SECURITY_FAQ

RETURN_TO_BASE

Why is information censored?

To protect your privacy and safety. We strictly redact sensitive PII (Personally Identifiable Information) such as full passwords, IP addresses, and birth dates to prevent this tool from being used by malicious actors for "doxing" or targeted attacks.

UNLOCK FEATURE: As the data owner, you can unlock specific records by verifying your identity with the password used for that account. This ensures only you see your full data.

Is it safe to check my password?

Yes. We use client-side SHA-1 hashing and secure APIs (k-Anonymity model). Your plain-text password is never sent to our servers. We calculate the hash locally in your browser and only send the first 5 characters of that hash to check against our database.

What is a "Deep Scan"?

Standard scans check public breach databases (like Have I Been Pwned). A Deep Scan searches private leak databases, dark web dumps, and "combolists" that are not publicly indexed. This often reveals newer or more sensitive breaches including username-only leaks and specific IP logs.

How does "Roast My Password" work?

It's a fun way to test password strength! We use an advanced algorithm (zxcvbn) to calculate entropy and crack time, then pair it with a snarky comment based on how weak or strong it is. Like all our tools, this runs 100% locally in your browser.