Anonymous Tools
Privacy & security laboratory

Real evidence. Deeper analysis. Clear boundaries.

An integrated lab for contracts, requests, files, supply chains and infrastructure, with local analysis by default and optional AI that only sees the redacted payload you approve.

Local by default

Sensitive processing stays on device

No invented findings

Every result maps to a rule or evidence

Evidence-bound AI

Redaction and approval before sending

46

working tools

42

run on your device

3

server-query tools

1

optional AI analysis

46 toolsAll current tools are available without an account

Developer

HTTP Message Boundary Differential Lab

Detect CL/TE ambiguity, conflicting lengths, authority disagreement, parser-sensitive whitespace and hop-by-hop boundary hazards without replaying requests.

Runs locally

Website Security

CORS & Preflight Decision Laboratory

Simulate a browser CORS decision and audit wildcard credentials, null origins, Vary behavior, exposed headers and mutation methods.

Runs locally

Website Security

Cache-Key Integrity & Poisoning Auditor

Review shared-cache directives, routing headers, Vary dimensions, cookies and query keys for evidence-backed poisoning and leakage surfaces.

Runs locally

Developer

GraphQL Complexity & Resolver Surface Lab

Measure structural depth, fields, aliases, fragments, introspection, operation batching and high-impact mutation names without executing the query.

Runs locally

Website Security

WebAuthn & Passkey Ceremony Auditor

Audit challenge entropy, RP ID, COSE algorithms, user verification, attestation privacy, timeout and credential exclusion options.

Runs locally

Encryption

JOSE & JWKS Trust-Boundary Auditor

Verify algorithm allowlists, key-type binding, remote selectors, duplicate key IDs, key use metadata and estimated RSA strength without exposing key material.

Runs locally

Developer

Distributed Rate-Limit & Abuse Modeler

Simulate token budgets across IP and account dimensions, traffic distribution, request cost, replica state and failure behavior.

Runs locally

Privacy

Sensitive Data Lineage & Retention Mapper

Map data categories, sources, stores, processors, purpose, ownership, encryption, retention and deletion completeness without personal values.

Runs locally

Developer

CycloneDX & SPDX Evidence Verifier

Validate SBOM component identity, resolved versions, package URLs, hashes, licenses and dependency-graph references.

Runs locally

Website Security

Subresource Integrity & Third-Party Auditor

Inspect HTML for missing or weak SRI, crossorigin contract gaps, cleartext executable resources and inline script exposure without fetching content.

Runs locally

Developer

Authorization Matrix & Separation-of-Duties Verifier

Detect wildcard grants, allow/deny contradictions, privilege-management exposure, missing conditions, orphan roles and separation-of-duties conflicts.

Runs locally

Encryption

Webhook HMAC Signature & Replay Lab

Generate and cryptographically verify timestamped HMAC-SHA256 webhook signatures against the exact raw body, including rotation candidates and replay tolerance.

Runs locally

Developer

OpenAPI Threat & Authorization Mapper

Map every API operation, declared authentication boundary, object route, request schema and error contract from OpenAPI evidence.

Runs locally

Website Security

OAuth & OpenID Connect Protocol Lab

Verify PKCE, state, nonce, redirect boundaries, response modes and duplicate security parameters without sending the authorization URL.

Runs locally

Developer

Software Supply-Chain & OSV Scanner

Parse npm and pnpm manifests locally, review provenance and install risks, then query exact versions against OSV on demand.

Server query

Developer

Infrastructure-as-Code Security Auditor

Audit Docker, Terraform, Kubernetes and CI controls for public exposure, privilege, secrets, mutable artifacts and unsafe execution.

Runs locally

Privacy

HAR Network Privacy Forensics

Inspect browser network captures for third-party destinations, credential-shaped URLs, cleartext requests, cookies and referrer leakage.

Runs locally

Website Security

Evidence-Driven CSP Policy Engineer

Derive a restrictive CSP draft from observed HTML or HAR origins while surfacing inline code and dynamic execution blockers.

