MyPassGen
Security notes: AES-256-GCM and browser-local encryption
What we compute, where it runs, and what never leaves the device. Every tool opens without an account.
These are the constraints the product is built on. Expand a row for the exact rule.
Rules you can verify on this device
No alternate ciphers. Authenticated encryption for files and burn-link payloads.
Plaintext, keys, and files stay on the device by default. Nothing is uploaded for generation, strength checks, URL cleaning, or file encryption.
Fragments are not sent with the HTTP request. The server can hold ciphertext; it does not receive the key.
No registration for any tool. Recipients of a one-time secret also do not need an account.
Random mode defaults to 16 characters and warns below 8. File encryption writes .lock or .enc.