Paste a config, get findings back
Drop in an AOS-CX running config. Every line is checked against the real command set of the release you pick, from 10.15 to 10.18, every name it uses is checked against what it defines, and the rest is held up to the CIS benchmark for CX switches, by control number, and to the habits that keep a campus access switch out of trouble. Each finding says why, and most come with the lines that fix them.
Your config never leaves this page
The checker is code that came down with the page. It reads the box below and nothing else, and it runs in this tab. Nothing is uploaded, stored or logged, and there is no analytics on this page.
That is enforced, not just promised: the page carries a Content-Security-Policy with connect-src 'none', so your browser refuses any network request it might try once it has loaded. Open the network tab in your browser's developer tools, paste, check, and watch it stay empty. Close the tab and the config is gone.
What that cannot cover: browser extensions can read any page you open. Secrets in a running config are already ciphertext, but hostnames and addresses still say a lot about a network, so follow your own policy on where configs go.