Password checker
and breach verification

Check your password strength, entropy, and estimated crack time. Verify if it has been exposed in known data breaches. Generate secure passwords instantly.

Check your password security

Enter a password to analyse its strength, or generate a new secure one. All calculations are performed locally in your browser — nothing is sent to any server.

Password check

How it works: k-anonymity protocol

1

Your browser computes the SHA-1 hash of your password

Example hash: 5BAA61E4C9B93F3F0682250B6CF8331B7EE68FD8
2

Only the first 5 characters of the hash are sent to the API

5BAA61E4C9…FD8→ API
3

The API returns thousands of hashes that start with those 5 characters

1E4C9B93F3F068225...:3
0A2B5C7D8E9F01234...:152
9F8E7D6C5B4A30129...:47
... + migliaia di altri
4

Your browser checks locally if the full hash matches — nobody knows which password you checked

5BAA61E4C9…=

Generate secure password

4

All calculations are performed locally in your browser. No passwords are saved or transmitted to external servers, except for the breach check which uses the k-anonymity protocol from Have I Been Pwned.

Understanding password security

A strong password is your first line of defence against unauthorised access. Understanding how password strength is measured helps you make better choices when creating or updating your credentials.

Entropy

Measures randomness in bits. Higher entropy means more possible combinations and longer crack times.

Crack time

Estimated time to brute-force the password at 10 billion guesses per second (high-end offline attack).

Character variety

Using lowercase, uppercase, digits, and symbols increases the character set size and overall entropy.

Password length

Length has the greatest impact on security. Each additional character multiplies the number of possible combinations.

Data breaches

Even a strong password is unsafe if it has been leaked. The breach check uses Have I Been Pwned with k-anonymity.

Password managers

Use a password manager to generate and store unique passwords for every account, eliminating reuse risks.

For enterprise-grade identity protection including multi-factor authentication, SSO, and access governance, see our Digital Identity Management page.

Frequently asked questions about password security

Answers to common questions about password strength, breach checks, and best practices.

Protect your business identities

From multi-factor authentication to identity governance and access management: we help you secure every digital identity in your organisation. Contact us for a consultation.