Send in your ideas. Deadline October 1st, 2020.


Current Projects

Listed on this page are programs and projects which are - at this moment - working with NLnet funding.

At present NLnet Foundation is actively supporting the following projects:
802.11n feature of openwifi - Open Hardware implementation of wifi
A Distributed Software Stack For Co-operation - Facilitating easy ad hoc cooperation
A proof of concept of identity-based encryption - Make encryption simpler
Accessible security - Integration effort of independent security efforts like Qubes, Heads, coreboot, etc
Adopt improvements in Email Encryption in KMail - Adopt improvements in Email Encryption in KMail
AI-VPN - Local machine-based learned analysis of VPN trafffic
An x86, 64-bit Virtual Machine Monitor for the seL4, verified microkernel - Very restricted virtualized environment for higher security
ARPA2 - Working towards a decentralised global internet that offers security and privacy by design.
ARPA2 LDAP Middleware - Privacy enhancing middleware
ARPA2 resource ACL and HTTP SASL modules for NGINX - Extend consistent access control to NGINX webserver
ARPA2 Steamworks - ARPA2 Steamworks
Autocrypt for Thunderbird - Make email encryption extremely simple
Balthazar - One laptop for the new internet age.
Balthazar - One laptop for the new internet age. - A secure fully open hardware laptop
betrusted - A protected hardware device for your private matters.
Betrusted OS - An embedded OS for cryptographic devices
Betrusted software - A minimalist and secure OS for embedded communication devices
Bitmask - User-friendly and secure VPN configuration
Blink RELOAD - Secure P2P real-time communications with RELOAD
Briar - A secure messaging app with offline capabilities
Build Transparency (Trustix) - Towards a decentralized supply chain for software
Castopod - Podcasting in the fediverse
Chips4Makers ASICs - Chips4Makers ASICs
Conferences - sponsoring of various conferences
Connect by Name - Library for easy connection setup
Conversations - A secure mobile messaging client
Creative Passport - Allow creative artists to gain visibility and build reputation on the web
CryptPad - Real-time collaboration with client-side encryption
CryptPad for communities - Collaborative web editor with client-side encryption
CryptPad: Project Dialogue - Secure surveys and polls for Cryptpad
Dat Private Network - Private storage in DAT
DCnets - Implementation of Dining Cryptographers Network
Decentralized privacy preserving search by mathematical design - Decentralized privacy preserving search by mathematical design
DeltaBot - Social discovery over mail-based chat
Democratic Sendcomm - An easy to use connected open hardware device with a flat learning curve
dhcpcanon - Network configuration with better privacy
DIME - A new encrypted, end-to-end email protocol
Dino - User-friendly and secure instant messaging
Discourse ActivityPub - Connecting internet discussions with ActivityPub
Discover and move your coins by yourself - A safe way to explore and work with cryptocurrency forks
Distributed Private Trust - Decentralised trust and reputation system
Distributed Trust for Web Servers - Establishing a Distributed Trust Authority
DNSSEC Key Signing Suite - A best practise for DNSSEC Key Signing
Donations - smaller contributions to various activities
EDeA - A forge suitable for open hardware development
eduVPN - Making secure VPN network technology available to everyone
eduVPN app - Add Wireguard protocol to federated VPN suite
eduVPN mobile testing - eduVPN mobile testing
eduVPN multi-protocol - Review of the eduVPN multi-protocol project.
EGIL SCIM client - System for Cross-domain Identity Management
ELF Linking - Analytic tools for UNIX' Executable and Linkable Format - Resilient, human-centered, distributed content sharing and discovery. - Resilient, human-centered, distributed content sharing and discovery.
End-To-End Encryption for Jitsi Meet - Proven strong encryption for open source video conferencing
EteSync - iOS application - Encrypted synchronisation for calendars, addressbook, etc
EteSync - protocol and encryption scheme enhancements - Redesign EteSync protocol and encryption scheme
Explain - Deep search on open educational resources
Explain Direct - Providing effective and efficient access paradigms for open educational material
Extending PeerTube - Adding advanced search capabailities to PeerTube
FairSync - Simplify aggregation and discovery of places and events
Fashion Freedom - Supporting research, development, and education to bring the fashion industry into the 21st century
Faster and configurable datapath/Linux xfrm - Rewriting nftables to optimise for xfrm - Find your way in the Fediverse
FileSender - FileSender is a secure and private way to share large files with anyone.
