LocalAudit

Security · 100% local

Toolkit

Password & secret lab

Estimate how long a password resists an offline attack, and generate cryptographically secure secrets and passphrases. All computation happens in your browser.

Strength checker

Runs locally — nothing is sent anywhere

Secret generator

192 bits of entropy

Uses the browser’s cryptographic RNG (crypto.getRandomValues). Ideal for JWT secrets, API keys and session keys.

Passphrase generator

~40 bits

Memorable and strong — good for disk encryption or a password manager’s master password.

How the estimate works

Entropy is estimated from the character set and length, then reduced for patterns an attacker tries first: dictionary words, keyboard runs, repeats and years.

Crack times assume an attacker already has the password hash and runs a single modern GPU rig. A slow hash like bcrypt buys enormous time; a fast one like MD5 buys almost none.

Figures are order-of-magnitude guidance, not a guarantee. When in doubt, add length.