01 / The purpose

Useful tools should
be within reach.

NestCipher is a free, open security toolkit. Developers and security researchers should be able to inspect an email, review a website's security headers, or learn about LLM risks without a paywall or an account.

The aim is to make the evidence easier to examine: show what was observed, explain why it matters, and give the next step a clear place in the interface.

Explore the toolkit

02 / The person behind it

Built by Gancho.

I'm Gancho — a web developer and cybersecurity enthusiast based in Surrey, UK. I built NestCipher because I wanted free, well-designed security tools that don't gate useful functionality behind sign-ups or paywalls. Every tool here is something I'd actually use myself.

03 / A design case study

An identity with
something to show.

The redesign had two jobs: make the existing tools easier to use and give the project a distinctive identity that could stand as a portfolio piece. That required more than changing an accent colour.

  1. Question the first answers.

    Two initial directions were rejected: a graphite and citron editorial layout, then an orange technical workbench. Both helped clarify the brief: a bolder identity, recognisable typography, and evidence of real craft.

  2. Study the original sources.

    Pentagram's Oxide identity shows how a technical visual language can extend across a product. Google PAIR's Explorables show how an interaction can explain a relationship. The lesson for NestCipher was to connect its identity to something visitors can inspect.

  3. Build three real alternatives.

    Signal, Evidence Bureau, and Cipher Atlas explored different type, colour, and composition. Each prototype used the same three tool destinations and working synthetic email examples, so the comparison could focus on the design.

  4. Choose Signal. Carry it through.

    Signal was selected for its bold condensed type, solid lime and ink planes, and geometric boundary mark. Barlow Condensed gives the identity its voice; Barlow and DM Mono keep the reading and evidence clear. The selected system is integrated across the toolkit and field guide.

Prototype review / measured implementation checks

206 scoped checks passed across the three concepts and comparison board. They covered responsive geometry, control sizes, contrast, fixture output, keyboard state, reduced motion, and readable defaults without JavaScript.

These are prototype implementation checks. No participant user study was run. The integrated application is verified separately with production builds and browser tests for navigation, filtering, tool handoff, report display, and keyboard interaction.

The example inspector runs the toolkit's deterministic email prepass on clearly labelled synthetic inputs. It makes the source, displayed text, destination, and findings visible. A flag is evidence to investigate, rather than a final verdict.

04 / Under the hood

The details matter.

Interface design, application development, and security engineering meet in the finished tools. These are concrete implementation choices that can be examined in the source.

01 / Request boundaries

Inspect a URL without trusting it.

The headers scanner checks destinations before fetching them, using SSRF safeguards to restrict access to private network addresses. A per-request nonce and content security policy define the site's script boundary.

02 / Structured analysis

Turn a response into a usable report.

Email analysis uses a validated response schema. The interface presents a score alongside the reasons and recommendations, and renders returned content as text.

03 / Interface resilience

Make the small interactions hold up.

Search and filters work together. Reports handle long values on small screens. Reference content renders before JavaScript, with keyboard focus, labelled inputs, and clear status messages.

04 / Private research continuity

Carry the evidence without losing the context.

The Research Workbench keeps historical conditions beside exact inputs and observations. Explicit encrypted local saving, validated backups, report attachments and private Markdown exports support longer sessions. Concurrent save checks and draft replacement controls protect ongoing work. Encryption protects stored content; it does not protect an unlocked page from compromised code.

05 / Inspectable teaching

Make the reasoning part of the interface.

Three authored labs turn source authority, action evidence and controlled comparisons into decisions a visitor can inspect. An exact permission check, a revealed action record and explicit unknown conditions make each lesson concrete. Prepared private experiments carry the question forward with empty observations. These invented examples teach a method; they do not claim to measure a model's robustness.

Explore the learning labs
Explore the implementation

05 / Keep it useful

Feedback shapes
what comes next.

Got feedback, ideas, or just want to say hi? Reach out at hello@nestcipher.com.