lab

lab · by fin1te

Browser tools for data and platform engineers. Nothing you paste leaves the page.

Small tools for the things you can't paste into a SaaS product: production CronJobs, table definitions, event schemas. Each one is a static page that does its work in your browser, and the page isn't allowed to talk to any server once it has loaded.

Private by construction

What stays in your browser, and how to check.

Built for engineers at banks, telcos and government shops, where pasting production config into a web tool is a policy breach. The promise is enforced by the browser, not by a privacy page.

  1. 01

    There is no server to send to

    The site is static files on Cloudflare's CDN. No API, no backend, no database, no logs of what you type, because nothing you type is ever in a request.

  2. 02

    The browser refuses outgoing connections

    Every page carries a Content Security Policy with connect-src 'none'. Fetch, XHR, WebSockets and beacons are blocked, even for a buggy or injected script. Scripts, styles and fonts load only from this site.

  3. 03

    No analytics, cookies or third parties

    No tracking pixel, no consent banner, no fonts or scripts from anyone else's domain. The fonts are served from here.

  4. 04

    Your input stays on your machine

    It autosaves to this browser's local storage and to the part of the address after the #, compressed. Browsers never send that fragment to a server, so a copied link carries your input with nobody in between seeing it. Your own browser history keeps it too, so use a private window for anything that shouldn't sit there.

  5. 05

    Check it yourself

    Open your browser's developer tools on the Network tab, paste something, and watch nothing happen. Or read the Content-Security-Policy header on any response.