← All Tools

IAM Policy Analyzer

Your policy said *:*. That’s an all-you-can-eat buffet for attackers. Paste an AWS, Azure or GCP policy and get a grade, the findings in plain English, and a least-privilege starting point.

🔒 Nothing you paste here is sent anywhere. The analysis runs in this tab; there is no endpoint behind this page — check your browser’s network tab. Nothing is written to browser storage: an IAM policy reveals your account structure and it stays in memory only.
Load example:
⚠ Advisory only. The rules (2026-09-19.1, 22 checks) catch the common over-grants, not every escalation path; a clean grade is not an authorisation review. Tools are provided for educational and authorized use only.