🔑 Secrets & Credential Scanner
Scans source code or logs client-side to detect high-entropy credentials, private keys, AWS access keys, and connection strings.
Input Code / Log Text
Scanner Audit Findings
Paste text on the left and click "Scan for Secrets" to run the auditor.
🐳 Dockerfile Security Linter
Performs static analysis on your Dockerfile to detect privilege escalation, hardcoded secrets, dirty package caches, and unpinned parent tags.
Dockerfile Code Editor
Linter Audit Findings
Paste a Dockerfile on the left and click "Lint Dockerfile" to run.
✍️ AWS IAM Policy Auditor
Parses JSON IAM policy documents to flag wildcard assignments, dangerous administrative policies, and privilege escalation risks.
IAM Policy JSON
Auditor Findings
Paste IAM Policy JSON on the left and click "Audit Policy JSON" to check rules.
🌐 SSL Certificate & Secure HTTP Headers Checker
Verify HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy configurations, and SSL validity timelines.
Select Assessment Mode:
Security Certificate & Header Report
Submit a query or run header analysis to display report.