Audit CSP, HSTS, X-Frame-Options, and security headers with OWASP grading (A+ to F).
Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. Zero egress.
Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.
Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.
Paste your server's HTTP response headers or raw CSP string.
Inspect your overall security grade (A+ to F), vulnerabilities, and recommendations.
Copy production-ready configuration snippets for Next.js, Nginx, Apache, or Cloudflare.
Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy.
Yes, all audits run 100% in client memory without external network calls.
Zero-egress companion tools in the Security & Network suite
Measure cryptographic randomness, Shannon entropy (0-8 bits/byte), Chi-square test, and byte distributions.
Brute-force all 256 single-byte XOR keys with automated English frequency & chi-squared scoring.
Compare memory hardness, GPU ASIC resistance, and security parameters across KDF standards.
Generate secure RFC 6238 Base32 TOTP secret keys and standard otpauth:// URIs for Google Authenticator.