Provider Adapter Contract + TLS Certificate Evidence Foundation
This gate binds Clara’s already-approved transport preflight to a reviewed adapter contract and immutable TLS evidence. It rejects adapter-key drift, method changes, redirect following, weakened TLS/hostname/certificate validation, invalid certificate evidence, observed redirects, and missing transport proof. This QA release still performs no live provider network dispatch and no real TLS handshake.
Adapter + TLS self-test
Exercise the adapter/TLS boundary
GREEN means the safe adapter contract and deterministic QA evidence were accepted. EXPECTED BLOCK means Clara correctly stopped a weakened adapter or TLS claim. RED means the test itself failed.
Approved vs rejected contracts
No adapter reviews loaded yet.
Certificate + hostname claims
No TLS evidence loaded yet.
Adapter/TLS guard history
No adapter events loaded yet.
Real adapter + runtime TLS evidence
Leave these open until a real production provider is selected, the actual deployed adapter is reviewed, its code digest is pinned, Cloudflare-runtime HTTPS/TLS validation is observed against the real provider, redirects remain blocked, monitoring and recovery are proven, and public QA endpoints are disabled. Deterministic QA TLS evidence is not production handshake evidence.
Recent adapter QA runs
Evidence tools
Clearing browser evidence never rewrites server-owned adapter review, TLS evidence, or adapter event records.
