# safing/portmaster

🏔 Love Freedom - ❌ Block Mass Surveillance

Repository: https://github.com/safing/portmaster
Canonical: https://ross.abutalabs.com/products/portmaster
Homepage: https://safing.io
Language: Go
License: GPL-3.0
License Family: copyleft
Topics: application-firewall, dns, firewall, go, golang, privacy, privacy-by-design, privacy-protection, privacy-enhancing-technologies, privacy-tools, networking
Last push: 2026-08-21T11:25:18+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 98, release rhythm 89, longevity 100
- inputs: {"age_days": 2850, "days_push": 12, "days_rel": 78, "gap_med": 29.0, "n_releases_24m": 7}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 13612, forks 573 (observed 2026-08-28T04:11:03.655327+00:00)

## What it is
Portmaster is a free and open-source application firewall and privacy suite for Windows and Linux desktops. It intercepts all network traffic at the packet level to monitor connections, block trackers and malware, enforce secure DNS, and apply per-app rules, with an optional paid onion-routing network (SPN).

## Use cases
- block apps from phoning home
- block ads and trackers system-wide
- encrypt all DNS queries with DNS-over-TLS
- monitor which applications make network connections
- set per-application firewall rules
- restrict app connections to certain countries
- replace my VPN with per-connection privacy routing

## When to choose
- you want automatic, default-on privacy protection on a Windows or Linux desktop
- you need visibility and control over every application's network activity
- you want system-wide tracker and malware blocking beyond the browser
- you prefer fully local, auditable open-source privacy tooling

## When to avoid
- you need a firewall for servers or headless environments
- you require macOS or mobile support
- you need only a simple VPN without per-app control
- you cannot run kernel-level packet interception on your machine

## Facets
- artifact type: application
- maturity: active
- function: security, networking, privacy, monitoring, caching
- domain: privacy, security, networking, self-hosted
- platform: windows, go
- tags: application-firewall, dns, dns-over-tls, tracker-blocking, per-app-rules, network-monitoring, onion-routing, spn, linux, desktop

## Member repositories
- safing/portmaster (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:03.655327+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:13:09.719240+00:00, confidence not recorded.
  - readme: https://github.com/safing/portmaster (fetched 2026-08-28T04:11:03.655327+00:00, sha 4870ba15e260)
  - homepage: https://safing.io (fetched 2026-08-29T08:07:51.369866+00:00, sha 80c6f44364da)
  - site_page: https://safing.io/features (fetched 2026-08-29T08:07:51.379146+00:00, sha 3bd50bf6f9b6)
  - site_page: https://safing.io/about (fetched 2026-08-29T08:07:51.384154+00:00, sha 2b54d351e1bb)
  - site_page: https://safing.io/spn (fetched 2026-08-29T08:07:51.387503+00:00, sha 32f30604fd4f)
  - site_page: https://safing.io/pricing (fetched 2026-08-29T08:07:51.381771+00:00, sha add3d191f6d6)
  - site_page: https://wiki.safing.io/ (fetched 2026-08-29T08:07:51.385846+00:00, sha ffa45723a8d1)
- Data as of 2026-08-30T08:39:29.467469+00:00.
