Real evidence. Deeper analysis. Clear boundaries.
An integrated lab for contracts, requests, files, supply chains and infrastructure, with local analysis by default and optional AI that only sees the redacted payload you approve.
Local by default
Sensitive processing stays on device
No invented findings
Every result maps to a rule or evidence
Evidence-bound AI
Redaction and approval before sending
working tools
run on your device
server-query tools
optional AI analysis
Developer
HTTP Message Boundary Differential Lab
Detect CL/TE ambiguity, conflicting lengths, authority disagreement, parser-sensitive whitespace and hop-by-hop boundary hazards without replaying requests.
Runs locallyWebsite Security
CORS & Preflight Decision Laboratory
Simulate a browser CORS decision and audit wildcard credentials, null origins, Vary behavior, exposed headers and mutation methods.
Runs locallyWebsite Security
Cache-Key Integrity & Poisoning Auditor
Review shared-cache directives, routing headers, Vary dimensions, cookies and query keys for evidence-backed poisoning and leakage surfaces.
Runs locallyDeveloper
GraphQL Complexity & Resolver Surface Lab
Measure structural depth, fields, aliases, fragments, introspection, operation batching and high-impact mutation names without executing the query.
Runs locallyWebsite Security
WebAuthn & Passkey Ceremony Auditor
Audit challenge entropy, RP ID, COSE algorithms, user verification, attestation privacy, timeout and credential exclusion options.
Runs locallyEncryption
JOSE & JWKS Trust-Boundary Auditor
Verify algorithm allowlists, key-type binding, remote selectors, duplicate key IDs, key use metadata and estimated RSA strength without exposing key material.
Runs locallyDeveloper
Distributed Rate-Limit & Abuse Modeler
Simulate token budgets across IP and account dimensions, traffic distribution, request cost, replica state and failure behavior.
Runs locallyPrivacy
Sensitive Data Lineage & Retention Mapper
Map data categories, sources, stores, processors, purpose, ownership, encryption, retention and deletion completeness without personal values.
Runs locallyDeveloper
CycloneDX & SPDX Evidence Verifier
Validate SBOM component identity, resolved versions, package URLs, hashes, licenses and dependency-graph references.
Runs locallyWebsite Security
Subresource Integrity & Third-Party Auditor
Inspect HTML for missing or weak SRI, crossorigin contract gaps, cleartext executable resources and inline script exposure without fetching content.
Runs locallyDeveloper
Authorization Matrix & Separation-of-Duties Verifier
Detect wildcard grants, allow/deny contradictions, privilege-management exposure, missing conditions, orphan roles and separation-of-duties conflicts.
Runs locallyEncryption
Webhook HMAC Signature & Replay Lab
Generate and cryptographically verify timestamped HMAC-SHA256 webhook signatures against the exact raw body, including rotation candidates and replay tolerance.
Runs locallyDeveloper
OpenAPI Threat & Authorization Mapper
Map every API operation, declared authentication boundary, object route, request schema and error contract from OpenAPI evidence.
Runs locallyWebsite Security
OAuth & OpenID Connect Protocol Lab
Verify PKCE, state, nonce, redirect boundaries, response modes and duplicate security parameters without sending the authorization URL.
Runs locallyDeveloper
Software Supply-Chain & OSV Scanner
Parse npm and pnpm manifests locally, review provenance and install risks, then query exact versions against OSV on demand.
Server queryDeveloper
Infrastructure-as-Code Security Auditor
Audit Docker, Terraform, Kubernetes and CI controls for public exposure, privilege, secrets, mutable artifacts and unsafe execution.
Runs locallyPrivacy
HAR Network Privacy Forensics
Inspect browser network captures for third-party destinations, credential-shaped URLs, cleartext requests, cookies and referrer leakage.
Runs locallyWebsite Security
Evidence-Driven CSP Policy Engineer
Derive a restrictive CSP draft from observed HTML or HAR origins while surfacing inline code and dynamic execution blockers.
