# Daylight — a public watchdog for federal .gov infrastructure > Daylight is a public, observational watchdog for United States federal .gov infrastructure. It reads only already-public data — CISA's official .gov ownership registry, Certificate Transparency logs, and live public page source — and keeps a timestamped, source-linked record of who owns each federal domain, what certificates and subdomains appear, what trackers run on public pages, and what quietly changed or was removed. Every claim links the exact public artifact it was read from. As of 2026-07-29 it tracks 1,338 federal .gov domains with 12,826 recorded changes. Daylight is observational and built entirely on public data. It never authenticates past an access wall, guesses credentials, probes, port-scans, or crawls — it records that things exist and how they change. Copy stays neutral and factual ("no published privacy filing was found as of {date}; searches shown"), never accusatory. It is not a government site and is not affiliated with any agency. ## Core pages - [Home](https://daylight.watch/): Front door and recent activity across all modules. - [Registry](https://daylight.watch/registry): Search who owns each federal .gov domain, from CISA's public dotgov-data. - [Domain dashboard](https://daylight.watch/domain/vote.gov): Composite per-domain record — ownership, certificates, trackers, and filing status. Replace `vote.gov` in the path with any federal .gov domain. - [Ledger](https://daylight.watch/ledger): Every change to .gov ownership and security contacts, diffed daily from the registry. - [Lookout](https://daylight.watch/lookout): New federal .gov subdomains the day their TLS certificate first appears in public Certificate Transparency logs. - [Floodlight](https://daylight.watch/floodlight): Trackers, session replay, and analytics disguised as first-party traffic on public .gov pages. - [Receipts](https://daylight.watch/receipts): A dated, archived removal ledger — what privacy notice, seal, tracker, or form field was present and then vanished. - [Redtape](https://daylight.watch/redtape): Federal .gov collections of personal data with no published Privacy Impact Assessment or SORN found (human-reviewed). - [Foundry](https://daylight.watch/foundry): Which build vendors quietly serve many federal agencies at once, and what is staged but not yet launched. ## Reference - [Methods & sources](https://daylight.watch/methods): Every public data source Daylight reads, its bot's identity and politeness, and its observational-only scope and guardrails. - [FAQ & glossary](https://daylight.watch/faq): Common questions (who owns a .gov, is it tracking me) and definitions — PIA, SORN, Certificate Transparency, session replay, reverse-proxied analytics. - [Watchlist](https://daylight.watch/watchlist): The priority domains, comparators, and watches that drive the modules. - [Corrections](https://daylight.watch/corrections): Public retraction ledger — every correction, dated. - [Status](https://daylight.watch/status): Live health of the watchers. - [Privacy](https://daylight.watch/privacy): First-party, aggregate-only analytics; no IP, user-agent, or cookie is ever stored. ## Data & feeds - [JSON API](https://daylight.watch/api/v1/changes): Public read API — changes, domains, subdomains, scorecards, and gaps under /api/v1. - [Global RSS feed](https://daylight.watch/feed.xml): Every observed change as RSS. Per-module feeds exist at /{module}/feed.xml. - [Global JSON Feed](https://daylight.watch/feed.json): Every observed change as JSON Feed. ## About & contact - Source code and issues: https://github.com/kevstauss/daylight - Contact: contact@daylight.watch - Canonical site: https://daylight.watch