Item logo image for tardisec

tardisec

Item media 1 (screenshot) for tardisec

Overview

Browse your own site with its recommended security headers applied, one domain at a time. See what breaks before you enforce it.

Apply stricter security headers to your own site as you browse it, and read the violation reports the browser raises. One domain at a time, and only the domains you switch on. While a domain is switched on, the toolbar icon carries a badge: `i` (blue) while it is only monitoring, `!` (red) while it is enforcing a policy that can break the page. ## What it does on a domain you switch on - **Report-Only (default)** applies the report-only twins of the recommended headers. Additive monitoring, it cannot break the page. - **Enforce strict** applies the enforcing headers, so you can see exactly how the site would break under the real policy. What gets enforced depends on whether you are signed in. - Violations appear in the page's own DevTools console (opt-in per site) and in a log you can download as JSON. ## Without an account Nothing to sign up for. A built-in strict baseline is applied in Report-Only, and every violation it raises is logged in your browser. Enforce strict applies your custom header overrides and nothing else. The built-in baseline is a monitoring tool: enforcing it is a decision about your site. ## With an account Signed in at https://app.tardisec.com, it fetches that domain's recommended security headers from your account and applies them in both modes. That set names a reporting endpoint, so the browser delivers violation reports to your account as well as to the in-browser log. ## Privacy By default: - Does nothing until you switch monitoring on for a domain. Installing it changes no page, and there is no default-on list. - Does not log to the page console. You can turn that on per site. - A domain's settings are discarded once every tab for it is closed. Tick "Remember these settings for this domain" and they persist until you switch the site off. The report log is held in memory for the browser session, and the popup can clear it at any time. Violation reports are produced by the browser's own Reporting API, not by this extension. They go to whatever endpoint the headers being applied name: your account's collector when signed in, and no endpoint at all on the built-in baseline, where reports never leave the browser. No analytics, no telemetry.

Details

  • Version
    0.0.1
  • Updated
    August 23, 2026
  • Offered by
    TardiSec
  • Size
    65.6KiB
  • Languages
    English
  • Developer
    Farrell Labs Inc
    116 26 Ave NE Calgary, AB T2E 1Y7 CA
    Email
    team+chrome-extension@tardisec.com
    Phone
    +1 403-797-0557
  • Trader
    This developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
  • D-U-N-S
    240339705

Privacy

Manage extensions and learn how they're being used in your organization

tardisec has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

tardisec handles the following:

Location

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

Related

Header Editor - Modify Request & Response Headers

0.0

Modify request headers, response headers and redirect URLs, with rules isolated per site.

PolyCode NoCookie — Smart Cookie Consent Manager

0.0

Automatically handles cookie consent banners with privacy-first defaults and local protection analytics.

Website Time Tracker & Blocker - SiteLimit

5.0

Track time spent on websites and block distracting sites with daily time limits.

Statable GDPR Checker

0.0

Audit what a website loads before consent: third-party trackers, cookies and embeds, with a live verdict in a side panel.

History Cleaner: Auto Clean & Custom Rules

0.0

Curate your browsing history with custom rules. Auto-clean by URL, domain, or time. Preview before deleting, protect what matters.

Cyera Privacy Inspector

0.0

Audit your site for compliance with privacy frameworks like CPRA or GDPR.

Page Visibility API Blocker

3.0

Blocks the Page Visibility API to prevent websites from detecting when the page is hidden

Security Header Scanner

0.0

Analyze HTTP security headers of any website and get an instant security grade with detailed recommendations.

Website Safety Checker

5.0

Use website safety checker to automatically run safety checks on any website to ensure its legitimacy. Stay safe while browsing!

Domain Age Checker | Website Age Checker

4.9

Instantly check domain age, registration date, and expiry date for any website with a single click.

CSP DSB

5.0

Modify or remove Content-Security-Policy headers on any website. Edit directives or use no-csp to disable CSP entirely.

URL Blocker

5.0

Silently and instantly block any website or web address — whole domains or single pages. Private, lightweight, free.

Header Editor - Modify Request & Response Headers

0.0

Modify request headers, response headers and redirect URLs, with rules isolated per site.

PolyCode NoCookie — Smart Cookie Consent Manager

0.0

Automatically handles cookie consent banners with privacy-first defaults and local protection analytics.

Website Time Tracker & Blocker - SiteLimit

5.0

Track time spent on websites and block distracting sites with daily time limits.

Statable GDPR Checker

0.0

Audit what a website loads before consent: third-party trackers, cookies and embeds, with a live verdict in a side panel.

History Cleaner: Auto Clean & Custom Rules

0.0

Curate your browsing history with custom rules. Auto-clean by URL, domain, or time. Preview before deleting, protect what matters.

Cyera Privacy Inspector

0.0

Audit your site for compliance with privacy frameworks like CPRA or GDPR.

Page Visibility API Blocker

3.0

Blocks the Page Visibility API to prevent websites from detecting when the page is hidden

Security Header Scanner

0.0

Analyze HTTP security headers of any website and get an instant security grade with detailed recommendations.

Google apps