What is CipherGuard?
CipherGuard is a free password generator and checker. It runs in your browser.
CipherGuard
Generate strong passwords, passphrases, and PINs with WebCrypto; check strength and whether a password has been leaked in a breach — and none of it ever leaves your device. Runs in your browser — your passwords are never transmitted.
Create strong passwords, passphrases, PINs, and pronounceable secrets with WebCrypto.
Generate strong, random passwords with configurable length and characters. Powered by WebCrypto, with live entropy shown. 100% in your browser — never transmitted. Free.
Generate memorable 'correct-horse-battery-staple' passphrases from the EFF diceware wordlist. Choose your word count. Strong and easy to type. 100% in-browser. Free.
Generate passwords that are easy to read and say aloud but still strong, built from random syllables with WebCrypto. Easier to remember, hard to crack. 100% in-browser. Free.
Generate random numeric PINs from 4 to 8 digits for banking, phone, and SIM cards, with WebCrypto randomness. No patterns, no repeats. 100% in-browser. Free.
Generate dozens or hundreds of strong passwords at once with WebCrypto, then export the batch as CSV, JSON, or .zip. All in your browser — nothing is ever transmitted. Free + Pro.
Score a password's strength and check it against known data breaches — nothing leaves your device.
Check how strong your password really is with zxcvbn real-world scoring, an estimated crack-time, and plain-English tips. The password is NEVER transmitted. 100% in-browser. Free.
Check if your password appears in known data breaches using Have-I-Been-Pwned k-anonymity. Only a 5-char hash prefix leaves your device — your password NEVER does. 100% private. Free.
Validate a password against configurable NIST-style rules and a common-password blocklist.
Updated 17 August 2026
CipherGuard is a password tool. Checks use k-anonymity. Your full password stays on your device.
CipherGuard is a free password generator and checker. It runs in your browser.
No. Generation is local. Breach checks send only the first five characters of a SHA-1 hash to Have I Been Pwned.
k-anonymity means the API never sees your full hash. Many suffixes share the same prefix. Your browser checks the match locally.
No. Open a tool and start.
Yes, except the breach check, which needs the public HIBP API.