Files
network-tools/public/docs/PRIVACY-SECURITY.md
T
2026-09-01 02:44:20 +02:00

968 B

Privacy and security

Network Tools has no runtime network operation. Entering a URL does not visit it; constructing a DNS record does not perform a DNS query; and the MIME reference is bundled in the app. There is no account, telemetry, analytics, persistence or imported active content.

Inputs and results stay in React memory until they are replaced or the page is closed. URL passwords are removed from the displayed resolved URL, but query strings, fragments and the original input remain visible and may still contain secrets. Header findings and generated CSP are advisory, not a complete security audit.

The URL parser rejects inputs above 16 KiB, the header parser rejects blocks above 256 KiB and obsolete folding/control characters, TXT character strings are limited to 255 UTF-8 bytes, and DNS names/numbers are syntax- and range-checked. These limits reduce accidental resource use; they do not make copied output trustworthy for an unrelated system.