Provider Transport Policy + TLS/Redirect Boundary
This gate proves Clara refuses transport changes that could bypass the approved provider origin: HTTP, alternate ports, hostname/SNI drift, method changes, redirect following, custom Host headers, disabled TLS, stale/missing DNS proof, and live transport before the production adapter is reviewed. No external provider request or TLS handshake is performed here.
Transport boundary self-test
Exercise the transport boundary
GREEN means a safe preflight was accepted. EXPECTED BLOCK means Clara correctly stopped a dangerous transport change. RED means the test itself failed.
Allowed vs blocked transport
No transport preflights loaded yet.
Transport guard history
No transport events loaded yet.
Real transport + TLS evidence
Leave these open until the selected production provider is connected through a reviewed live adapter, real HTTPS/TLS certificate and hostname validation is observed, redirect behavior is verified on the real runtime, DNS freshness is enforced, monitoring is connected, and public QA endpoints are disabled.
Recent transport QA runs
Evidence tools
Clearing browser evidence never rewrites server-owned transport preflight or event records.
