PODSHL PublishRegister ProjectsLog SecurityNotice

What this does to a machine, and what reaches whom

For a maintainer deciding whether to publish, and for anyone deciding whether to install the client.

A publisher may only choose, never invent

The list of things that can be read, and the list of things that can be changed, both live on the client. What you publish names an operation and fills in declared parameters. A careless or compromised publisher can mis-parameterise a tested operation — validation and the dry-run catch that — but cannot introduce one. Nothing published here can ship a capability.

Extending either list is a client release that people choose to install, not a field anybody can set. The read vocabulary is published, so what may be asked of a machine is checkable rather than promised.

Nothing runs without being shown first

What travels, if the user says so

Diagnosis happens on the user's machine. Readings are compared against the published solution there, and only a conclusion is produced. Reporting is optional and comes last, after they already have their answer.

observedMeasured on the machine, already coarsened
statedSupplied by the person. Never mixed with the above — a claim and a measurement must not wear the same name
droppedWithheld entirely. Serial numbers and anything identifying never travel, whoever supplied them
descriptionFree text — an error, the lines of a log — and only where the user read the exact words and agreed, with the recipient named. Names, addresses, tokens and times are replaced on the user's machine before they are asked, and they are told what was replaced

No timestamp and no incident identifier, so a report cannot be linked back to the run that produced it.

The pseudonym

A report carries a pseudonym so a recipient can count people rather than submissions, and rate-limit abuse. It is different for every project and changes every month, derived from local randomness that is never a hardware fingerprint. Across projects nothing links; across months nothing links. Resetting it is the user's call, and costs them their accumulated standing.

Nothing is shown below five distinct reporters

Not to a maintainer, not to the operator, not to anybody. Below that a constellation is identifying — and the threshold counts distinct pseudonyms, so one person reporting five times still counts once.

What this server holds

Read from the server's own answer rather than restated here, so this section cannot drift from what it actually does.

Holds

Never holds

Checking us rather than believing us

Attestations go into an append-only, signed transparency log. It is fetched whole — there is deliberately no per-domain lookup, because one would tell us which software everyone runs. A domain owner watching the log sees any attestation claiming their domain, including one we should not have issued. Read the log.

No warranty, and who wrote the advice

All of this is provided as is, without warranty of any kind. The bounds above are real and they are bounds on effect — nothing here promises that a suggested change fixes anything.

Support content is written by the projects, not by us. We mirror what a project publishes in its own repository. We do not author it, do not review it for correctness and do not endorse it — the project is named in every answer, so you can always see whose advice you are taking. A solution that is wrong is wrong at its source, which is also why the report goes back there.

Back up what matters before acting on any advice, from here or anywhere. The full statement, including what cannot be excluded under German law, is on the imprint.

Reporting a finding

See the imprint.