Runs locallyAI Security
AI Application Trust-Boundary Lab
Audit prompts, RAG boundaries, tool schemas, authorization, output rendering, retention and privacy with deterministic rules.
Runs locallyDeveloper
Secret Exposure Flow Mapper
Map secret types, variable references, public client crossings and logging sinks across multiple pasted source files without echoing values.
Runs locallyWebsite Security
Session & Authentication Contract Lab
Review redacted login and session traces for URL credentials, cookie contracts, redirects, caching and evidence needed to verify rotation.
Runs locallyFiles
PDF & Office Active-Content Inspector
Inspect PDF object markers and Office archive structure for scripts, macros, embedded objects, external links and metadata without executing content.
Runs locallyPrivacy
Privacy Notice Reality Comparator
Compare observed HAR destinations and processing categories with the actual privacy notice using deterministic, non-legal disclosure checks.
Runs locallyEncryption
Encrypted Security Evidence Vault
Redact, organize, encrypt, persist and export security evidence locally with AES-256-GCM and a password-derived key.
Runs locallyAI Security
Evidence-Bound AI Security Analyst
Redact sensitive data locally, then turn supplied evidence into a structured remediation plan without inventing scan results.
AI after redactionDeveloper
Environment Hardening Auditor
Audit .env configuration locally for public secrets, unsafe transport, duplicate keys and production hardening failures.
Runs locallyWebsite Security
Cookie Security Contract Lab
Verify Set-Cookie scope, prefixes, lifetime, SameSite, Secure, HttpOnly and Partitioned contracts without exposing values.
Runs locallyDeveloper
API Attack Surface Mapper
Parse a raw HTTP request and map trust boundaries, credential placement, parser risks and authorization-shaped fields.
Runs locallyPasswords
Password Generator
Create strong passwords and passphrases with cryptographically secure randomness.
Runs locallyFiles
Metadata Remover
Strip common image metadata without uploading the original file.
Runs locallyFiles
Secure File Encryption
Encrypt and decrypt files locally with AES-256-GCM and a password-derived key.
Runs locallyDeveloper
Secret Leak Scanner
Detect exposed API keys, tokens, private keys and credential URLs in text files.
Runs locallyPrivacy
Privacy Redaction Studio
Detect sensitive JSON fields and mask, remove or tokenize them with a transformation ledger.
Runs locallyWebsite Security
Email Trust Chain Forensics
Reconstruct Received hops and review SPF, DKIM, DMARC and Reply-To alignment from raw headers.
Runs locallyFiles
File Identity & Polyglot Lab
Compare magic bytes, extension and MIME type, then inspect active markers and trailing payloads.
Runs locallyPrivacy
Browser Permission Surface
Map permission states, isolation controls, storage exposure and advanced browser capabilities.
Runs locallyPrivacy
Browser Fingerprint Check
See which browser and device signals may contribute to identification.
Runs locallyEncryption
Secure Note
Encrypt a short note in your browser and share it inside a URL fragment.
Runs locallyLinks
Link Structure Inspector
Inspect a URL for deceptive characters, unsafe protocols and suspicious structure.
Runs locallyDeveloper
Hash Generator
Generate SHA-256, SHA-384 and SHA-512 hashes for text or files.
Runs locallyDeveloper
JWT Decoder
Decode token claims locally with sensitive values concealed by default.
Runs locallyEncryption
Text Encryption
Encrypt text using password-derived AES-GCM keys in your browser.
Runs locallyWebsite Security
CSP Policy Analyzer
Parse a Content Security Policy and check dangerous or missing directives.
Runs locallyWebsite Security
DNS Security Inspector
Inspect public DNS, mail, SPF, DMARC, CAA and nameserver records for a domain.
Server queryWebsite Security
Website Security Headers Audit
Check HTTPS and public response security headers returned by a website.
Server queryPrivacy
Privacy Findings Explainer
Explain common privacy findings locally with clear, practical next steps.
Runs locally