Documentation
Everything written down,
in one place.
How to read a report, what a check sends, how to run your own copy, and how to reach us. Short pages here; the full reasoning lives with the source.
01 / Reading a report
What a result means.
Each check has its own rules and its own limits. These pages explain both.
Transport
The TLS handshake and certificate: what is graded, what is only reported, and what a scan cannot see.
Rule set porch-tls-v7Reach
How a site is reached over HTTP and HTTPS, and exactly what the web check sends to a server.
Rule set porch-web-v3What the domain's DNS says about its mail, what the check connects to, and why an exchanger may not answer.
Rule set porch-mail-v3DNS
How the domain itself is served: its name servers, what it publishes, and whether its DNSSEC chain holds.
Rule set porch-dns-v2Names
Which names under a domain its certificates, its own records and its zone publish, where each one came from, and what the list cannot show.
informational, and graded by nothingWhat changed
Every rule set version, and what each one grades differently.
On GitHub02 / Privacy & terms
What is kept, and what is agreed.
Privacy, and what a scan does
What this service records, what a check sends, who else is asked anything, and how to stop a scan.
On this siteTerms of use
What you agree to when you use this, and what it does not promise.
On this siteWho makes this, and what they receive
What denyfirst undertakes whatever you run — chiefly that nothing published here reports back to them — and how to check each undertaking rather than take it on trust.
On this site03 / Run it yourself
Your machine, your scope.
Porch is built to be run by the people responsible for what it checks.
Self-hosting
Docker or a single binary, proof of control for every domain, and a certificate for a public address.
On GitHubVerify a download
Check a release's signature and rebuild it yourself, byte for byte.
On GitHubWho may scan what
The boundaries a copy enforces, and the reasoning behind each one.
On GitHubHow the undertakings are split
Why the organisation says its part once and each product adds its own, what holds the two apart, and what a second product has to do.
On GitHub04 / Security & source
Check it, and tell us.
Report a vulnerability
How to reach us privately, and the fingerprint of the key to encrypt to.
On GitHubGuarantees and their tests
Every promise this project makes, each with the test that fails if it is broken.
On GitHubSource
The whole of it, under the AGPL-3.0, with no third-party dependencies.
On GitHubThe key itself is served at denyfirst.dev/pgp-key.txt and the contact details at denyfirst.dev/.well-known/security.txt, and nowhere else: an installation of Porch somebody runs is theirs to answer for, and does not publish ours. Compare the key's fingerprint with the one on GitHub before using it.