§ masterplan.md
Cybersecurity Toolkit
A dark-premium suite of small security tools: password strength checker, breach scanner and privacy checklist.
01
App overview and objectives
A suite of small, trustworthy security self-checks for ordinary people and small teams: password strength, breach exposure, a hardening checklist and short lessons. Everything runs with the least data possible.
02
The problem worth solving
Most people know they are insecure but not what to fix first. Ranked, concrete, free checks convert vague anxiety into a short list of actions.
03
Target audience
- Primary — Non-expert individuals and small business owners.
- Secondary — IT volunteers and trainers running awareness sessions.
04
Roles and permissions
- Visitor — read-only public pages, can sign up.
- Member — owns their own records, cannot see other users' data.
05
Core features
- Password strength analyser that never transmits the password
- Breach exposure check using k-anonymity so the full email or hash never leaves the device
- Personalised hardening checklist by role and device
- Short lessons on phishing, two-factor authentication and backups
- Printable summary report for a team
- Tool index with clear explanations of what each check does and does not do
Deliberately later
- Team dashboards
- Scheduled re-checks
- Local-language content packs
06
Technical stack
React with client-side cryptography, a thin server proxy for breach lookups, no user accounts by default.
Why: The product's credibility rests on not collecting secrets — computing locally is a feature, not an optimisation.
Alternatives: Server-side scanning (more capable, requires trusting you with secrets) or browser extension (deeper checks, store friction).
07
Conceptual data model
CheckDefinition — id, name, description, risk weight, remediation steps
ChecklistResult — anonymous session, answers, score, generated actions
Lesson — topic, body, difficulty, estimated minutes
BreachSource — name, date, record count, description
08
Integrations
- Breach data API supporting range queries
- Static content for lessons
- PDF export
09
UI design principles
- Deep neutral background, one saturated accent, thin borders instead of heavy cards.
- Monospace for data and code; tight, technical spacing.
- Subtle glow and gradient only where you want the eye to land.
10
Security considerations
- Passwords are hashed locally; only a five-character hash prefix is ever sent.
- No analytics on input fields, no session recording, strict content security policy.
- Publish the threat model and what the tool cannot detect.
11
Development phases
Phase 1 — Prove the core
- — Password strength analyser that never transmits the password
- — Breach exposure check using k-anonymity so the full email or hash never leaves the device
- — Personalised hardening checklist by role and device
- — Static content and design system in place
- — Basic analytics
Phase 2 — Make it real
- — Short lessons on phishing, two-factor authentication and backups
- — Printable summary report for a team
- — Tool index with clear explanations of what each check does and does not do
- — Accounts, sign-in and password reset
- — Empty, loading and error states everywhere
Phase 3 — Polish and launch
- — Performance, accessibility and SEO pass
- — Legal pages, contact route and 404 handling
- — Wire up: Breach data API supporting range queries
- — Wire up: Static content for lessons
Phase 4 — Grow
- — Team dashboards
- — Scheduled re-checks
- — Local-language content packs
12
Challenges and solutions
Risk — Users distrust a security site asking for their password
Solution — Explain the local-only design in one sentence with a link to the open source and network tab proof.
Risk — False sense of safety
Solution — Show residual risks explicitly and never display a perfect score.
Risk — Breach data licensing
Solution — Use a provider whose terms allow public non-commercial lookups, and cache responsibly.
13
Future expansion
- Small business compliance starter kits
- Phishing simulation for teams
- Community-translated lessons
14
Page list (13 pages)
- 01 PUBLIC Tools — Index of all checks with plain descriptions.
- 02 AUTH Password Check — Local strength analysis and guidance.
- 03 PUBLIC Breach Scan — Privacy-preserving exposure lookup.
- 04 PUBLIC Checklist — Personalised, ranked actions.
- 05 PUBLIC Learn — Short lessons and threat explainers.
- 06 AUTH Sign up — Create an account with email or a social provider.
- 07 AUTH Log in — Return to the account, with error and lockout states.
- 08 AUTH Reset password — Request a reset link and set a new password.
- 09 APP (signed in) Account settings — Profile, email, password, language and delete account.
- 10 PUBLIC Contact — Contact form plus real address, phone and email.
- 11 LEGAL & SYSTEM Privacy policy — What data is collected, why, and how to remove it.
- 12 LEGAL & SYSTEM Terms of service — Rules of use, liability and account termination.
- 13 LEGAL & SYSTEM 404 not found — Friendly dead end with search and links back.
15
Page map
PUBLIC AUTH APP (signed in) LEGAL & SYSTEM ────────────── ───────────────── ─────────────────── ─────────────────── ├─ Tools ├─ Password Check └─ Account settings ├─ Privacy policy ├─ Breach Scan ├─ Sign up ├─ Terms of service ├─ Checklist ├─ Log in └─ 404 not found ├─ Learn └─ Reset password └─ Contact key flows: Tools ──▶ Password Check Tools ──▶ Breach Scan Breach Scan ──▶ Checklist Checklist ──▶ Learn
