Personal Exposure Defense Cockpit

Service provisioning center

Secure communications, Cloudflare, AWS, SCC, mail, partner and reporting service scaffolds.

UI scaffoldOpen cockpit
Synthetic principal scenario. All identifiers are reserved or fictional. No real people are scraped or enriched.
Authorized scopeHuman approval requiredNo live scrapingNo external sendingNo real personal data

One authorized client, one real exposure-defense loop, zero fake actions.

Required services are prepared, labeled and blocked before real provisioning.

Principal

Jordan Hale

synthetic-principal-001

Findings

12

case-state fallback

StealthScore

54 -> 78

rubric estimate

External actions

0

human approval required

Loop proof

Evidence that this screen supports the Jordan Hale defense loop.

12 service categories
owners
due days
protected actions

State declaration

No surface claims a live action that is not wired.

UI scaffoldNeeds envProtected actionWaiting partner

Any outside-world touch remains protected, gated, or dry-run. Scaffolded controls can acknowledge intent locally but do not send, provision, upload, scan, call, publish, or mutate external systems.

Capability proof

Route-level proof that this screen stays inside the Jordan Hale loop.

operate

Service provisioning center

UI scaffold

A service setup center that shows what infrastructure the case needs and what is blocked before real provisioning.

Real today

The center renders service cards with owners, due days, related findings, protected flags, and next actions.

Scaffolded

Provider calls, resource creation, queue workers, partner completion, and real service activation are not executed in this UI phase.

12 service categories
Owners
No resource has been provisioned
No provider key is exposed

externalActionTaken: false. No external action is triggered from this route.

operate

SCC provisioning

UI scaffold

A configurable service class for secure client communications, case containers, cover coordination, or special client controls.

Real today

The route renders a clear SCC scaffold and avoids legal claims or automatic completion.

Scaffolded

Human/partner completion, document review, and service activation require protected workflow and partner handoff integration.

SCC type
Required documents
Human/partner completion required
No provisioning success is claimed

externalActionTaken: false. No external action is triggered from this route.

operate

Cloudflare posture

Needs env

A domain security planning panel for DNS, WAF, bot defense, Turnstile, redirects, and security headers.

Real today

The panel renders checklist and recommendation scaffolds without Cloudflare credentials.

Scaffolded

Cloudflare API calls, WAF rule creation, Turnstile setup, and DNS mutation require protected backend integration.

DNS checklist
WAF plan
No Cloudflare API call is made
No resource has been provisioned

externalActionTaken: false. No external action is triggered from this route.

evidence

AWS evidence storage

UI scaffold

A storage map for evidence, screenshots, reports, retention policy, encryption, and access controls.

Real today

The UI shows storage classes and redaction-before-upload requirements with no AWS keys client-side.

Scaffolded

Presigned URLs, uploads, object-lock controls, lifecycle policies, and storage health checks require backend services.

Storage map
Upload queue
No AWS keys client-side
No fake upload success

externalActionTaken: false. No external action is triggered from this route.

operate

SendGrid mail provisioning

UI scaffold

A mail setup checklist that explains DNS and template readiness without pretending email delivery works.

Real today

The route renders mail setup steps and dry-run email templates only.

Scaffolded

SendGrid credentials, DNS verification, mailbox provisioning, and email delivery require backend work and approval.

SPF checklist
DKIM checklist
No fake delivered state
No email is sent

externalActionTaken: false. No external action is triggered from this route.

Support mode

5

Capabilities

1

Docker

1

Vercel

Postgres can persist support and audit facts locally or on Vercel. Deployments without DATABASE_URL stay public-safe and degraded.

integration

Provider provisioning

Protected action
Local Postgres: degradedVercel: degraded

Cloudflare, AWS, SCC, and mail controls produce scaffold/protected responses only.

No resource has been provisioned.

externalActionTaken: false

integration

External service actions

UI scaffold
Local Postgres: degradedVercel: degraded

Jitsi, Twilio, SendGrid, Cloudflare, AWS, SCC, scan, and submit tools all return implemented:false.

