Developers & ops
Spin up strong passwords, pass keys once via Burn-Link, and encrypt config packs in the file box.
PassAfer
A browser toolkit for password generation, audit, privacy cleanup, and end-to-end encryption. Crypto and sensitive processing run locally — plaintext and keys are not uploaded by default.
Web Crypto AES-256-GCM No plaintext upload
PassAfer keeps sensitive work on your device instead of shipping it to a remote server.
Password generation, strength checks, link cleaning, redaction, and file encryption use Web Crypto locally.
Test passwords, source text, passphrases, and file bytes are not sent out as analytics or logs.
Audit shows entropy and risks, Clean Link lists stripped params, Burn-Link shows a burned state on reopen.
Generate random and passphrase passwords without an account. Sign in for audit, privacy, burn-links, file box, and vault.
Built for people who handle secrets often and prefer not to hand plaintext to a third party.
Spin up strong passwords, pass keys once via Burn-Link, and encrypt config packs in the file box.
Strip tracking params with Clean Link and mask international phones, national IDs, and API keys before sharing screenshots or logs.
Run Password Audit against a local weak-password blacklist to catch reuse and breach-list hits.
Share a secret that should not remain readable — zero-knowledge burn-links destroy after first open.
A focused set of local security tools. Each one does one job well.
Concrete choices you can inspect — not just slogans.
A few straight answers before you put sensitive data into PassAfer.
Password generation, audit, privacy tools, and the file box run in the browser. Plaintext, passphrases, and original files are not uploaded as business data. Burn-Link only uploads ciphertext; the decryption key stays on the client.
Random and passphrase password generation (including copy/export). Password Audit, privacy tools, burn-link creation, the file box, and the vault require sign-in.
A zero-knowledge one-time share link. Creating one requires sign-in; recipients open the read page with no account. After the first successful read, the secret is destroyed.
It estimates entropy and character classes locally, and checks a built-in weak-password blacklist from public breach lists. The password under test never leaves your browser.
No client install. Use the generator right away; sign in when you need the rest of the stack.