Skip to main content

§ masterplan.md

Cybersecurity Toolkit

A dark-premium suite of small security tools: password strength checker, breach scanner and privacy checklist.

All ideas
Dark Premium

01

App overview and objectives

A suite of small, trustworthy security self-checks for ordinary people and small teams: password strength, breach exposure, a hardening checklist and short lessons. Everything runs with the least data possible.

02

The problem worth solving

Most people know they are insecure but not what to fix first. Ranked, concrete, free checks convert vague anxiety into a short list of actions.

03

Target audience

  • Primary — Non-expert individuals and small business owners.
  • Secondary — IT volunteers and trainers running awareness sessions.

04

Roles and permissions

  • Visitor — read-only public pages, can sign up.
  • Member — owns their own records, cannot see other users' data.

05

Core features

  • Password strength analyser that never transmits the password
  • Breach exposure check using k-anonymity so the full email or hash never leaves the device
  • Personalised hardening checklist by role and device
  • Short lessons on phishing, two-factor authentication and backups
  • Printable summary report for a team
  • Tool index with clear explanations of what each check does and does not do

Deliberately later

  • Team dashboards
  • Scheduled re-checks
  • Local-language content packs

06

Technical stack

React with client-side cryptography, a thin server proxy for breach lookups, no user accounts by default.

Why: The product's credibility rests on not collecting secrets — computing locally is a feature, not an optimisation.

Alternatives: Server-side scanning (more capable, requires trusting you with secrets) or browser extension (deeper checks, store friction).

07

Conceptual data model

CheckDefinition — id, name, description, risk weight, remediation steps

ChecklistResult — anonymous session, answers, score, generated actions

Lesson — topic, body, difficulty, estimated minutes

BreachSource — name, date, record count, description

08

Integrations

  • Breach data API supporting range queries
  • Static content for lessons
  • PDF export

09

UI design principles

  • Deep neutral background, one saturated accent, thin borders instead of heavy cards.
  • Monospace for data and code; tight, technical spacing.
  • Subtle glow and gradient only where you want the eye to land.

10

Security considerations

  • Passwords are hashed locally; only a five-character hash prefix is ever sent.
  • No analytics on input fields, no session recording, strict content security policy.
  • Publish the threat model and what the tool cannot detect.

11

Development phases

Phase 1 — Prove the core

  • — Password strength analyser that never transmits the password
  • — Breach exposure check using k-anonymity so the full email or hash never leaves the device
  • — Personalised hardening checklist by role and device
  • — Static content and design system in place
  • — Basic analytics

Phase 2 — Make it real

  • — Short lessons on phishing, two-factor authentication and backups
  • — Printable summary report for a team
  • — Tool index with clear explanations of what each check does and does not do
  • — Accounts, sign-in and password reset
  • — Empty, loading and error states everywhere

Phase 3 — Polish and launch

  • — Performance, accessibility and SEO pass
  • — Legal pages, contact route and 404 handling
  • — Wire up: Breach data API supporting range queries
  • — Wire up: Static content for lessons

Phase 4 — Grow

  • — Team dashboards
  • — Scheduled re-checks
  • — Local-language content packs

12

Challenges and solutions

Risk — Users distrust a security site asking for their password

Solution — Explain the local-only design in one sentence with a link to the open source and network tab proof.

Risk — False sense of safety

Solution — Show residual risks explicitly and never display a perfect score.

Risk — Breach data licensing

Solution — Use a provider whose terms allow public non-commercial lookups, and cache responsibly.

13

Future expansion

  • Small business compliance starter kits
  • Phishing simulation for teams
  • Community-translated lessons

14

Page list (13 pages)

  1. 01 PUBLIC Tools — Index of all checks with plain descriptions.
  2. 02 AUTH Password Check — Local strength analysis and guidance.
  3. 03 PUBLIC Breach Scan — Privacy-preserving exposure lookup.
  4. 04 PUBLIC Checklist — Personalised, ranked actions.
  5. 05 PUBLIC Learn — Short lessons and threat explainers.
  6. 06 AUTH Sign up — Create an account with email or a social provider.
  7. 07 AUTH Log in — Return to the account, with error and lockout states.
  8. 08 AUTH Reset password — Request a reset link and set a new password.
  9. 09 APP (signed in) Account settings — Profile, email, password, language and delete account.
  10. 10 PUBLIC Contact — Contact form plus real address, phone and email.
  11. 11 LEGAL & SYSTEM Privacy policy — What data is collected, why, and how to remove it.
  12. 12 LEGAL & SYSTEM Terms of service — Rules of use, liability and account termination.
  13. 13 LEGAL & SYSTEM 404 not found — Friendly dead end with search and links back.

15

Page map

PUBLIC          AUTH               APP (signed in)      LEGAL & SYSTEM
──────────────  ─────────────────  ───────────────────  ───────────────────
├─ Tools        ├─ Password Check  └─ Account settings  ├─ Privacy policy
├─ Breach Scan  ├─ Sign up                              ├─ Terms of service
├─ Checklist    ├─ Log in                               └─ 404 not found
├─ Learn        └─ Reset password
└─ Contact

key flows:
  Tools ──▶ Password Check
  Tools ──▶ Breach Scan
  Breach Scan ──▶ Checklist
  Checklist ──▶ Learn