System status
Cloak Harbor Personal Exposure Defense surfaces. We show honest states — live, degraded, planned or missing environment configuration — and never present fallback fixtures as live data.
Persistence
- Postgres case backendLive
Durable principal, evidence, findings, Kanban, report and intent storage.
config: aurora/postgres connection
Case Management
- Case KanbanLive
Local case task creation and lane movement backed by the active case-state store.
config: aurora/postgres connection
- Case calendarLive
Case cadence derived from persisted remediation tasks.
config: aurora/postgres connection
Reporting / Handoff
- Executive reportsLive
Case-derived report generation and human-review intents persisted locally.
config: aurora/postgres connection
- DocsLive
Publish approved case-derived executive reports to the Docs service.
config: server operator credential, protected handoff flag
- SheetsLive
Export approved findings, risk scores and task matrices to Sheets.
config: server operator credential, protected handoff flag
- FilesLive
Upload approved reports, evidence bundles, and public media candidate manifests to Files.
config: server operator credential, protected handoff flag
Deployment
- Visibility policyLive
Runtime flag for redacted, private, or public authorized case data surfaces.
config: cloak visibility mode
- Vercel runtimeLive
Production request/runtime metadata and deployment environment awareness.
- Vercel Connect OAuthPlanned
Delegated provider authorization through Vercel Connect. Cloak Harbor keeps provider tokens server-side and exposes only authorization and token-metadata status.
config: server secret
Evidence Storage
- Public media captureLive
Bounded public-photo candidate manifests stored through Files for authorized case review.
config: cloak public media capture, server operator credential, protected handoff flag
- Vercel Blob evidence storageLive
Server-side private artifact storage for OSINT run packets, evidence bundles, exports, and screenshots.
config: server secret
- AWS evidence vaultLive
Server-side AWS object-store credentials for evidence vault workflows.
config: aws access id, server secret
- HunchlyLive
Local Hunchly export indexer for protected evidence review when a desktop export directory is configured.
config: hunchly export dir
Auditability
- TraceLive
Export protected operation lifecycles, tool calls, W3C parentage, and public-safe evidence into Trace.
config: server operator credential, protected handoff flag
- MonitorLive
Availability and recurrence monitoring for the public-safe Cloak Harbor surface.
config: server operator credential, protected handoff flag
Exposure Discovery
- BrowserOpsLive
Run browser journeys, screenshots and public-safe capture workflows for authorized cases.
config: server operator credential, protected handoff flag
- SearchOpsLive
Bounded exposure discovery and recurrence monitoring for authorized identifiers.
config: server operator credential, protected handoff flag
- Wayback evidenceMissing env
Server-side archive checks for authorized public evidence and historical source links.
config: server secret · missing server secret
- Numverify phone validationLive
Server-side APILayer Numverify validation for authorized onboarding phone identifiers, with evidence, Kanban, webhook, and Sandbox records.
config: server secret
- ACE correlation mapLive
Local graph-aware correlation scoring over authorized client identifiers with explainable remediation planning.
config: aurora/postgres connection
- Sherlock ProjectMissing env
Local Sherlock CLI adapter for authorized username and alias correlation checks.
config: sherlock bin · missing sherlock bin
- SpiderFootMissing env
Local SpiderFoot command adapter for authorized domain, email, and entity pivots.
config: spiderfoot bin · missing spiderfoot bin
- EpieosLive
Human-review queue for authorized email and phone checks until an approved server API contract is added.
config: aurora/postgres connection
- IntelTechniquesLive
Cloak-owned source playbook automation inspired by public OSINT workflows; generates evidence links and approval tasks for authorized identifiers.
config: aurora/postgres connection
- Recovery-answer exposure reviewLive
Defensive LLM-assisted review queue for public clues that may weaken password recovery questions. It never stores actual answer values.
config: aurora/postgres connection
- Overpass TurboLive
Bounded OpenStreetMap address-surface review for authorized address identifiers.
config: aurora/postgres connection
Evidence Validation
- TrustOpsLive
Evidence confidence, false-positive review and trusted-domain validation.
config: server operator credential, protected handoff flag
- SpecLive
Local schema and contract validation for findings, evidence and action packets.
- EvalsLive
Score risk-rubric consistency, release readiness and action-packet quality.
config: server operator credential, protected handoff flag
- Public filings / PACERLive
SEC EDGAR and PACER-style source-link queue for authorized entity, domain, and name review.
config: aurora/postgres connection
Agent-Safe Operations
- ClawsLive
Agentic remediation requests that remain protected and human-gated.
config: server operator credential, protected handoff flag
- SandboxLive
Safe replay and dry-run execution for action packets.
config: server operator credential, protected handoff flag
- WebhookLabLive
Webhook simulation and delivery testing for protected events.
config: server operator credential, protected handoff flag
- WebhooksLive
Protected local event emission, HMAC signing, optional delivery target, and Postgres delivery ledger for case lifecycle events.
config: aurora/postgres connection
- AgentUILive
Agent-facing workflow validation and human-machine handoff review surfaces.
config: server operator credential, protected handoff flag
- Vercel Sandbox diagnosticsLive
Optional isolated diagnostics for redacted OSINT run packets using deny-all network policy.
config: cloak enable vercel sandbox
- Drafting gatewayPlanned
Provider routing for human-reviewed drafts. Template fallback remains available when missing.
config: server secret
- Drafting provider fallbacksMissing env
Server-side fallback credentials for provider-specific workflows when Gateway is unavailable.
config: server secret · missing server secret
- PentestLive
Authorized OSINT and surface-assessment handoff through the JC PenTest Harness MCP.
config: server operator credential, protected handoff flag
Topology
- AtlasLive
Cross-site topology and relationship context for Cloak Harbor workflows.
config: server operator credential, protected handoff flag
Payment
- Stripe paywallPlanned
Server-side Stripe Checkout, webhook receipts, and paid-plan entitlement handoff for Custom Cloak.
config: server secret
- Stripe MCPPlanned
Optional server-side Stripe MCP credential for operator-assisted billing investigation and future entitlement automation.
config: server secret
Communications
- Twilio communicationsMissing env
Approved phone verification and client-notification workflows from server-side routes.
config: server secret · missing server secret
