In your browser

Tools

6 tools All posts

Each of these runs entirely in your browser. There is no account, nothing is uploaded, and nothing you type is sent anywhere — which is the whole reason to use ours for a question you would not want to put into someone's web form.

The AI Audit

Score an LLM app against the OWASP LLM Top 10 and the EU AI Act, and print the gap list.

Read first: What the AI Audit is for

Open AI Audit

The CSP Builder

Build a Content-Security-Policy from what your site actually loads, or paste one and see what it really permits — with the breakage named before you ship it.

Read first: Your CSP probably does nothing

Open CSP Builder

Breach exposure triage

Tick what a breach exposed and get the fixes in the order they matter — why a bcrypt hash buys time an unsalted MD5 does not, and why a leaked phone number is not a password problem.

Read first: How to check if your email was breached, and what to do in the next hour

Open Breach exposure triage

Password strength checker

Estimates the guesses a password actually costs, under an attack model you pick — and says plainly when something every other checker calls strong is not.

Read first: Why password strength meters lie

Open Password strength checker

Phishing email analyzer

Paste a raw email and read what SPF, DKIM and DMARC each concluded — and what none of them prove. Flags lookalike senders, a diverging Reply-To, a path that does not fit, and pretext language.

Open Phishing email analyzer

Hacked account triage

Two questions, then an ordered first-hour checklist for an account that was just taken over.

Read first: The first hour of a hacked account is an ordering problem

Open Hacked account triage
← All posts