Password Generator
Strong, random passwords with adjustable length and character types.
Open tool →Flassword builds a plain-text password policy from a few simple choices — a solid starting point for your team, your app, or your handbook.
Built around widely published public guidance, fully yours to adjust.
Start from a preset loosely aligned with NIST, PCI DSS, or HIPAA-style practice, then adjust every rule.
Every rule — length, history, lockout, MFA — is a simple control you can tune to your own risk tolerance.
Everything happens locally in your browser. Nothing about your policy choices is ever sent to a server.
Everything you might want to know about the policy generator.
It's a well-informed starting point, not legal advice. The presets loosely follow widely published public guidance (NIST SP 800-63B, common PCI DSS and HIPAA practice), but compliance requirements vary by industry, region, and auditor. Have your final policy reviewed by whoever owns compliance at your organization.
Modern NIST guidance moved away from mandatory periodic password expiration because it tends to push people toward small, predictable variations of the same password, which is easier to guess, not harder. Forced rotation is now recommended only after evidence of an actual compromise.
It's optional rather than essential. Length contributes more to real entropy than symbol requirements do, and overly strict composition rules often push people toward predictable patterns. A generous minimum length paired with a password manager is generally more effective than a long list of character requirements.
Yes. The output is plain text, so you can paste it into any document editor, adjust the wording, add your organization's name, and fold it into an existing employee handbook or security policy document.
No. The policy text is generated locally in your browser from the options you choose, and nothing is transmitted to a server or saved anywhere on our end.
The same private, client-side approach for everything else you need to generate.
Strong, random passwords with adjustable length and character types.
Open tool →See entropy, crack-time estimates, and tips for any password you type.
Open tool →Check if a password has appeared in a known data breach, privately.
Open tool →