New in v1.1.0The mobile app is out of Beta and included in every edition — iOS and Android, signed in to your own instance.Read the announcement

Platform Platform overviewSee it in actionAI SearchAI AssistantAI Connectors & MCPIntegrationsQuality LoopAdministration & SecurityMobile app
Solutions IT & Platform teamsCompliance & Data ProtectionDevelopersAgencies & Partners
Sovereignty
References
Pricing
Resources Trust CenterEU AI ActSecurity & disclosureFree toolsOpen source & open coreDocumentation ↗API reference ↗GitHub ↗ReferencesBlogChangelog
Company AboutPartnersContact
Search See it live Book a demo
Sovereignty

Ten free tools, and how to check in thirty seconds that nothing you type into them leaves your browser

All ten tools on ragsuite.de compute in page JavaScript. Nothing you enter into one, and nothing it calculates, is sent anywhere. You do not have to take that on faith — here is how to verify it yourself in thirty seconds, and where the two boundaries of that claim honestly sit.

SOVEREIGNTY nothing you enter crosses the lineyour browserwhat you typethe tool, in the pageanyserver ragsuite.de
Jürgen Pietschmann
Jürgen Pietschmann AI Consultant
Published2 September 2026 Read12 min Sovereignty

Every one of the ten free tools on this site computes inside your browser. What you type into them is not sent to a server, not written to a database, and not seen by us. The calculation happens on your machine, in the page you already loaded.

That is an easy sentence to write and a cheap one to fake, which is why the more interesting half of this article is the part where you check it. It takes about thirty seconds and needs nothing installed.

The ten tools

Five aimed at the compliance side of an AI project, five at the engineering side. All free, no account, no gate.

ToolWhat it does
EU AI Act Risk ClassifierAnswer a few questions, get your risk tier, the obligations that attach, and the date each one applies from.
AI Data Sovereignty CheckerPick a model provider and a deployment mode, see where your prompts and retrieved context actually travel.
DSGVO RAG-Readiness ScorecardNine questions on what really blocks a rollout on internal documents — residency, impact assessment, processing agreement, works council, retention, audit.
AI Vendor Residency LookupA filterable reference of where common AI vendors host and process data, and what that exposes them to.
DPIA / AVV StarterGenerates the structure of a data-protection impact assessment or a processing agreement, to take to your officer and counsel.
RAG Cost & Self-Hosting CalculatorSize the metered cost of a retrieval system and watch it move with usage.
Token & Cost VisualizerPaste text, see how it splits into tokens, price it at your own rate.
Chunking & Retrieval PlaygroundMove the sliders and watch how chunk size and overlap reshape what a retriever can find.
Embedding Cost EstimatorCost out the first pass over a document corpus, and the re-runs nobody budgets for.
Context-Window CalculatorCheck whether your prompt plus retrieved context fits a model’s window, and what to do when it does not.

A note on terms, since two appear above and both get used loosely. RAG — retrieval-augmented generation — means an AI system that looks up passages from your own documents and answers from them, rather than from memory. A token is the unit models are billed and measured in, roughly three-quarters of a word in English.

How to check the claim yourself

Every browser ships with a panel that records the requests the page makes. It is the browser’s record, not ours, which is what makes this worth doing rather than reading.

Thirty seconds, no installation

  • Open any tool on this site, then press F12 (Windows) or Cmd + Option + I (Mac).
  • Select the tab labelled Network. It lists every request the page makes.
  • Click the clear button — usually a circle with a line through it — so the list is empty.
  • Now use the tool. Type into it, change the options, get a result — but leave the optional email form at the bottom alone for now.
  • Watch the list. Nothing appears carrying what you typed. The answer arrived without a round trip, because it was computed where you are sitting.

If you want the sharper version of the test, turn off your network connection entirely and use the tool offline. It still works.

What “runs in your browser” means technically

Where a tool's data goes Where a tool’s data goesYOUR BROWSERWhat you typeThe tool’s logic — page JavaScriptThe result, on your screenANY SERVERno request carryingyour input is madeno crossing
The whole computation happens inside the page. There is no server step to trust, because there is no server step.

Concretely: the tool logic itself makes no network call. Whatever you type into a classifier or a calculator is read by JavaScript already loaded in the page, computed there, and rendered back to you. There is no request to send, so there is nothing to intercept, log or retain. There is also no analytics script on this site at all — not a self-hosted one, not a third-party one — so there is no beacon recording that you used a calculator or what you put in it.

The two boundaries of that claim, drawn by us rather than found by you

Here is the part a marketing page would leave out. The claim above is about what the tool does with what you type. It is precise and it holds. The page around it does other things, and if you run the network test properly you will see them.

On a tool pageDoes it transmit anything?
The tool itselfNo. Your input and its result stay in the page.
The optional email form, if you submit itYes — your address, which tool you were on, your consent flag. To this domain. Not your inputs or results.
The AI Assistant and AI Search widgetsYes, on page load, to an origin that is not ours. Whatever you type into them reaches them.
The cookie-consent noticeSends nothing, but writes one key to your browser’s local storage when you dismiss it.

One: the optional email form. Below the result on each tool there is a form offering to send you a copy. It is optional and it sits below the answer rather than in front of it — but if you fill it in and submit, that is a request, to an endpoint on this same domain. What it carries is your email address, which tool you were on and your consent flag. It does not carry your inputs or your results; those stay in the page. If you never touch the form, nothing is sent at all.

