Use this for your own accounts or your organization's own policy — for example, checking a team's passwords against your company's password standard before a security review. Never run passwords you don't have authorization to test.
Define Your Policy
Banned words (comma or newline separated — e.g. your company or product name)
Test a Single Password
Start typing above to check it against your policy
Bulk Check
Check a whole list against this policy
Paste or Upload Passwords
One password per line, or a CSV with a password column (an optional username column is picked up automatically). Uses the policy defined above — change it any time and re-run.
Privacy
How this stays private
Every check runs locally against the policy you define in your browser — nothing is uploaded, logged, or transmitted, and closing or refreshing this tab discards everything, including your policy settings.
Sources & Standards
Where this tool's guidance comes from
This tool's defaults and recommendations are built on the following official, internationally recognized standards and guidance — not opinion. Each link goes directly to the source.
NIST
SP 800-63B-4 — Digital Identity Guidelines
The current federal reference policy — minimum length, no forced periodic rotation, mandatory breach screening.
csrc.nist.gov →
PCI SSC
PCI DSS v4.0 — Payment Card Industry Data Security Standard
The global payment-industry standard, whose password requirements (including 90-day rotation) differ from NIST's.
pcisecuritystandards.org →
ISO
ISO/IEC 27001:2022 — Information Security Management
The international standard for information security management systems, widely used as an audit baseline.
iso.org →
CISA
Use Strong Passwords
U.S. government guidance on password policy, referenced for the tool's built-in default policy presets.
cisa.gov →