Free local check
See the obvious risks in a policy before it ships.
Paste an S3 bucket policy or IAM policy. The seven deterministic checks run in your browser. Your policy never leaves this page, no model sees it, and we never call your AWS account.
- Runs on this device
- No upload or storage
- No AWS credentials
01
Paste one policy
S3 bucket policies and IAM identity policies are supported. Maximum 256 KiB.
Loading the local analyzer…
02
Review the findings
Know the boundary
A focused check, not a security verdict.
The analyzer checks public principals, action wildcards, overbroad resources, missing
aws:SecureTransport, IAM privilege escalation, public ACL grants, and
NotResource expansion. It uses exact-string matching, so patterns such as
iam:Attach*Policy are not caught. It counts statements rather than risk, does
not model Deny/Allow interplay, and is not AWS Access Analyzer or a penetration test.