Cybersecurity · free, no signup
Password Policy Analyzer
Paste a password policy and see it measured against current evidence rather than tradition — which means two rules most policies still contain are reported as findings rather than credited. Scheduled rotation with no evidence of compromise produces incremental passwords, so one leak reveals the pattern for all the others; character-class rules narrow the search space rather than widening it, because people satisfy them in the same few ways. The inference it exists for is harder to see: a maximum length of 16 or 20 has no technical justification, because a hash is fixed-length whatever the input, so a cap that low is evidence the password is going into a sized database column and may not be hashed at all. Storage outranks every rule about the password itself, and a policy that states none of the decisive settings is reported as unjudged rather than approved.
Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.
Paste a password policy and see it judged against what current evidence supports — which means two rules most policies still contain come back as findings, not credits. Scheduled rotation makes passwords weaker (Summer2024! becomes Summer2025!), and character-class rules narrow the search space rather than widening it.
Never paste an actual password. This reads a policy document, and a policy is a claim — a document and a running login system routinely disagree, and only testing the system settles which is true. To check one specific password, the Password Exposure Checker does that without transmitting it.
What happens to what you enter
- The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
- Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
- An email address is stored only where a tool offers to send you a report and you choose to give one.
Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.
When a free check is not enough
This tool reads what is public and reports what it can see. The Identity, Authentication & Passkey Review engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.
Explore Identity, Authentication & Passkey Review