Free security tools for daily use. The checks run in your browser – the domain checks transmit only the domain name.
🔑 Password Strength Checker
Check the strength of an existing password.
ℹ️ Hinweis: Die Passwort-Analyse erfolgt ausschließlich in Ihrem Browser. Das Passwort wird nicht gespeichert oder übertragen. Crack-Zeiten sind Schätzungen für einen Offline-Angriff mit 100 Mrd. Versuchen/Sekunde (z. B. gegen unsalted MD5) — gegen bcrypt oder Argon2 verlängern sich die Werte deutlich.
🔐 Password Generator
Generate cryptographically secure random passwords using crypto.getRandomValues().
ℹ️ Hinweis: Alle Passwörter werden ausschließlich in Ihrem Browser generiert. Keine Daten werden an einen Server übertragen.
🌐 Domain, DNS & Mail Security Check
E-mail (SPF, DKIM, DMARC, MX), SSL/HTTPS, and DNS (including DNSSEC, nameserver redundancy, and IPv6) at a glance in 10 seconds: Are all security settings correct for your domain?
E-mail (SPF/DKIM/DMARC), SSL/HTTPS and DNS at a glance: Are all security settings correct for your domain? Checked in 10 seconds – runs in your browser and through our security checks.
Would you like to resolve open findings?
Let's discuss the technical details in a free 30-minute intro call.
ℹ️ Note: The check reads public DNS records via Cloudflare DNS-over-HTTPS and verifies HTTP/SSL reachability. No private credentials or mailbox contents are transmitted.
🧯 Backup Self-Assessment
Will your backups hold up when ransomware hits? Six yes/no questions based on the 3-2-1 rule – with an honest evaluation. Runs entirely locally in your browser.
Six yes/no questions based on the 3-2-1 rule and what ransomware groups attack first. Unchecked counts as "no" – honesty pays off.
🚨 Critical risk
As it looks, your data would hardly be recoverable in a real incident – exactly the scenario where companies end up paying or giving up. Priority one: at least one offline/immutable copy and a restore that has actually been rehearsed.
⚠️ Partially covered
The basics are in place – but the missing points are precisely what ransomware groups exploit: the copy that is not separated, the restore that was never tested, the cloud mailbox nobody backed up.
✅ Well positioned
The foundation is solid. Remaining risks usually hide in the details: exceptions to the rule, permissions on the backup server, a recovery plan that only exists on paper. An outside look is worthwhile.
ℹ️ Note: Orientation, not a guarantee: the check condenses proven rules (3-2-1-1-0) and does not replace an assessment of your actual environment. All answers stay local in your browser.
🔒 MFA Self-Assessment
Where is multi-factor authentication missing? Eight yes/no questions about the access points attackers target first – with an honest evaluation. Runs entirely locally in your browser.
Eight yes/no questions on multi-factor authentication (MFA) – the single most effective protection against compromised credentials. Unchecked counts as "no" – honesty pays off.
🚨 MFA is missing almost everywhere
This is the most common finding I see in audits: a single compromised password is enough to reach email, cloud, and admin access. MFA is by far the most effective single lever – and in most cases quick to add.
⚠️ Partially protected
The basics are in place – but the gaps are exactly what attackers take: the mailbox without MFA, the remote access, the banking, the SMS code that can be intercepted. Attackers only need one open point.
✅ Well positioned
MFA is the most important piece – and it is in place. The remaining levers are elsewhere: password management, permissions, monitoring, and a recovery path that actually works under pressure.
ℹ️ Note: Orientation, not a guarantee: the check condenses proven MFA principles and does not replace an assessment of your actual environment. All answers stay local in your browser.
🛡️ NIS2 Self-Assessment
Not sure whether NIS2 applies to your company? Four questions on sector, role and size – plus a quick check of your security foundation. Runs locally in your browser.
✅ Probably an essential entity
With high probability your company falls within the scope of NIS2 — with the most extensive obligations: risk management, reporting of significant incidents, and management responsibility. Time to assess your current state and close the gaps in priority order.
✅ Probably an important entity
Even as an "important entity", NIS2 obligations apply to you: risk management, reporting of significant incidents and baseline security measures. The requirements are somewhat lighter than for essential entities — but supervision and reporting duties still apply.
ℹ️ Probably not directly in scope
You probably don't fall directly under NIS2. However: companies outside the scope still feel NIS2 through the supply chain — customers in scope increasingly expect security evidence from their partners. It pays to put the basics in place before that request arrives.
Bonus: How solid is your foundation?
Which of these are already in place?
ℹ️ Note: Orientation, not legal advice: this check is based on EU Directive (EU) 2022/2555 ("NIS2"). The binding German implementation (NIS2UmsuCG) may regulate details differently — only an individual assessment is binding. All inputs stay local in your browser.