🔒 100% Private & Client-Side

Generate a clear password policy in one click

Flassword builds a plain-text password policy from a few simple choices — a solid starting point for your team, your app, or your handbook.

Start from a preset Then adjust anything below
Minimum length NIST recommends 8 minimum, 12+ ideal
12
Require uppercase letters A-Z
Require lowercase letters a-z
Require numbers 0-9
Require symbols !@#$% etc.
Password history Previous passwords blocked from reuse
off
Maximum password age Modern guidance favors no forced expiry
Account lockout threshold Failed attempts before temporary lock
10
Require multi-factor authentication Strongly recommended
Generated policy
Generated locally in your browser — never stored, never transmitted. Not legal or compliance advice.

A sensible starting point, not a rigid template

Built around widely published public guidance, fully yours to adjust.

Guidance-aligned presets

Start from a preset loosely aligned with NIST, PCI DSS, or HIPAA-style practice, then adjust every rule.

Fully customizable

Every rule — length, history, lockout, MFA — is a simple control you can tune to your own risk tolerance.

Private by design

Everything happens locally in your browser. Nothing about your policy choices is ever sent to a server.

Frequently asked questions

Everything you might want to know about the policy generator.

It's a well-informed starting point, not legal advice. The presets loosely follow widely published public guidance (NIST SP 800-63B, common PCI DSS and HIPAA practice), but compliance requirements vary by industry, region, and auditor. Have your final policy reviewed by whoever owns compliance at your organization.

Modern NIST guidance moved away from mandatory periodic password expiration because it tends to push people toward small, predictable variations of the same password, which is easier to guess, not harder. Forced rotation is now recommended only after evidence of an actual compromise.

It's optional rather than essential. Length contributes more to real entropy than symbol requirements do, and overly strict composition rules often push people toward predictable patterns. A generous minimum length paired with a password manager is generally more effective than a long list of character requirements.

Yes. The output is plain text, so you can paste it into any document editor, adjust the wording, add your organization's name, and fold it into an existing employee handbook or security policy document.

No. The policy text is generated locally in your browser from the options you choose, and nothing is transmitted to a server or saved anywhere on our end.

More free tools

The same private, client-side approach for everything else you need to generate.