Digital Safety Toolkit

Check before you click

Practical checks that run entirely on your own device. Nothing you type here is uploaded, stored or transmitted — there is no server involved.

Privacy by design All analysis happens in your browser using local JavaScript. You can disconnect from the internet and every tool on this page still works.

🔑 Password Strength Analyser

Measures search-space entropy and checks for the patterns attackers try first.

🔗 Suspicious URL Inspector

Structural analysis for lookalike domains, brand mismatch, punycode, shorteners and direct file downloads.

Limits of this check A clean structural result does not mean a link is safe — compromised legitimate sites and newly registered domains look fine structurally. The reliable rule stays: reach login pages from your bookmarks or the official app, never from a link.

📧 Phishing & Scam Message Analyser

Scores a message against the lure patterns used in Indian and global fraud — OTP requests, remote-access instructions, urgency, advance fees and authority threats.

📊 Security Score

Two minutes, honest answers. The result is a gap list you can act on, not a grade.

View record

📷 QR Code Safety Guide

The single rule

Scanning a QR code and entering a PIN always sends money. It can never receive money. Anyone asking you to scan a code "to get your refund" is stealing from you.

  • Preview the URL before opening anything a QR resolves to
  • Check the payee name on the confirmation screen before approving
  • Never scan codes from e-mails, posters, parking meters or DMs to reach a login page
  • Treat QR codes in printed letters claiming to be from banks or government as hostile

For merchants

  • Laminate and tamper-seal your QR standee; photograph it and check daily
  • Enable soundbox and SMS confirmation, and reconcile at close of business
  • Train staff that a customer's "payment successful" screenshot is not proof
  • Report a swapped code to your acquirer and to 1930 immediately

Full QR fraud profile →

🎭 Deepfake Awareness Guide

Assume it can be faked

Voice cloning needs seconds of audio. Real-time video deepfakes work on calls. A familiar voice or face is no longer identity verification.

Verify by channel, not by senses

Hang up and call back on a number you already had saved. For business payments, use an out-of-band callback plus a second approver.

Set a safe word today

Agree a family phrase that never appears online. No money moves in an emergency without it — including for elderly parents and students living away.

Live-call tells (useful, not reliable)

  • Ask them to turn their head fully sideways or pass a hand across the face
  • Ask for a specific unpredictable action or phrase
  • Listen for absent background noise and flat, consistent emotion
  • Watch for lip-sync drift and shifting edges around the jaw and hair

If synthetic content of you is circulating

  • Report at cybercrime.gov.in — intimate imagery must be removed within 24 hours under the IT Rules
  • Submit hashes at stopncii.org to block re-uploads across participating platforms
  • Preserve URLs and screenshots before requesting removal
  • Tell the people it will be sent to, first — that removes the extortion leverage
  • Do not pay. Call Tele-MANAS 14416 if you are in distress

Full deepfake & AI voice fraud profile →

Nothing you type here leaves your device Every tool on this page runs entirely in your browser. Passwords, links and messages you paste are never sent to HAPSA or anyone else, there is no logging, and the page keeps working with your connection switched off — which is the point for schools and rural centres. Want these tools running inside your organisation? Talk to us.