Developers and ops
Generate strong passwords in bulk, pass a key once with a self-destructing message, and encrypt config packs in the file tool.
PassAfer
Local encryption, secure anywhere
Generate a strong password, check how guessable it is, strip tracking parameters from a URL, send a one-time secret, or encrypt a file with AES-256-GCM. All of that runs in the browser. Plaintext and keys are not uploaded; every tool is available as soon as you open the page.
Web Crypto AES-256-GCM No plaintext upload
People searching for an online password generator or a way to encrypt a file usually want one answer first: will the tool send plaintext to someone else’s server? PassAfer keeps that work on this device.
Random passwords, strength scoring, link cleaning, redaction, and file encryption use the Web Crypto API on your machine — not a remote worker.
Test passwords, source text, file passphrases, and original bytes are not sent as analytics or logs. A one-time secret stores ciphertext only.
The strength checker shows entropy and risks. Clean Link lists stripped parameters. Reopening a burned message shows it is gone.
Open any tool and use it immediately: generate a password, check strength, clean a URL, send a one-time secret, or encrypt a file. No account.
Built for people who handle secrets often and would rather not hand plaintext to a third party.
Generate strong passwords in bulk, pass a key once with a self-destructing message, and encrypt config packs in the file tool.
Strip UTM and ad click IDs before you share a link. Mask phone numbers, national IDs, emails, and API keys before a ticket or screenshot goes out.
Use the local password strength checker for entropy, character mix, and hits against a public leaked weak-password list.
Send a password or recovery code that should not sit in chat history. The recipient opens it once; then it burns.
Each page answers one question so they do not compete for the same search.
No empty slogans. You can check these on this machine or in DevTools.
Read these before you put a secret into any of the tools.
No. Password generation, strength checks, link cleaning, redaction, and file encryption run in the browser. Plaintext, passphrases, and original files are not uploaded as product data. A self-destructing message uploads ciphertext only; the decryption key stays in the URL fragment after #.
No. Password generation, strength checks, privacy tools, creating a one-time secret, and file encryption are available as soon as you open the page. Recipients also open a self-destructing message with no account.
No. Creating and reading a link both work without an account. The recipient opens the read page directly. After the first successful read, the secret is destroyed. Opening the same link again shows that it has been burned.
No. The password you test never leaves the browser. The tool estimates entropy and character mix locally, then compares against a built-in list of publicly leaked weak passwords. That catches common reused secrets. It is not a full internet breach lookup.
No client to install and no account to create. Generate a password, check strength, clean a URL, or encrypt a file as soon as you open the page.