Free · no sign-up · open source

Check it before you trust it.

Thirteen security tools we use ourselves, opened to everyone. Paste a link, drop a file, scan a QR code or type an IP — and get a plain answer in seconds.

  • Private by designFiles and passwords never leave your browser.
  • Open dataabuse.ch, Spamhaus, Tor, RDAP, Have I Been Pwned.
  • Built in BengaluruBy the Arventiq Labs security team. MIT licensed.

Before you click or pay

For everyone. Most fraud starts with a link, a QR code or an attachment.

Your accounts and privacy

Passwords, breaches and what your connection reveals.

For IT teams, institutions and analysts

The checks we run during engagements, made self-service.

Why we built these

Every week someone in our network — a student, a parent, an administrator at a college we work with — forwards us a message and asks “is this real?”. Usually it takes two minutes and the same handful of checks. These pages are those checks, written down and automated, so you can run them yourself at 11 pm without waiting for a reply.

They are deliberately simple. A tool tells you what it found and why it matters; it will not pretend to certainty it does not have. When a check says “no red flags”, read it as “nothing we test for”, not “safe”.

How they work

  • Nothing you upload is stored. Attachments and passwords are processed on your device. For breach checks we send five characters of a hash, not the password.
  • We fetch links from our server, never from your browser, so a malicious site does not see you.
  • Threat data is open and credited on every result.
  • Rate limits apply (40 checks per network per 10 minutes) so the tools stay available to everyone.
  • Open source on GitHub, MIT licence. Fixes and ideas welcome.

Changes

2 Oct 2026
Added QR, UPI, breach exposure, domain check, download verifier, decoder and “what the internet sees”. Passphrase generator on the password page. Tools moved to the main menu.
1 Oct 2026
First release: link, attachment, IP, password and email-header checkers.

Known limits: the breach-exposure search needs an API key we are still arranging; VirusTotal and AbuseIPDB rows show “Not enabled” until keys are added; the QR decoder needs a reasonably sharp photo.

Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.