Exposed secrets
API keys, tokens and database URLs left in shipped JavaScript, source maps and config files.
Kavach reads your live site the way an attacker reads it first — exposed keys, missing controls, forgotten subdomains — and tells you in plain English. No agent to install, no code access.
raksha@scan:~$ ./scan --mode passive
Enter your domain. We read only what's already public — no login, no code, no card.
~60s · 5+ exposure classes · no data stored
API keys, tokens and database URLs left in shipped JavaScript, source maps and config files.
Security headers, TLS configuration and cookie flags — the defaults that quietly never got set.
Staging boxes, old dashboards and dangling DNS records still answering to the open internet.
SPF, DKIM and DMARC gaps that let anyone send mail that looks like it came from you.
Open buckets, unguarded API routes and client-side keys that read straight from your tables.
Findings mapped to India's data-protection obligations, so you know what actually needs fixing.
Verify your domain, see every hole we can see.
Run a free scanYear-round cover for your domain — we watch, you know first.
Get Raksha Kavach