PA PassAfer

PassAfer

Local encryption, secure anywhere

A browser toolkit for password generation, audit, privacy cleanup, and end-to-end encryption. Crypto and sensitive processing run locally — plaintext and keys are not uploaded by default.

Web Crypto AES-256-GCM No plaintext upload

Why local-first

PassAfer keeps sensitive work on your device instead of shipping it to a remote server.

Who it’s for

Built for people who handle secrets often and prefer not to hand plaintext to a third party.

Developers & ops

Spin up strong passwords, pass keys once via Burn-Link, and encrypt config packs in the file box.

Support & ops teams

Strip tracking params with Clean Link and mask international phones, national IDs, and API keys before sharing screenshots or logs.

Privacy-minded users

Run Password Audit against a local weak-password blacklist to catch reuse and breach-list hits.

One-time collaboration

Share a secret that should not remain readable — zero-knowledge burn-links destroy after first open.

The stack

A focused set of local security tools. Each one does one job well.

Security at a glance

Concrete choices you can inspect — not just slogans.

Crypto
AES-256-GCM authenticated encryption; passphrase derivation via Web Crypto
Where it runs
Static frontend + local compute; use DevTools Network to verify nothing sensitive is sent
Burn-Link
Server stores ciphertext only; decryption key stays in the client `#` fragment — zero knowledge
Vault
Saved items are encrypted at rest; plaintext passwords are never persisted

FAQ

A few straight answers before you put sensitive data into PassAfer.

Are passwords and files uploaded?

Password generation, audit, privacy tools, and the file box run in the browser. Plaintext, passphrases, and original files are not uploaded as business data. Burn-Link only uploads ciphertext; the decryption key stays on the client.

What works without signing in?

Random and passphrase password generation (including copy/export). Password Audit, privacy tools, burn-link creation, the file box, and the vault require sign-in.

What is Burn-Link? Does the recipient need an account?

A zero-knowledge one-time share link. Creating one requires sign-in; recipients open the read page with no account. After the first successful read, the secret is destroyed.

How does Password Audit detect weak passwords?

It estimates entropy and character classes locally, and checks a built-in weak-password blacklist from public breach lists. The password under test never leaves your browser.

Start with one strong password — locally

No client install. Use the generator right away; sign in when you need the rest of the stack.

Open password generator