Finish porting Replicant to a newer Android version - Alternative, free software version of Android
Fix the Pitch Black Attack in Freenet friend-to-friend routing - A decentralized distributed platform for private communication
ForgeFed - Federation for software collaboration tools
Free Software Vulnerability Database - A resource to aggregate software updates
Funkwhale - ActivityPub-driven audio streaming and sharing
Genodepkgs - When Genode and Nixpkgs meet
Geographic tagging and discovery of Internet Routing and Forwarding - Geographic tagging and discovery of Internet Routing and Forwarding
GetDNS - Deliver DNSSEC as a building block in harsh environments
Global Directories - Distributed contact information discovery mechanism
GNU Guix - Discovery of service configurations in a declarative setup
GNU Mes - Help create an operating system we can trust
GNU Mes on ARM - Trustworthy bootstrap for operating systems on ARM ISA
GNU Mes: Full Source bootstrap - GNU Mes: Full Source bootstrap
GNU Name System - Authenticated naming system for the internet from GNU project
GNU Taler - Advanced electronic payment system for privacy-preserving payments
GnuTLS - Implement TLS-KDH in GnuTLS
GoatCounter - Privacy-friendly web analytics for small websites
Graphics acceleration on Replicant - Free software graphics drivers for mobile phones
GUN P2P Encryption - A realtime, decentralized, offline-first, graph database engine
Hackathons - contributions to various hackathons
Handling Data from IPv6 Scanning - Scanning tools for scaling up IPv6 scans
Hubzilla - Federated social networking environment
Implement sound support in the Hurd - Add audio capabilities to the multiserver microkernel from GNU
Improve usability of Linux firewall userspace tools - Userspace tooling for Linux kernel Netfilter
Improving Matrix E2E encryption UX - Better usability of E2E encryption
IMSI Pseudonymization - Better privacy protection for 2G-5G
IN COMMON - Public platform to map and act together for the Commons
In-document search - Interoperable Rich Text Changes for Search
Indigenous - Indieweb mobile clients
Internet of Coins - Create a decentralized, self-sustaining economy by implementing inter-blockchain connectivity
Interpeer - Collaboration infrastructure with near real-time p2p data synchronization
Inventaire - Wikidata-based social sharing of reading experiences - Search engine for the Interplanetary File System
IRMA made easy - Usability research into attribute based authentication
iuh-openbsc - An open source implementation of 3G
JavaScript Shield - Cross-browser extension to make javascript less exploitable
Kaidan - Adding crypto to userfriendly Cross-platform XMPP client
Katzenpost - Observation resistant secure messaging layer
Key Management - Key Management
Kiwi IRC - Self-hosted web IRC environment
KWin and Wayland input - Secure windowing system for KWin
Langsec in Pectore - A secure pacemaker created from formal grammars
Lemmy - ActivityPub for link aggregation
librarian - Custom meta-search
Libre Silicon compiler - Synthesize, place and route hardware description to silicon
Librecast Live - Live streaming with multicast
LibreOffice P2P - Encrypted collaborative editing in the browser
LibreSilicon - Free/open source semiconductor manufacturing process
LibreSOC - A fully open hardware System-on-a-Chip
Lightmeter - Email server configuration lifecycle management
Lizard - E2E Rendez-vous and discovery
LumoSQL - Create more reliable, distributed embedded databases
Maemo Leste - An independent mobile operating system focused on trustworthiness
Magic Wormhole/SPAKE2 - Securely send files between two computers with minimum fuss
Mailpile Search Integration - Personal email search engine
Mangaki - Advanced group recommendations
Manyverse - An off-line capable privacy-centric social messaging app
Matrix-Appservice-CommonsPub - Bridge ActivityPub and Matrix realms
MEGA65 Phone - A phone simple enough to understand in full
MeiliSearch - Modern and responsive search - A press search engine in your browser
Minedive - P2P search over webRTC
MNT Reform - A trustworthy open hardware laptop
mobile-nixos - NixOS for mobile phones and tablets
Modular CA - Modular infrastructure for building secure internet services
MPTCP - MultiPath TCP
Mynij - Portable indexing and search engine for mobile
Namecoin - Decentralized, censorship resist Internet infrastructure for e.g. DNS and identities
Namecoin: Core Infrastructure - Alternative domain name system
neuropil - Privacy by design P2P search including IoT