Two: the assistant and search widgets. The pages also carry our own AI Assistant and AI Search widgets, and those are currently served from an origin that is not ours. You will see requests to that origin on page load, before you have done anything, and anything you type into the assistant does reach it.

The last row is in the table because “nothing is written to your browser” would have been the tidier sentence, and it would have been wrong.

We could have written “nothing on these pages calls a third party” and been mostly right. Mostly right is the failure mode this whole site exists to argue against, so: the narrower claim, and the open item stated in public.

The claim we make, and the one we don't Two claims, one of them oursVERIFIABLE — THE CLAIM WE MAKENothing you enter into atool, and nothing itproduces, leaves the browser.check it in the network panel,or with the network switched offNOT CURRENTLY TRUENothing on these pagescalls any third party.the assistant and search widgetsload from an origin that is notours — so we don’t say this
The wider claim would be easier to write and would read better. It is also not currently true, so it is not the one on the page.

Why they are not behind a form

A gated calculator converts better. Put an email field in front of a cost estimator and a measurable share of people will fill it in, and you get a list.

We decided against it on grounds that were not entirely noble — a list of people who wanted a number badly enough to trade an email for it is not a list of buyers — but mostly because of the contradiction. It is not possible to argue that a company should be able to inspect what its AI vendor does, and simultaneously require a company to identify itself before it may use a token counter. One of those positions would have to be the marketing one.

So the tools have no gate, and they are worse lead magnets than they could be. That was the trade.

Three ways people actually use them

Which tools answer which job Three routes through the toolsA COMPLIANCE LEAD SCOPING A PROJECTrisk classifier → readiness scorecardA DEVELOPER SIZING AN IDEAtoken visualiser → embedding estimator → chunking playgroundA BUYER COMPARING VENDORSresidency lookup → sovereignty checker
Three jobs, three routes through the same ten tools. Nothing here needs an account, so there is no cost to starting in the wrong place.

A compliance lead scoping a project. Start with the risk classifier to establish which tier a planned system falls in and which date attaches to it — that alone resolves most of the phantom urgency in AI planning, because a great deal of material written in 2025 still carries superseded dates. Then the readiness scorecard, which asks the nine questions that actually stall internal rollouts.

A developer sizing an idea before proposing it. The token visualiser to understand what a document costs to process, the embedding estimator for the first pass over a corpus and the re-runs after that, and the chunking playground to see why retrieval quality moves so much with parameters that look cosmetic.

A buyer comparing vendors. The residency lookup and the sovereignty checker together answer a question most questionnaires never quite ask: not where is the data stored, but who can reach it and under whose law. The figures carry a date stamp on the page — read it, and treat the tool as a map of the questions rather than a current answer on any single vendor.

What they deliberately do not do

They do not make determinations. The risk classifier gives you a tier, the obligations attached to it and the date each applies from — it does not tell you that your system is or is not high-risk, because that depends on facts about your deployment that a five-question form cannot see. The DPIA and AVV starter produces a structure, not an assessment, and the structure is there so the first conversation with your data-protection officer starts further along than a blank page.

None of the ten is legal advice, and the two that come closest say so on the page.

The honest summary

Ten tools, no account, and a claim you can check without trusting us: what you type into them is computed where you are sitting and goes nowhere.

The claim stops at the tools, and we have said where. If you run the test and find something we have not described here, tell us — a claim you can check is only worth making if being wrong about it is expensive for the person who made it.

Frequently asked questions

Do I have to sign up or give an email address to use the tools?

No. There is no account, no gate and no email wall on any of the ten — you get the full answer without identifying yourself. There is an optional form below each result offering to email you a copy, and it does send your address to us if you fill it in and submit. It sits below the answer rather than in front of it, and your inputs and results stay in your browser either way.

How do I actually verify that nothing is sent?

Open your browser's developer panel — F12 on Windows, or Cmd + Option + I on a Mac — and select the Network tab. Clear the list, then type into a tool and change its options. Watch the list: no request appears carrying what you entered. You are watching the browser's own record of its traffic, not ours, which is the point.

Does the page as a whole make no requests, then?

No — and we would rather say so than have you find it. The tool logic makes no request. Two other things on the page do. The optional email form at the bottom of each tool posts to an endpoint on this same domain if you fill it in and submit — it carries your email address, which tool you were on and your consent flag, not your inputs or results. And our own AI Assistant and AI Search widgets load from an origin that is not ours, on page load, before you have done anything; whatever you type into those reaches them. There is also one cookie-consent key in local storage. The narrow claim — that what you enter into a tool and what it produces go nowhere — holds, and it is the only one we make.

Are the vendor and price figures in the tools current?

They are dated on the page, which is the honest form and also a warning. The vendor residency and sovereignty data carries a June 2026 stamp, so at the time of writing it is a quarter old — useful for the shape of the question, not authoritative on any one vendor today. Model prices and context-window sizes in the developer tools are dated the same way and are editable, so you can put your own contracted rate in rather than trusting ours. The EU AI Act dates in the classifier were rechecked against Regulation (EU) 2026/1744 before this article was published and are current.

Can I use the DPIA/AVV starter as our actual documentation?

No. It produces a structured starting point — the sections a data-protection impact assessment or processing agreement needs, in an order that makes sense for a retrieval system. It is something to take to your data-protection officer and your counsel so the first conversation starts further along. It is not the assessment and it is not legal advice.

Sources & further reading

  1. RAGSuite — free tools hub — all ten, no account required
  2. EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI) — the instrument the risk classifier's dates were rechecked against
  3. Chrome DevTools — Network features reference — how to read the network panel, if you have not opened it before

← All posts