Authorized Local Defense Loop

Evidence validation

Each finding carries source class, capture, confidence, attribution and a redaction state before it can drive action.

Manual evidence capture

Add authorized evidence metadata to the configured Postgres backend. Public reads receive redacted summaries. This form does not fetch the URL or submit third-party requests; it stores a redacted evidence record through a server-side protected operator route.

protected server action

Uses the server-side environment PLATPHORM_API_KEY boundary. If Postgres or the server key is unavailable, the API returns a blocked/degraded result. externalActionTaken remains false for manual capture.

Evidence records

0

Screenshot captures

0

redacted, files://

Avg confidence

0%

Source view

protected

vercel_postgres · configured

No evidence records are available. Use the capture panel to persist authorized-local evidence metadata.

Evidence capture stores authorized metadata in Postgres when configured. Protected source inspection is rendered server-side only when PLATPHORM_API_KEY is available; the browser never receives the key. Public API record links remain redacted unless an API client supplies platform authorization.