Skip to content

Request verification

Free at this stage. We verify only what you ask us to verify, and only what you give us access to.

Public repositories only at this stage. That restriction exists so we never hold your secrets — and so that anyone can recompute the verdict from the same source.

Every verification at this stage is read-only. We read what is already public and touch nothing. Fewer operations can be measured that way, and the passport says which ones and why.

A probing mandate — where you name what we may touch, how often, what must not be affected and how you revoke it — becomes available when the prober exists. It will require a signed document before anything runs. It is not offered here yet because offering it would be a promise nobody could keep today.

Nothing is charged. There is no payment step anywhere on this site, in this phase or any later one — money does not pass through us by design.

What happens to what you type here

  • Stored: the repository URL, your address, the time, and the two-letter country your request arrived from. Nothing else, and this form sets no cookie of its own.
  • Where: Cloudflare key-value storage, plus a copy in the operator’s private message channel so a human sees it. Both are read by the operator alone.
  • Used for: deciding whether to run a verification and contacting you about it. Never for anything else, never sold, never passed on.
  • Deleted: whenever you ask, by opening an issue or replying to any message from us. There is nothing to unsubscribe from — we do not send anything you did not ask for.
  • Separately, about this whole site: Google Analytics runs on every page here, without a consent banner. It sets a cookie and creates an identifier for your browser, and what it records goes to Google. That is the operator’s decision and it is written down, with the argument against it, in the project’s decision log. Advertising and personalisation signals are switched off, which is the most that can be said for it.