Free local check

See the obvious risks in a policy before it ships.

Paste an S3 bucket policy or IAM policy. The seven deterministic checks run in your browser. Your policy never leaves this page, no model sees it, and we never call your AWS account.

01

Paste one policy

0 / 262,144 bytes

S3 bucket policies and IAM identity policies are supported. Maximum 256 KiB.

Loading the local analyzer…

02

Review the findings

Findings will appear here with the exact statement path, matched evidence, and a concrete remediation.

    Know the boundary

    A focused check, not a security verdict.

    The analyzer checks public principals, action wildcards, overbroad resources, missing aws:SecureTransport, IAM privilege escalation, public ACL grants, and NotResource expansion. It uses exact-string matching, so patterns such as iam:Attach*Policy are not caught. It counts statements rather than risk, does not model Deny/Allow interplay, and is not AWS Access Analyzer or a penetration test.