LocalAudit

Security · 100% local

100% client-side

A security toolkit for your configs, secrets and tokens

Scan deployment files against 77+ rules, hunt for leaked credentials, inspect JWTs, build hardened HTTP headers and generate strong secrets — all without anything leaving your browser.

What you can do

Why client-side?

Security tooling that uploads your configs and secrets to a server creates the exact risk it is meant to reduce. Everything here runs in your browser with the Web Crypto API — no backend, no network calls, no telemetry. You can disconnect from the internet and it still works.

Frequently asked questions

Is LocalAudit free?

Yes. Every tool is free to use, with no account, no limits and no ads.

Are my files or secrets uploaded anywhere?

No. All analysis runs in your browser with JavaScript; there is no backend. Loaded files are kept in your browser storage so a reload does not lose your scan, and "Clear all" deletes them. Once the page has loaded it even works offline.

Which files can LocalAudit scan?

Dockerfile, docker-compose.yml, nginx.conf, .env, .gitignore, package.json and vercel.json get dedicated rules. Any other text file, up to 5 MB, is scanned for leaked secrets such as AWS, GitHub, Stripe or OpenAI keys.

How is the security score calculated?

Every scan starts at 100. Each finding subtracts points by severity: 15 for critical, 8 for medium and 3 for low. Findings are mapped to CWE and OWASP and come with a copy-ready fix.

Can I use the results in CI or GitHub?

Yes. Export a report as Markdown for pull requests, JSON for other tools, or SARIF 2.1.0 to upload to GitHub code scanning.