Kavach

Disclaimer

Effective 10 October 2026. Operator: Support IT Ventures, Mumbai, Maharashtra, India.

Kavach reports technical observations about publicly reachable configuration at the moment of the scan. It is not a security guarantee, a certification, or legal/compliance advice. Results are provided 'as is' without warranty of any kind. You are solely responsible for how you use them and for having authorization to scan the target. See the Terms of Service.

1. Observations, not guarantees

Kavach checks a defined set of externally observable controls (security headers, cookies, TLS certificates, DNS and email-authentication records, externally loaded scripts, a few well-known paths) at the moment of the scan. It does not and cannot test business logic, authenticated areas, server-side code, malware, zero-day vulnerabilities or every known weakness. An “A+” means the controls Kavach checks were present and correctly configured at that time — nothing more. Websites graded “A+” can still be hacked; websites graded “F” may never be.

2. Not a certification or compliance verdict

Kavach is not a PCI SSC Approved Scanning Vendor, not a certification body and not a law firm. “Readiness” indicators mapping findings to OWASP, PCI DSS, GDPR or DPDP concepts show where a technical control may be relevant; they are not audits and do not establish compliance with any standard, regulation or contract. Payment-page script monitoring provides evidence relevant to PCI DSS 6.4.3 / 11.6.1; it does not replace an ASV scan or a QSA assessment.

3. Accuracy and time

Results may be affected by caching layers, CDNs, geographic routing, bot defences, rate limits and transient network conditions, and may contain false positives or false negatives. Results expire: Trust Passports and badges go stale automatically and must not be relied upon beyond the stated observation time.

4. Remediation guidance

Fix suggestions and configuration snippets are generic examples. They may not suit your stack, may conflict with other settings and, applied incorrectly, can break a website or weaken its security. Test in a staging environment and keep a rollback before applying any change to production.

5. Third-party content and tools

Information retrieved from third-party sources (DNS resolvers, Certificate Transparency logs) is reproduced as received. Free tools are provided for convenience without any service commitment.

6. No professional advice; use at your own risk

Nothing in the Service is legal, financial, regulatory or professional security advice. You use the Service and act on its Results entirely at your own risk. Our liability is limited as set out in the Terms of Service, section 13.