Nextcloud - Unified and intelligent search within private cloud data
Nitrokey - Open hardware for encryption and authentication
Nixcloud - Declarative internet services based on NixOS
Nixcloud Mail - Declarative mail server based on NixOS
Nixcloud Webservices - Declarative web services based on NixOS
node-Tor - Implementation of Tor protocols for inside webpages
Noise Explorer-VerifPal - Automated proofs and code generation for secure protocols
Non-Ranking Comparison Platform - Neutral tool to bring together facts for analysis
Nym Credentials - A decentralised solution for authentication
Nyxt - A programmable browser with advanced search integration
Off-the-Record messaging version 4 - Advanced protocol for secure messaging
offen - Ethical site analytics, controlled by the user
OnBaSca - Tor Bandwidth Scanner
Opaque Sphinx - Secure password-based authentication with Opaque/Sphinx
Opaque Sphinx Server and Clients - Server and tools for modern authentication
Open Source DRTM implementation with TrenchBoot for AMD processors - Unified framework for dynamic RTM
openEngiadina - Platform for creating, publishing and using open local knowledge - Make local events and meetups discoverable
OpenPGP Certificate Authority - Managing OpenPGP keys for communities and organisation
P2Pcollab - A framework for sufficiently safe social interaction
P2Pcollab - Decentralised social search and discovery
Padding Machines for Tor - Protect metadata in the Tor onion routing network
pcb-rnd - Modular printed circuit board editor
Personal Food Facts - Privacy protecting personalized information about food
PGP4civiCRM - Add email encryption to CRM
Physical Chip Design Framework - An integrated development environment for chip design
Pitchfork - Open hardware for compartmentalizing key material and cryptographic operations
Pitchfork PKCS#11 - Contribute to OASIS standardisation PKCS#11 v3
Pixelfed - ActivityPub driven decentralised photo sharing platform
Pixelfed Live - Live streaming and other Pixelfed enhancements
PKCS#11 v3 - Contribute to standardisation of PKCS#11 for cryptographic tokens
Plaudit - Make good science discoverable through endorsements
Poliscoops - Make political news and online debate accessible
Port of AMDVLK/RADV 3D Driver to the Libre RISC-V SoC - Adapt Vulkan Drivers to the Libre RISC-V SoC
postmarketOS - An independent mobile operating system
Practical Decentralised Search and Discovery - Search and discovery inside mesh/adhoc networks
Practical Tools to Build the Context Web - Declarative setup of P2P collaboration
Pretty Easy Privacy - At scale simulation over GNUnet with different realistic user behavior scenarios
Privacy Enhancements for PowerDNS and DNSdist - Make it easier to deploy private DoT/DoH resolvers
Privacy Preserving Disease Tracking - Research into contact tracing privacy
Private Searx - Add private resources to the open source Searx metasearch engine
Qubes OS - Bring the security of Qubes OS to people with disabilities
RaptorJIT - RaptorJIT is a high-performance Lua virtual machine for network dataplanes.
Re-isearch - Vectorise text with a flexible unit of retrieval
Record Federation for Corteza Clouds - Data federation over ActivityPub
Redwax - Standardisation of client side PKI interfaces
Remote PKCS#11 - Remote usage of PKCS#11
Reowolf - Rip and replace for BSD socket insecurity
Reproducible Builds - Make the build processes behind software distributions reproducible
Ricochet Refreshed - Anonymous, meta-data free secure messaging
RISC-V Phone - Open hardware RISC-V Phone
Robur privacy-enhanced DNS resolver and DHCP server - Secure network configuration and DNS resolution
Rocket CWMP - Remote governance and configuration for internet equipment
Rust Threadpool - Improve privacy of Rust threading library
SASL Works for the InternetWide Architecture - Integrate new authentication mechanisms into SASL
SASL XMSS - Make SASL work with XMSS protocol
SCION-Swarm - Secure and reliable decentralized storage platform

Create a GSM mobile phone consisting of completely open source software and SDR radio

Search and Displace - Find and redact privacy sensitive information
searx - A privacy-respecting, hackable metasearch engine
searx - Federating self-hosted search hubs
Secure User Interfaces (Spritely) - Usability of decentralised social media
Securing PLCs via embedded Open-Source protocol adapters - Open hardware protocol adapters for industrial automation
Secushare Box - Operating system extension of Secushare for hardware devices
