Tools
Each of these runs entirely in your browser. There is no account, nothing is uploaded, and nothing you type is sent anywhere — which is the whole reason to use ours for a question you would not want to put into someone's web form.
The AI Audit
Score an LLM app against the OWASP LLM Top 10 and the EU AI Act, and print the gap list.
Read first: What the AI Audit is for
Open AI AuditThe CSP Builder
Build a Content-Security-Policy from what your site actually loads, or paste one and see what it really permits — with the breakage named before you ship it.
Read first: Your CSP probably does nothing
Open CSP BuilderBreach exposure triage
Tick what a breach exposed and get the fixes in the order they matter — why a bcrypt hash buys time an unsalted MD5 does not, and why a leaked phone number is not a password problem.
Read first: How to check if your email was breached, and what to do in the next hour
Open Breach exposure triagePassword strength checker
Estimates the guesses a password actually costs, under an attack model you pick — and says plainly when something every other checker calls strong is not.
Read first: Why password strength meters lie
Open Password strength checkerPhishing email analyzer
Paste a raw email and read what SPF, DKIM and DMARC each concluded — and what none of them prove. Flags lookalike senders, a diverging Reply-To, a path that does not fit, and pretext language.
Open Phishing email analyzerHacked account triage
Two questions, then an ordered first-hour checklist for an account that was just taken over.
Read first: The first hour of a hacked account is an ordering problem
Open Hacked account triage