{
  "slug": "sourcehut",
  "category": "code-hosting",
  "name": "SourceHut",
  "description": "Git and Mercurial hosting with ticket tracking, mailing lists, wikis and a CI build service. Can be self-hosted, or used through the hosted instance at sr.ht.",
  "website": "https://sourcehut.org",
  "source": "https://git.sr.ht/~sircmpwn/git.sr.ht",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "NL",
    "name": "Netherlands",
    "eyes": "Nine Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "B",
  "score": 75,
  "coverage": 100,
  "summary": "SourceHut scores 75 out of 100 (grade B) on the code hosting criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, tells users about requests and TLS configuration. It partly meets transparency report. It does not meet independent audit and security headers. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
  "url": "https://privacyratings.com/code-hosting/sourcehut/",
  "markdown": "https://privacyratings.com/code-hosting/sourcehut/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://git.sr.ht/~sircmpwn/git.sr.ht/tree/master/item/LICENSE",
      "note": "AGPL-3.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://man.sr.ht/privacy.md",
      "note": "The privacy policy lists no analytics and states no user information is shared with third parties apart from payment processing."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://sourcehut.org/pricing/",
      "note": "Funded by paid subscriptions, with no ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://man.sr.ht/privacy.md",
      "note": "The privacy policy describes how court orders for account data are handled, but no request counts are published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://man.sr.ht/privacy.md",
      "note": "The privacy policy promises to notify users of court orders for their data unless the order prohibits it."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=sourcehut.org&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=sourcehut.org",
      "note": "Grade D (35/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "D",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:03:55.197Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}