Tool Listing Policy
How tools enter, appear in, and move between the statuses of our directory. This policy exists so that every badge on our site means the same thing to every visitor, and so that submitters know exactly what to expect.
Version 1.0 · August 2026
What every listing requires
All tools in the directory, at any tier, must be open source under a recognized open source license, with the complete source code publicly available for inspection. The submitter must disclose any affiliation with the tool, agree to our community standards, and consent to the specific status the tool will be listed under.
A tool can be removed from the directory at any time if it no longer meets the requirements of its tier, if the project is abandoned, or if ODIPA determines that continued listing could mislead or harm users. Listing is always at ODIPA's discretion, is never sold, and we do not accept payment or other consideration for any listing decision.
Tier 1. Approved
ApprovedThe green badge. This is the directory's core status and the only one that represents ODIPA's review and approval.
An Approved listing means the tool passed our full review process. That process covers an initial review of code quality, documentation, and stated purpose, followed by a security review including dependency scanning, static analysis, and manual code review, followed by board confirmation of mission and community alignment. Review timelines are published on our Contribute Code page.
Approval attaches to a specific version. We review a tagged release or pinned commit, and the listing identifies the version reviewed and the review date. The tool itself remains in the author's repository, and authors retain full ownership and control of their projects. When a project ships material changes to its security model, data handling, or core functionality, the approval applies only to the reviewed version until a re-review is completed. ODIPA may re-review on its own schedule or at the author's request.
An Approved badge is a statement that the tool met our published criteria at the time of review. It is not a certification, a guarantee, or an endorsement for any particular use.
Tier 2. Community Project, the Needs Help badge
Needs HelpThe amber badge. This status features promising open source privacy tools that are not yet ready for approval, and invites our contributor community to help finish them.
A Needs Help listing is not a review outcome and does not imply any level of safety. Every Needs Help card is labeled experimental and not yet reviewed, and carries this statement or its equivalent. A project to help build, not a tool we recommend using yet. The card's primary action is a contribution link, not a link encouraging use.
Community Projects are featured only with the author's consent. By default, ODIPA maintains a fork of the project in our GitHub organization as the community contribution workspace. We curate the open issues there, highlight the specific gaps standing between the project and formal review as headline challenges, and direct contributors to them. Completed work flows upstream to the author's repository as pull requests, and the author remains the maintainer and the final word on every merge. Where an author prefers a different working arrangement, including hosting the project's primary home within ODIPA's organization, we are open to discussing it.
A Community Project graduates by closing its identified gaps and then completing the full Tier 1 review process. Graduation is never automatic.
Tier 3. ODIPA Adopted
ODIPA AdoptedBy mutual agreement, an author may move a project's primary home into ODIPA's GitHub organization, following the model long used by open source foundations. This is entirely opt in and is never a condition of any listing.
Under adoption, ODIPA holds the repository settings and enforces branch protection, and the original author continues as lead maintainer with required review authority on every change, so nothing merges without both the author and ODIPA. GitHub's transfer mechanism preserves the project's stars, watchers, history, and inbound links.
Adopted projects still follow the same review standards as everything else. Adoption does not confer Approved status, and an adopted project that has not passed review carries the Needs Help badge like any other community project.
How the badges appear
Approved tools show a green badge reading ODIPA Built and Maintained for tools we author, or ODIPA Reviewed and Approved with the review date for external tools that passed review.
Community Projects show an amber Needs Help badge, the experimental notice, and a Contribute call to action.
No other badge or status exists, and the absence of a badge means the tool has no standing with ODIPA.
Ready to submit a tool?
Submissions go through the form on our Contribute Code page, and questions about this policy can come through our contact form.