Find the weak and reused passwords, without handing them over
An audit that ranks your saved logins by how much trouble each one is — and does it without a password, a hash of one, a username or a site name ever leaving your phone. Your device measures. The server decides. Neither step needs the other to see the secret.
Illustrative preview — a look at the interface.
The problem
Every password checker faces the same contradiction: to tell you a password is weak, something has to look at it. Send it to a server and the vault’s promise is broken. Judge it only on the phone and a modified app can report that everything is fine — which is exactly what a compromised device would do.
How it works
Split the job. The phone measures: how much entropy each password has, which ones are identical to each other, how long since each changed. What travels is an item id, a bit count, a group number and a day count — numbers with nothing recoverable in them. The scoring engine on the server ranks those numbers, because a verdict computed on a device you no longer trust is not a verdict.
How it works
Password Health, step by step
Measure
Your unlocked vault is read on the device. Each password gets an entropy estimate and a reuse group.
Send numbers
Only the measurements travel. There is no field in the request that could carry a password even if the app tried.
Rank
The server sorts findings by severity — reuse above weakness, because a strong password on six sites still fails when any one of them is breached.
Fix
Work down the list. Re-run the audit and watch the findings close.
What you’ll get
Built the NexGuard way
Reuse outranks strength
A 90-bit password used on three sites is a bigger problem than a mediocre one used once. The ranking says so.
Entropy, not composition rules
“One capital and one digit” accepts Password12 and rejects a four-word passphrase. We measure how much guessing it takes instead.
Age never stands alone
Being old is not a security finding — forced rotation was dropped from the NIST guidance years ago. Age only sharpens something already weak or reused.
Privacy first
Designed to protect, never to snoop
The audit sends an item id, a number of bits, an arbitrary group integer and an age in days. It cannot send a password, a hash of one, a username or a website — not as a matter of policy, but because there is nowhere in the request to put them.
How NexGuard protects your dataQuestions
Password Health, explained
How can you score a password you cannot see?
How do you detect reuse without comparing passwords?
Why not just score it on the phone?
What score does an empty vault get?
Get early access
Get Password Health with NexGuard
Password Health is part of NexGuard — start on the Free plan with no card, and upgrade only if you want higher limits and the advanced engines.