Trust Center
Where Nexinon proves, live and in your own browser, the privacy and security it promises.
A principle, not an empty promise
Nexinon handles passwords, secrets and sensitive data every day — that's why, instead of asking you to trust us, this page shows you: the network monitor below is your own browser reporting what leaves your machine, and the two analyzers test nexinon.dev exactly as they would test any other site.
Live network monitor
Every network call made by this browser, captured in real time — not a claim, a witnessed proof.
No requests captured yet. Keep browsing Nexinon in this same tab — every network call shows up here, live.
Nexinon testing itself
The two analyzers below are already part of the catalog — here they run on their own against nexinon.dev itself, nothing to type.
security.txt
Published at /.well-known/security.txt (RFC 9116) — the standard channel the security community uses to report a vulnerability to any domain.
Open /.well-known/security.txtExecution transparency, tool by tool
Every tool in the catalog already declares this on its own page (local, server, or hybrid) — here it's all together, in a single table. Generated from the same registry that powers the Home page: it never goes stale on its own.
| Tool | Execution | Summary |
|---|---|---|
| Password Checker | Hybrid | nothing leaves your browser by default — the only exception is the optional leak check, under your explicit action. |
| Secret Share | Hybrid | everything is encrypted in your browser — not even Nexinon can read what you share. |
| Secret Request | Hybrid | the question and the response are encrypted in the browser — not even Nexinon can read them. |
| Anonymous Line | Hybrid | the question and each response are encrypted in the browser — not even Nexinon can read them. |
| Authenticity Seal | Hybrid | The file never leaves your browser — only a 32-byte hash is sent to the server. |
| DNS Lookup | Server | the domain you type goes to the server at query time — nothing is stored. |
| WHOIS | Server | the domain you type goes to the server at query time — nothing is stored. |
| SSL/TLS Checker | Server | the domain you type goes to the server at query time — nothing is stored. |
| Security Headers | Server | the URL you type goes to the server at analysis time — nothing is stored. |
| security.txt | Server | the domain you enter is sent to the server for the check — nothing is stored. |
| Is It Down? | Server | the URL you type goes to the server on check — nothing is stored. |
| Where Does It Go? | Server | our server visits the link, never your browser — nothing is stored. |
| Domain Health Report | Server | the domain you type goes to the server, which queries five sources — nothing is stored. |
| Mock API | Server | the pasted JSON and the management token stay on the Nexinon server until the mock expires. |
| IP Lookup | Server | the IP you query goes to the server at lookup time — nothing is stored. |
| Date Calculator | Hybrid | everything runs locally by default — the date range only reaches Nexinon's public API when "consider holidays" is checked. |
| Paste Share | Hybrid | by default, content is sent as plain text to the server; with encryption on, everything happens in your browser. |
| Brazilian Holidays | Server | holidays are fetched from Nexinon's own public API — nothing of yours is sent. |
| CEP Lookup | Server | the CEP/address you type is sent to our server, which queries ViaCEP — nothing is logged. |
| Exchange Rates | Server | the currency you choose is sent to our server, which queries the Central Bank — nothing is logged. |
| CNPJ Lookup | Server | the CNPJ you type is sent to our server, which queries BrasilAPI — nothing is logged. |
Proof, not promises
This page offers behavioral proof, observable at runtime, that you can verify again at any moment: the network monitor shows real traffic from your own session, the two analyzers run against the real domain, and security.txt is a genuine public file. None of this proof requires knowing how to read code.