← All Tools

LLM Output Scanner

The model answered. Before that answer goes into a ticket, a report or a customer's inbox: did it reproduce someone's e-mail, IBAN or an API key from its context, and which of its confident citations has a human actually opened? Paste the output, get the sensitive values masked and every reference as a checklist.

🔒 Nothing you paste here leaves this page. Verifiably. The scan runs in your browser with static rule sets; this page has no server endpoint, stores nothing (no draft, no history, no localStorage) and hands nothing to other tools. Open the developer tools on the Network tab, paste a real answer, press Review: no request. That is also why the citation check is a checklist, not a verdict — the page cannot fetch a URL or resolve a DOI, and does not pretend to.

Why the output side is different. The LLM Pre-flight Redactor stops you sending sensitive data into a model. This tool looks at what came out: a model can reproduce a customer's e-mail or an access key it saw in the retrieved documents, the conversation, or its training data, and it can cite a paper, a URL, a CVE or a regulation article that does not exist or does not say what it claims (OWASP LLM Top 10: Sensitive Information Disclosure, Improper Output Handling, Misinformation — see the OWASP LLM Top 10 Checker). Personal data comes from the same detector library as the Pre-flight Redactor and the Log Snippet Anonymizer; credentials from the same rule set as the Secrets & Credential Leak Scanner. Regulatory articles link to the Compliance Reference Database so you can read the article the model quoted; CVEs link to NVD, DOIs to doi.org, RFCs to the RFC Editor. Rule sets . Informational only: a citation the tool lists is neither confirmed nor refuted, and text with nothing flagged can still be wrong.