SeedVault - Private backups of mobile applications
SensifAI - AI driven image tagging
Serval-LR - SERVAL Long-range WiFi Add-on
Simmel - A wearable contact tracing beacon/scanner
SIPproxy64/6bed4 - 0cpm, SIPproxy64, 6bed4, applet, freeswitch RTT
Software Heritage - Collect, preserve and share the source code of all software ever written
Software vulnerability discovery - Automating discovery of software update and vulnerabilities
SOLID Data Workers - Toolkit to ingest data into SOLID
Solid-NextCloud app - Bridge Nextcloud to Solid
Sonar: a modular peer-to-peer search engine for the next-generation web - Modular peer-to-peer search engine
Spectrum - A security through compartmentalization based operating system
Standard Cell Library - Open Standard Cell Library with automated dimensioning of transistors
StreetComplete - Fix open geodata with OpenStreetMap
Stubby - A local DNS Privacy stub resolver using DNS-over-TLS
Suhosin-NG - Harness PHP 7 applications
Supersizing the Gun - Chipwhisperer open hardware for side channel analysis
Sylk Client - Secure multiparty videoconferencing application
Sylk Mobile - Secure real-time mobile communications
Tantum Search - Context-enhanced search driven by
TETRA cryptography analysis - Security Analysis of Proprietary Cryptography in Terrestrial Trunked Radio
The Libre RISC-V SoC, Formal Correctness Proofs - Mathematical unit tests for open hardware System-on-Chip
The Libre RISC-V SoC, Formal Standards Development - Formal Standards for RISC-V extensions from Libre RISC-V SoC
The Libre-RISCV SoC - A fully open hardware System-on-a-Chip
The Libre-RISCV SoC, Coriolis2 ASIC Layout Collaboration - Open tooling for ASIC Layout
The Libre-RISCV SoC, Video Acceleration - Optimised video acceleration instructions for Libre RISC-V SoC
The Open Green Web - Ethical meta-search filter on green hosted websites
Thunderbird - native EteSync integration using TbSync - Add encrypted sync to Thunderbird
TLS-KDH - Combined Kerberos and Diffie-Hellman as an authentication mechanism for TLS
TLS-KDH mbed - Implement TLS-KDH into mbed
Tooling to improve security and trust in GNU Guix - Contextual software vulnerability discovery
TOS;DR - A user rights initiative to rate and label website terms & privacy policies
Tracking Exposed - Increase transparency behind personalization algorithms
Tracking the Trackers - Automated scanning for spyware in mobile applications
Transparency Toolkit - A decentralized hosted archiving service with search
Trusted Boot Module - An open hardware trusted boot manager
Uberflow - An Open-Source OpenFlow Controller Implementing the North-Bound Interface
Universal DID Resolver and Registrar - Tooling for decentralized identifiers
URL Frontier - Develop a API between web crawler and frontier
ValOS Cryptographic Content Security project - Cryptographic Content Security for ValOS
variation graph (vgteam) - Privacy enhanced search within e.g. genome data sets
Verified Differential Privacy for Julia - Proving sound privacy guarantees through a type system
Verifpal - Prove soundness of verification in Verifpal
VFRAME: Visual Defense Tools - Use computer-vision to shield privacy in video
video box - Affordable open hardware video-to-network
Video chat privacy - Add privacy features to video chats
Virtualizing device firmware - Creating digital twins for auditing and testing appliances
Vita - A fast IPSEC-based VPN gateway
Vita - A high performance IPSEC implementation
Web Annotation - Building blocks for interoperable annotation systems
Web Shell - Desktop and security environment for web apps
WebXray Discovery - Expose tracking mechanism in search hubs
WireGuard - A fast and modern VPN that utilizes state-of-the-art cryptography
WireGuard - Scale up WireGuard
Wireguard - Take modern network tunnels to the next level
Wireguard Rust Implementation - Implementation of WireGuard in a type safe language
Wireguard Windows client - Native Wireguard protocol client for Windows
Wireguard Windows client - Wireguard Windows client
Wishbone Streaming - Add Streaming capabilities to Wishbone
WPIA CA Infrastructure - Deployment infrastructure for certificate authorities
XWiki - Bring wiki capabilities into the Fediverse
XWiki ActivityPub - First class ActivityPub support in XWiki
YaCy Grid SaaS - YaCy Grid SaaS
YunoHost and the Internet Cube - Solutions for DIY-ISP's and self-hosters
Zerocat Chipflasher Flashrom Interface - Hardware to flash alternative/libre firmware to BIOS chips
ZSipOs - Open hardware for telephony encryption