Find the holes before attackers do.
Shankhya Secure is website security testing, done with your written permission. We find the vulnerabilities and give you clear, prioritised fixes.
- ✓SSL certificateValid and current
- !Security headersRecommended headers are missing
- ✓Exposed pagesNo admin or config pages found
Start with a free, read-only check
Three quick checks that show whether the basics are in place. Nothing on your site is attacked or changed.
SSL certificate
Is your padlock valid and not about to expire? An expired or misconfigured certificate scares customers away at checkout.
Security headers
Checks for the browser protections that block common attacks on your shoppers.
Exposed pages
Flags admin or configuration pages that are visible to the public when they shouldn't be.
The full audit, step by step
When you want the full picture, we go well beyond the free checks — always inside a scope you've approved.
Scope and permission
We agree what will be tested, and you sign written permission (rules of engagement).
Deep testing
We look for real, exploitable issues that the free checks can't reveal.
Prioritised report
Findings grouped by severity, with what to fix and how.
Re-test
Once you've patched, we verify the issues are actually closed.
Security headers missing
MediumExample findingWhat we found
Recommended browser protections aren't set on your pages, which makes some common attacks easier.
How to fix it
Add the recommended headers in your web server or hosting settings. The suggested configuration is included in your report.
We only test what you authorise.
Testing a website without its owner's permission can be illegal, so we never do it. Everything beyond the free check starts with your written consent.
Written authorisation first
Deep testing begins only after you've signed written permission.
An agreed scope
You decide what's in scope, and we stay inside it.
Free checks are read-only
They look at what's publicly visible and don't attack or change anything.
Common questions
Can't find your answer? Ask us directly.
Is the free check safe to run?
Yes. It's a read-only check of your SSL certificate, security headers and publicly visible pages. Nothing on your site is attacked or changed.
Do you ever test a site without permission?
Never. Deep testing only happens after you've given written permission, and only within the scope we agree.
What do I get after a full audit?
A report that groups findings by severity and tells you what to fix and how — and a re-test once you've patched.
How much does an audit cost?
Every audit is quoted after a free call, so you know the full cost before we start.
Request a check or ask about an audit
Tell us which website to look at. For a free check we'll email you a plain-language summary; for a full audit we'll get in touch to agree the scope and permission.