Pwned Password Check

We never send your password to our server. Your browser hashes it with SHA-1, sends only the first 5 hex characters to HIBP, and checks locally.

No password is stored.
Disclaimer: These tools query publicly available HIBP and DNS endpoints. Use them only to check your own data. We don’t store your input or results on our server. Password checks use k-anonymity; your full password never leaves your browser.