Runs locally

AI Security

AI Application Trust-Boundary Lab

Audit prompts, RAG boundaries, tool schemas, authorization, output rendering, retention and privacy with deterministic rules.

Runs locally

Developer

Secret Exposure Flow Mapper

Map secret types, variable references, public client crossings and logging sinks across multiple pasted source files without echoing values.

Runs locally

Website Security

Session & Authentication Contract Lab

Review redacted login and session traces for URL credentials, cookie contracts, redirects, caching and evidence needed to verify rotation.

Runs locally

Files

PDF & Office Active-Content Inspector

Inspect PDF object markers and Office archive structure for scripts, macros, embedded objects, external links and metadata without executing content.

Runs locally

Privacy

Privacy Notice Reality Comparator

Compare observed HAR destinations and processing categories with the actual privacy notice using deterministic, non-legal disclosure checks.

Runs locally

Encryption

Encrypted Security Evidence Vault

Redact, organize, encrypt, persist and export security evidence locally with AES-256-GCM and a password-derived key.

Runs locally

AI Security

Evidence-Bound AI Security Analyst

Redact sensitive data locally, then turn supplied evidence into a structured remediation plan without inventing scan results.

AI after redaction

Developer

Environment Hardening Auditor

Audit .env configuration locally for public secrets, unsafe transport, duplicate keys and production hardening failures.

Runs locally

Website Security

Cookie Security Contract Lab

Verify Set-Cookie scope, prefixes, lifetime, SameSite, Secure, HttpOnly and Partitioned contracts without exposing values.

Runs locally

Developer

API Attack Surface Mapper

Parse a raw HTTP request and map trust boundaries, credential placement, parser risks and authorization-shaped fields.

Runs locally

Passwords

Password Generator

Create strong passwords and passphrases with cryptographically secure randomness.

Runs locally

Files

Metadata Remover

Strip common image metadata without uploading the original file.

Runs locally

Files

Secure File Encryption

Encrypt and decrypt files locally with AES-256-GCM and a password-derived key.

Runs locally

Developer

Secret Leak Scanner

Detect exposed API keys, tokens, private keys and credential URLs in text files.

Runs locally

Privacy

Privacy Redaction Studio

Detect sensitive JSON fields and mask, remove or tokenize them with a transformation ledger.

Runs locally

Website Security

Email Trust Chain Forensics

Reconstruct Received hops and review SPF, DKIM, DMARC and Reply-To alignment from raw headers.

Runs locally

Files

File Identity & Polyglot Lab

Compare magic bytes, extension and MIME type, then inspect active markers and trailing payloads.

Runs locally

Privacy

Browser Permission Surface

Map permission states, isolation controls, storage exposure and advanced browser capabilities.

Runs locally

Privacy

Browser Fingerprint Check

See which browser and device signals may contribute to identification.

Runs locally

Encryption

Secure Note

Encrypt a short note in your browser and share it inside a URL fragment.

Runs locally

Links

Link Structure Inspector

Inspect a URL for deceptive characters, unsafe protocols and suspicious structure.

Runs locally

Developer

Hash Generator

Generate SHA-256, SHA-384 and SHA-512 hashes for text or files.

Runs locally

Developer

JWT Decoder

Decode token claims locally with sensitive values concealed by default.

Runs locally

Encryption

Text Encryption

Encrypt text using password-derived AES-GCM keys in your browser.

Runs locally

Website Security

CSP Policy Analyzer

Parse a Content Security Policy and check dangerous or missing directives.

Runs locally

Website Security

DNS Security Inspector

Inspect public DNS, mail, SPF, DMARC, CAA and nameserver records for a domain.

Server query

Website Security

Website Security Headers Audit

Check HTTPS and public response security headers returned by a website.

Server query

Privacy

Privacy Findings Explainer

Explain common privacy findings locally with clear, practical next steps.

Runs locally