PA PassAfer

PassAfer

Local encryption, secure anywhere

Local-first encryption and privacy tools

Generate a strong password, check how guessable it is, strip tracking parameters from a URL, send a one-time secret, or encrypt a file with AES-256-GCM. All of that runs in the browser. Plaintext and keys are not uploaded; every tool is available as soon as you open the page.

Web Crypto AES-256-GCM No plaintext upload

Why encryption stays in the browser

People searching for an online password generator or a way to encrypt a file usually want one answer first: will the tool send plaintext to someone else’s server? PassAfer keeps that work on this device.

Who it is for

Built for people who handle secrets often and would rather not hand plaintext to a third party.

Developers and ops

Generate strong passwords in bulk, pass a key once with a self-destructing message, and encrypt config packs in the file tool.

Support and ops teams

Strip UTM and ad click IDs before you share a link. Mask phone numbers, national IDs, emails, and API keys before a ticket or screenshot goes out.

Anyone checking a reused password

Use the local password strength checker for entropy, character mix, and hits against a public leaked weak-password list.

One-time collaboration

Send a password or recovery code that should not sit in chat history. The recipient opens it once; then it burns.

Pick a tool by search intent

Each page answers one question so they do not compete for the same search.

Choices you can verify

No empty slogans. You can check these on this machine or in DevTools.

Algorithm
AES-256-GCM authenticated encryption. File passphrases are stretched with PBKDF2 via the browser Web Crypto API
Where it runs
Static frontend plus local compute. Open DevTools → Network to see whether plaintext, passphrases, or original files leave the tab
Self-destructing message
The server holds ciphertext only. The decryption key lives in the client URL fragment after # and is not sent with the HTTP request
No account
Every tool is available when you open the page. There is no sign-in and no password vault

FAQ

Read these before you put a secret into any of the tools.

Are generated passwords and files uploaded to a server?

No. Password generation, strength checks, link cleaning, redaction, and file encryption run in the browser. Plaintext, passphrases, and original files are not uploaded as product data. A self-destructing message uploads ciphertext only; the decryption key stays in the URL fragment after #.

Do I need an account?

No. Password generation, strength checks, privacy tools, creating a one-time secret, and file encryption are available as soon as you open the page. Recipients also open a self-destructing message with no account.

Does the recipient of a self-destructing message need an account?

No. Creating and reading a link both work without an account. The recipient opens the read page directly. After the first successful read, the secret is destroyed. Opening the same link again shows that it has been burned.

Does the password strength checker search every known data breach?

No. The password you test never leaves the browser. The tool estimates entropy and character mix locally, then compares against a built-in list of publicly leaked weak passwords. That catches common reused secrets. It is not a full internet breach lookup.

Start with one strong password — locally

No client to install and no account to create. Generate a password, check strength, clean a URL, or encrypt a file as soon as you open the page.