooling, and a record of who did what.

Open