Personal Security Checklist: 300+ Verifiable Digital Privacy Tips in One YAML File
đź”’ A compiled checklist of 300+ tips for protecting digital security and privacy in 2026
At a glance
- What is it?
- The Personal Security Checklist by Alicia Sykes is a community-maintained dataset of 300+ digital security and privacy tips, delivered as a YAML source file, an auto-generated Markdown document, a self-hostable Qwik web application with threat-model filtering, and a free public REST API. Engineers who need to audit personal security posture or build a security-awareness tool have all three formats generated from a single source of truth.
- Who is it for?
- Individuals who want a structured way to review and track their personal digital security will find this the most direct starting point: open CHECKLIST.md in the repository or use digital-defense.io and filter by the threats relevant to your situation. Engineers building a security-awareness application can consume the free REST API without cloning anything.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 22 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What the Personal Security Checklist Covers and Who Uses It
Most digital security advice is scattered across blog posts and vendor documentation. The Personal Security Checklist consolidates actionable tips into a single, structured resource aimed at individual users rather than enterprise security teams. The repository description calls it a compiled checklist of 300+ tips for protecting digital security and privacy in 2026.
The intended audience is anyone who wants to audit their own digital habits: password management, two-factor authentication, browser settings, device encryption, and similar personal-scope actions. The website at digital-defense.io allows users to filter tips by their specific threat model and tick off items as they complete them, with progress charts visible as they work through the list.
Engineers can use it as a starting point for building their own security-awareness tooling. The YAML data file and the free REST API make the checklist consumable without any preprocessing, and the MIT license imposes no restriction on building something on top of the data.
How the Checklist Data Is Structured and Maintained
All tip data lives in a single file: personal-security-checklist.yml at the root of the repository. The README describes this as the single source that is pulled in at website build time and referenced by the API. The Markdown file CHECKLIST.md is auto-generated from that YAML by running a Python script.
The repository includes a Makefile that exposes the most common operations as short commands. Running make validate checks your edits against the schema defined in lib/schema.json using the lib/validate.py script. Running make generate rebuilds CHECKLIST.md from the current YAML data.
make validatemake generateThe Makefile also bootstraps a Python virtual environment automatically: the first time you run either command, it creates .venv and installs the requirements listed in lib/requirements.txt.
This architecture means that a contributor who only wants to add or modify a tip edits personal-security-checklist.yml and nothing else. The Markdown document and the website both pick up the change at their next build. The README asks contributors to provide references backing up any information they add, amend, or remove.
Running the Website Locally and Deploying It Yourself
The web application lives in the web/ subdirectory of the repository. It is built with Qwik and TypeScript, using DaisyUI for component styling. Node 20.19 or newer (or 22.12 or newer) and Git are the documented prerequisites.
To run it locally:
git clone [email protected]:Lissy93/personal-security-checklist.git
cd personal-security-checklist/web
yarn
yarn devThe development server starts with hot reloading. To produce a static build:
yarn build.ssgThe build output lands in web/dist/, which you can copy to any CDN, web server, or static hosting provider. The README also mentions one-click deployment options for providers that can import a GitHub repository directly. A Dockerfile at the repository root covers containerized deployments.
The Makefile provides web.dev, web.build, and web.check as convenience targets that run the yarn commands above from the repository root, so you do not need to cd into web/ manually.
The Threat-Model Filter and How the Website Works
The digital-defense.io website adds filtering that the raw CHECKLIST.md does not provide. Visitors can select a threat model that matches their situation (for example, protecting against account takeover versus protecting against physical device access) and the website narrows the visible checklist items to those relevant to that model. Items can be ticked off as complete, and a progress chart shows how far through the relevant items the user has gotten.
The README does not document a mechanism for exporting that progress or syncing it across devices. Each browser session appears to maintain its own state. This is a real constraint: a user who reads the checklist on a laptop and then switches to a phone starts fresh on the second device.
The web/ source is built with Qwik, which is a TypeScript framework designed for fast initial rendering. The README does not document the specifics of what makes the site fast, but the architecture choice is noted in the README's About section.
The Free API and Programmatic Access to Checklist Data
The project exposes a free public REST API hosted at digital-defense.io. The base URL is digital-defense.io/api, and the README documents four endpoint patterns:
- /api/checklists: returns all checklists - /api/checklists/[name-or-index]: returns a single checklist by name or numeric index - /api/checklists/[name]/[point-index]: returns an individual point within a named checklist - /api/search/[searchterm]: returns checklist points matching a search term
The README links to Swagger documentation for trying out the API interactively. No authentication is documented, which means any application can query the data without obtaining a key.
This API is most useful for applications that want to present security guidance to users without maintaining their own copy of the checklist. Because the source YAML in the repository is what the API serves, updating the API's data means contributing to the repository rather than operating a separate data pipeline.
A Real Limitation: No Enforcement and No Cross-Device Sync
The checklist documents what to do; it does not verify whether any item has actually been done. There is no agent that inspects your device settings, scans your accounts, or confirms that a particular configuration is in place. An item marked as complete on the website reflects the user's self-assessment, not a measured state.
This separates the Personal Security Checklist from tools like CIS-CAT (the Center for Internet Security's configuration assessment tool) or OS-specific hardening scripts, which apply or verify settings programmatically. Those tools require administrative access to the machine they are run on and produce a pass/fail report. The checklist is a reading and self-reflection tool, not an auditing agent.
As noted above, progress is not synchronized across devices. The README does not document a user account system or an export mechanism, so a user who wants to track their progress over time must return to the same browser on the same device.
Alternatives and Licensing
The most direct alternative is a printed or PDF security guide, such as the ones published by national cybersecurity agencies (CISA in the United States or NCSC in the United Kingdom). Those resources are authoritative but static: they cannot filter by threat model, cannot be ticked off, and cannot be extended by community contributors. The Personal Security Checklist's YAML-backed approach lets contributors submit a pull request to add or correct a tip, and the change propagates to the website and API at the next build.
For enterprise environments, frameworks like the CIS Benchmarks or NIST SP 800-53 serve a different purpose: they target organizations and systems rather than individual users, and they come with detailed technical controls rather than short actionable tips.
The project is MIT-licensed and copyright is attributed to Alicia Sykes. The MIT license permits use, copying, modification, and distribution without further restriction. The last push to the repository was on 2026-09-07, meaning the repository received a commit within the past month and is not archived.
Editorial conclusion
Individuals who want a structured way to review and track their personal digital security will find this the most direct starting point: open CHECKLIST.md in the repository or use digital-defense.io and filter by the threats relevant to your situation. Engineers building a security-awareness application can consume the free REST API without cloning anything. The checklist does not enforce any setting or detect vulnerabilities; before treating any item as complete, verify the specific setting in the tool or service it refers to.
Frequently asked questions
How is the Personal Security Checklist data organized?
All tips are stored in personal-security-checklist.yml as the single source of truth. Running make generate rebuilds CHECKLIST.md from that YAML, and the website pulls the same file at build time. A schema in lib/schema.json can be checked against your edits by running make validate.
How do I run the Personal Security Checklist website locally?
Clone the repository, navigate to personal-security-checklist/web, run yarn to install dependencies, then yarn dev to start the development server. Node 20.19 or newer is required. To produce a static build, run yarn build.ssg; the output lands in web/dist/.
Does the Personal Security Checklist have a public API?
Yes. The API is hosted at digital-defense.io/api and exposes endpoints for listing all checklists, fetching a single checklist by name or index, retrieving individual checklist points, and searching by term. The README links to Swagger documentation for interactive exploration. No authentication is documented.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/lissy93-personal-security-checklist)