IRONROOT is a unified threat intelligence dashboard that bundles the most useful cybersecurity tools into a single, free web application. Everything runs in your browser — no backend servers process your queries, and nothing is logged or stored externally.
All processing happens in your browser. Your data never touches our servers. Queries go directly from your browser to public APIs.
Every tool uses free, public APIs that require no signup or authentication. Google DNS, IANA RDAP, crt.sh, NIST NVD, ip-api — all open.
DNS intelligence, WHOIS lookup, subdomain enumeration, breach scanning, SSL inspection, CVE search, hash generation, and more.
Use every tool without signing up. Optionally create an account to save preferences and track assets across sessions via localStorage.
Organized into five categories. Click any tool name to jump directly to it.
IRONROOT connects to these free, public APIs. No keys or authentication required for any of them.
DNS-over-HTTPS for all record type queries. Fast, reliable, global.
Registration Data Access Protocol for WHOIS-style domain lookups.
Certificate Transparency log aggregator for subdomain enum and SSL checks.
IP geolocation, ASN, ISP, and proxy/VPN detection.
National Vulnerability Database for CVE search and tracking.
Browser-native cryptographic hashing (SHA-1, SHA-256, SHA-512).
Common questions about how IRONROOT works.
Yes. IRONROOT runs entirely in your browser. When you query a domain or IP, the request goes directly from your browser to the public API — our servers are never involved. Saved preferences use your browser's localStorage only.
The breach scanner uses a simulated local database for demonstration. It does not query actual breach databases like Have I Been Pwned. Results are deterministic (same email = same results) but not real breach data.
Some APIs (like direct HTTP header inspection) can't be accessed from a browser due to Cross-Origin Resource Sharing restrictions. This is a browser security feature, not a bug. The tool will explain when this happens.
No. Every tool works without an account. Creating an account lets you save monitored assets and track scan history across sessions, but it's entirely optional and stored locally.
Yes. IRONROOT is a single HTML file with no build step, no dependencies, and no backend. Download it and open it in any browser, or host it on any static file server.
Simulated real-time global attack data for demonstration purposes.
All tools free. No API keys. No authentication required.
NIST National Vulnerability Database. Live API, no key.
Security overview
Security posture analysis
No account? Create