denyfirst.

What Porch
undertakes.

Porch adds these to denyfirst’s undertakings. Each one says how you can check it.

Porch never records who asked for a scan. What was scanned is kept only where the person running it chooses: on their own disk, or sealed under their password. The demonstration keeps only the latest report of each check of its own hosts, in memory, for fifteen minutes.
How you check it. No code can write down who asked, and a test fails if any appears. The public counter is only a number.
A scan only reads what a server already offers. It sends no login attempts, no exploits, no malformed packets and no mail.
How you check it. docs/checks.md lists every connection a scan makes.
Porch has no third-party code: only its own source and Go's standard library.
How you check it. go.mod has no require block, so a build fetches nothing but the Go toolchain. docs/releasing.md is the release procedure.
A report says which questions got no answer, so silence never reads as a pass.
How you check it. Every row is shown, answered or not, and says why it is empty.
Porch refuses private, loopback, link-local and reserved addresses, including ones reached through a redirect.
How you check it. internal/safedial checks the address of every connection where it is made.