🛡️

DevSecOps Toolkit

Client-Side Static Security Auditor

🔑 Secrets & Credential Scanner

Scans source code or logs client-side to detect high-entropy credentials, private keys, AWS access keys, and connection strings.

Input Code / Log Text

Scanner Audit Findings

Paste text on the left and click "Scan for Secrets" to run the auditor.

🐳 Dockerfile Security Linter

Performs static analysis on your Dockerfile to detect privilege escalation, hardcoded secrets, dirty package caches, and unpinned parent tags.

Dockerfile Code Editor

Linter Audit Findings

Paste a Dockerfile on the left and click "Lint Dockerfile" to run.

✍️ AWS IAM Policy Auditor

Parses JSON IAM policy documents to flag wildcard assignments, dangerous administrative policies, and privilege escalation risks.

IAM Policy JSON

Auditor Findings

Paste IAM Policy JSON on the left and click "Audit Policy JSON" to check rules.

🌐 SSL Certificate & Secure HTTP Headers Checker

Verify HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy configurations, and SSL validity timelines.

Select Assessment Mode:

Security Certificate & Header Report

Submit a query or run header analysis to display report.