Every external action remains scaffolded/protected until intentionally wired.

externalActionTaken: false

safety

Responsible-use gates

Connected
Local Postgres: supportedVercel: supported

Sensitive UI controls and MCP tools state human approval and externalActionTaken:false.

Safety gates remain active in fixture mode.

externalActionTaken: false

Service cards

Every card declares owner, dependency and protected status.

Comms

Secure Client Communications

UI scaffold

Encrypted, auditable channel between operator and protected client.

Provider
Cloak Harbor
Owner
Platform
Target
Day 1
Next: Wire transport + audit log

Network

Edge / WAF

UI scaffold

Firewall, IP allowlisting and bot mitigation in front of the cockpit.

Protected
Provider
Cloudflare
Owner
Platform
Target
Day 0
Next: Add CLOUDFLARE_API_TOKEN

Storage

Evidence Object Store

UI scaffold

Write-once, redaction-aware evidence vault with retention controls.

EXP-001EXP-002
Provider
AWS S3 / Vercel Blob
Owner
Platform
Target
Day 1
Next: Connect blob storage

Comms

Transactional Mail

Dry-run

Outbound notice delivery — dry-run only in the demo.

Human reviewProtectedEXP-002EXP-005
Provider
SendGrid
Owner
Operations
Target
Day 2
Next: Approve before any send

Comms

SMS / Voice

Dry-run

Client notifications and verification — dry-run only in the demo.

Human reviewProtected
Provider
Twilio
Owner
Operations
Target
Day 2
Next: Approve before any send

Comms

Secure Meeting

UI scaffold

Private operator/client briefings with agenda and audit trail.

Provider
Jitsi
Owner
Operations
Target
Day 7
Next: Embed room + agenda

Discovery

Web Exposure Scan

UI scaffold

Consented surface scan against the principal's known identifiers.

ProtectedEXP-003EXP-007
Provider
Cloak Harbor
Owner
Discovery
Target
Day 1
Next: Wire worker + rate limits

Platform

Job Queue / Workers

Future

Durable workers for scans, re-checks and webhook delivery.

Provider
Vercel / Upstash
Owner
Platform
Target
Day 14
Next: Roadmap

Security

Endpoint Hygiene

Ready for review

Credential rotation, passkeys, device hygiene and account recovery separation.

Human reviewEXP-007
Provider
Cloak Harbor checklist
Owner
Cloak analyst
Target
Day 1
Next: Review EXP-007 with client

Network

VPN / Privacy Networking

Future

Reduce network and identifier linkage where appropriate for the protected principal.

Human reviewProtectedEXP-011
Provider
Partner
Owner
Partner
Target
Day 14
Next: Scope after pilot

Partner

Legal / Trust Partner

Waiting partner

Registered-agent substitution, property record review and cover entity coordination.

Human reviewProtectedEXP-002EXP-005
Provider
Legal / trust partner
Owner
Legal/Trust partner
Target
Day 7
Next: Partner review required

Remediation

Data Broker Opt-Out

Ready for review

Suppress people-search, phone and household exposure records.

Human reviewProtectedEXP-001EXP-003EXP-006EXP-012
Provider
Broker operators
Owner
Cloak analyst
Target
Day 2
Next: Draft requests; do not submit

Monitoring

Recurrence Monitoring

UI scaffold

Re-check suppressed sources and report re-exposure without unbounded crawling.

ProtectedEXP-001EXP-006EXP-012
Provider
Cloak Harbor
Owner
Cloak analyst
Target
Day 14
Next: Schedule recurrence watch

Reporting

Executive Reporting

Connected

Generate before/after report and evidence-linked proof for the principal.

Human reviewProtected
Provider
Cloak Harbor
Owner
Cloak analyst
Target
Day 30
Next: Review report draft

Evidence, risk, work, approval, report

The single loop remains visible from every route.

Cloak Harbor Personal Exposure DefenseProduction pilotHuman approval requiredNo live scrapingNo external sendingResponsible-use policy