Is my password sent over the network?
No. The breach check uses k-anonymity: only the first five characters of the SHA-1 hash leave your browser. The full password is never transmitted.
Public tool
Type any password. Password Strength Gate scores its length, character variety and common patterns, then checks it against the Have I Been Pwned breach database using k-anonymity so the full password never leaves your browser, and asks the live AffixIO API for a signed yes or no.
Type any password. The full password stays in your browser. Only the first five characters of its SHA-1 hash are sent to the breach check.
AffixIO proof
Stamped by the live AffixIO API and signed with ML-DSA-65, the FIPS 204 post-quantum algorithm. Nothing personal goes into the payload.
Three moves, no sign-up.
Paste or type any password into the field. The field is masked, and the full password never leaves your browser.
The tool scores the password for length, character variety and common patterns, then checks it against the Have I Been Pwned breach database using k-anonymity.
A YES means the password is strong and has not appeared in a known breach. A NO tells you why, with a signed proof from the live AffixIO API.
Password Strength Gate scores a password on length, the mix of upper and lower case letters, digits and symbols, and common patterns such as walks across the keyboard, repeated characters and sequences. It also checks a list of frequently used passwords.
The breach check uses the Have I Been Pwned k-anonymity API. Your browser hashes the password with SHA-1, sends only the first five characters of that hash, and gets back a list of matching suffixes. The full password is never transmitted.
The proof card shows the answer stamped by the live AffixIO API: a proof id, an audit id, the policy version, and an ML-DSA-65 signature over the payload digest.
No. The breach check uses k-anonymity: only the first five characters of the SHA-1 hash leave your browser. The full password is never transmitted.
No. The HIBP k-anonymity endpoint is free and keyless. The signed verdict uses a throwaway demo key that the page requests from the live AffixIO API on its own.
Length, character variety, and common patterns such as keyboard walks, repeated characters and sequences, plus a list of frequently used passwords.
The answer stamped by the live AffixIO API: a proof id, an audit id, the policy version, and an ML-DSA-65 signature over the payload digest.