Free · no sign-up · open source

Check it before you trust it.

Thirteen security tools we use ourselves, opened to everyone. Paste a link, drop a file, scan a QR code or type an IP — and get a plain answer in seconds.

  • Private by designFiles and passwords never leave your browser.
  • Open dataabuse.ch, Spamhaus, Tor, RDAP, Have I Been Pwned.
  • Built in BengaluruBy the Arventiq Labs security team. MIT licensed.

Before you click or pay

For everyone. Most fraud starts with a link, a QR code or an attachment.

Your accounts and privacy

Passwords, breaches and what your connection reveals.

For IT teams, institutions and analysts

The checks we run during engagements, made self-service.

Watch the tools work

Eleven short screen recordings of the tools on this site. Press play on any of them. The examples are made up; the checks are the real ones.

What happens when you press Check

Most of the work happens on your own device. Only what has to be looked up on the internet reaches our server, and nothing you check is stored.

What happens when you press CheckYour input is analysed in your browser first; only links, IPs and domains go to our server, which looks them up in DNS, RDAP and open threat feeds and returns a verdict with reasons.You paste or dropa link, file, QR or UPI IDYour browserfiles and passwords stay hereOur serverDNS · RDAP · redirectsOpen threat dataURLhaus · Spamhaus · TorVerdict + reasonswhat we found, and whyNever uploadedNo cookies, nothing storedEvery source credited

Seen a scam? Report it.

A fake refund request, a phishing link, a threatening call, a server hammering yours. Tell us the UPI ID, number, link, IP or email behind it. Reviewed by our team; the next person who checks it here sees a warning.

Report a scam →

Why we built these

Every week someone in our network — a student, a parent, an administrator at a college we work with — forwards us a message and asks “is this real?”. Usually it takes two minutes and the same handful of checks. These pages are those checks, written down and automated, so you can run them yourself at 11 pm without waiting for a reply.

They are deliberately simple. A tool tells you what it found and why it matters; it will not pretend to certainty it does not have. When a check says “no red flags”, read it as “nothing we test for”, not “safe”.

How they work

  • Nothing you upload is stored. Attachments and passwords are processed on your device. For breach checks we send five characters of a hash, not the password.
  • We fetch links from our server, never from your browser, so a malicious site does not see you.
  • Threat data is open and credited on every result.
  • Rate limits apply (40 checks per network per 10 minutes) so the tools stay available to everyone.
  • Open source on GitHub, MIT licence. Fixes and ideas welcome.

Changes

3 Oct 2026
Community reports: anyone can report a scam UPI ID, phone number, link, IP or email; confirmed reports show as warnings in the UPI, link and IP checkers. The UPI checker now shows the registered account name, the same lookup your payment app does.
2 Oct 2026
Added QR, UPI, breach exposure, domain check, download verifier, decoder and “what the internet sees”. Passphrase generator on the password page. Tools moved to the main menu.
1 Oct 2026
First release: link, attachment, IP, password and email-header checkers.

Known limits: the breach-exposure search needs an API key we are still arranging; VirusTotal and AbuseIPDB rows show “Not enabled” until keys are added; the QR decoder needs a reasonably sharp photo.

Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.