ClaraWideProvider transport safety QA
v0.12.36 · SCHEMA 35

Provider Transport Policy + TLS/Redirect Boundary

This gate proves Clara refuses transport changes that could bypass the approved provider origin: HTTP, alternate ports, hostname/SNI drift, method changes, redirect following, custom Host headers, disabled TLS, stale/missing DNS proof, and live transport before the production adapter is reviewed. No external provider request or TLS handshake is performed here.

SCHEMA

Transport schema

READYExpected schema v35.
AUTOMATED ATTACK PATHS

Transport boundary self-test

READYRuns the server-owned transport policy attack matrix.
VISIBLE QA FLOW

Exercise the transport boundary

GREEN means a safe preflight was accepted. EXPECTED BLOCK means Clara correctly stopped a dangerous transport change. RED means the test itself failed.

READYStart with a QA Transport Admin session.
QA transport policyLoad transport state to inspect HTTPS, redirect, TLS-intent and DNS freshness rules.
PREFLIGHT EVIDENCE

Allowed vs blocked transport

No transport preflights loaded yet.

IMMUTABLE EVIDENCE

Transport guard history

No transport events loaded yet.

PRODUCTION GATE — DO NOT FAKE

Real transport + TLS evidence

Leave these open until the selected production provider is connected through a reviewed live adapter, real HTTPS/TLS certificate and hostname validation is observed, redirect behavior is verified on the real runtime, DNS freshness is enforced, monitoring is connected, and public QA endpoints are disabled.

Recent transport QA runs

No QA runs recorded yet.

Evidence tools

Clearing browser evidence never rewrites server-owned transport preflight or event records.