Paste your AWS IAM policy. We'll pull its priors, file the charges, and tell you exactly how bad it is — with jokes.
SAMPLE CASE FILE
THREAT LEVEL 10/10AKA: The All-You-Can-Eat Buffet
"You gave a Lambda function full account admin. That's not a function, that's a toddler with the nuclear launch codes and a snack."
EXHIBIT A — SUBMITTED POLICY
🔒 Nothing is saved. Your policy is analyzed right here in your browser — a generic issue summary is sent to our server to write the joke, and your raw policy text is forwarded only to AWS's own policy validator, then discarded immediately.
This page has no database, no login, and no server that stores anything — refresh, and every trace of your last roast is gone.
Your policy is parsed and checked entirely in JavaScript running in your browser. That step never leaves your device.
To write the joke, only a short summary of the issue types found (like "Public Resource Exposure") is sent to our backend, which forwards it to Claude — never your raw policy text, account IDs, or resource names reach the AI.
Your raw policy text is sent to our backend, but only so it can be checked against AWS's own official IAM Access Analyzer validator (to catch invalid action names or condition keys AWS itself would reject). Our server forwards it to AWS and discards it immediately afterward — never logged, never stored, and never passed to Claude in raw form.
You can verify the client-side half yourself: this is a single, unminified HTML file. Right-click → View Page Source, or open your browser's Network tab while you roast something, and confirm exactly what leaves your browser and where it's headed. What our server does with it after that isn't something page-source-viewing can prove — so we're just telling you plainly: we don't log it, we don't store it.
CHARGES FILED
COUNT-BY-COUNT BREAKDOWN
OFFICER'S RECOMMENDATION
For entertainment only — not a security audit. Your real security tool is still out there doing the actual work (and definitely judging you less).