Coverage map
What is tracked, how far each record goes, and where Cunicula stops.
Coverage is not completeness. A missing service, event, or jurisdiction means it is not documented here; it does not mean the underlying risk or record does not exist.
Directory scope
The directory groups 173 current entries into the public categories below. Counts are derived from the same records that render the directory. Depth is a promise about fields Cunicula tries to document, not a claim that every field is known for every entry. Unknown and partial values remain visible.
Comms · 20 entries
Policy-level coverage of account identifiers, metadata and logging claims, encryption architecture where sourced, ownership, and jurisdiction. It is not endpoint forensics or a protocol audit.
Privacy Tools · 47 entries
Mixed-depth coverage of purpose, account and data path, ownership, jurisdiction, source status, and audits where published. This broad category is selective, not an exhaustive software catalogue.
VPN · 12 entries
Policy-level coverage of signup and payment identity, logging claims, ownership, jurisdiction, audits, and reviewed incidents where records exist. It does not continuously test traffic handling, leaks, or speed.
DNS · 3 entries
Policy-level coverage of logging and retention claims, supported encrypted transports, ownership, and jurisdiction. It is not a continuous resolver performance or censorship measurement network.
Email · 9 entries
Policy-level coverage of signup identity, payment, retention and logging claims, operator, and jurisdiction. It does not benchmark deliverability or continuously test account recovery.
Cloud Storage · 4 entries
Profile-level coverage of signup identity, encryption and custody claims, logging, ownership, and jurisdiction. It does not independently inspect every client build or server-side control.
Hosting · 14 entries
Profile-level coverage of signup and payment identity, operator, jurisdiction, published use policies, and reviewed incidents. It does not monitor uptime or every abuse-handling decision.
Wallet · 19 entries
Profile-level coverage of account requirements, custody and recovery model, network exposure, ownership, and reviewed incidents. A listing is not a code or cryptography audit.
Swap · 26 entries
Profile-level coverage of signup identity, custody and transaction flow, fees or limits where recorded, operator, jurisdiction, source status, and reviewed incidents. It is not a live quote or liquidity feed.
P2P · 13 entries
Profile-level coverage of account and KYC requirements, escrow or custody, payment rails, operator, jurisdiction, and reviewed incidents. It does not measure current liquidity or counterparty availability.
Gift Cards · 13 entries
Profile-level coverage of signup and KYC requirements, payment methods, delivery model, limits, operator, and jurisdiction. It does not track live stock, region locks, or redemption success.
Virtual Cards · 8 entries
Profile-level coverage of account and KYC requirements, issuer or custody chain, funding rails, limits, and jurisdiction. It cannot guarantee eligibility, acceptance, or continued issuer support.
Merchants · 6 entries
Listing-level coverage of accepted privacy-preserving payments and identity requirements visible at purchase. It does not monitor inventory, fulfilment, returns, or every checkout route.
ATM · 3 entries
Listing-level coverage of identity thresholds, operator, and location context where sourced. It is not a live machine-status, fee, or cash-availability feed.
Tracker scope
- KYC changes: dated identity-policy changes found for selected services. It is not a complete history for every directory entry.
- Policy measures: selected encryption, age-verification, and data-protection measures with status dates and source links. It is not a global legislation database.
- ALPR contracts: selected local contract outcomes. Rows backed by deciding-body documents are separated from press-only reports; neither set is a national census.
- Service incidents: events an editor reviewed against named sources. Automated detection files leads and does not turn them into public records.
Primary-record jurisdictions represented
These lists name jurisdictions represented in the current primary-record trackers. They are not a promise that every relevant body, measure, contract, or later amendment in that jurisdiction is continuously monitored.
Policy records
- California, United States
- European Union
- India
- Louisiana, United States
- Texas, United States
- United Kingdom
- Utah, United States
ALPR deciding-body records
- Hillsborough, North Carolina
- Los Angeles, California
- Mountain View, California
- Washington State
Where another source is better
- Curated recommendations: Privacy Guides is better suited to a recommendation shortlist. Cunicula deliberately does not choose a tool for the reader.
- Live no-KYC swap quotes and public user ratings: KYCnot.me provides surfaces Cunicula does not operate. Cunicula is better used for its source bundles, ownership context, and separate evidence fields.
- Android tracker and permission scans: Exodus Privacy publishes static-analysis reports. Cunicula does not scan every app binary.
- Known software vulnerabilities: OSV and the NVD are better for package, version, CVE, and remediation lookups. Cunicula records selected incidents, not the full vulnerability corpus.
- Personal breach exposure: Have I Been Pwned is the appropriate lookup for whether an account identifier appears in its breach corpus. Cunicula does not accept or search personal identifiers.
- Threat modeling and practical security planning: EFF Surveillance Self-Defense provides step-by-step guidance. Cunicula records service and policy evidence rather than a personal security plan.
- Live price, availability, eligibility, and terms: the provider's own checkout, status page, and current legal documents are more current. They remain first-party claims and should be read with that limit.
Related records
- What Cunicula is: a claims index, not a certification, audit, or recommendation engine.
- Evidence trackers: the current KYC, policy, ALPR, and incident records.
- Methodology: the fields, source labels, score formulas, and limits.
- Corrections: the correction policy and public log.