System status

Cloak Harbor Personal Exposure Defense surfaces. We show honest states — live, degraded, planned or missing environment configuration — and never present fallback fixtures as live data.

Cloak Harbor operational · authorized_local · externalActionTaken:false

Persistence

  • Postgres case backendLive

    Durable principal, evidence, findings, Kanban, report and intent storage.

    config: aurora/postgres connection

Case Management

  • Case KanbanLive

    Local case task creation and lane movement backed by the active case-state store.

    config: aurora/postgres connection

  • Case calendarLive

    Case cadence derived from persisted remediation tasks.

    config: aurora/postgres connection

Reporting / Handoff

  • Executive reportsLive

    Case-derived report generation and human-review intents persisted locally.

    config: aurora/postgres connection

  • DocsLive

    Publish approved case-derived executive reports to the Docs service.

    config: server operator credential, protected handoff flag

  • SheetsLive

    Export approved findings, risk scores and task matrices to Sheets.

    config: server operator credential, protected handoff flag

  • FilesLive

    Upload approved reports, evidence bundles, and public media candidate manifests to Files.

    config: server operator credential, protected handoff flag

Deployment

  • Visibility policyLive

    Runtime flag for redacted, private, or public authorized case data surfaces.

    config: cloak visibility mode

  • Vercel runtimeLive

    Production request/runtime metadata and deployment environment awareness.

  • Vercel Connect OAuthPlanned

    Delegated provider authorization through Vercel Connect. Cloak Harbor keeps provider tokens server-side and exposes only authorization and token-metadata status.

    config: server secret

Evidence Storage

  • Public media captureLive

    Bounded public-photo candidate manifests stored through Files for authorized case review.

    config: cloak public media capture, server operator credential, protected handoff flag

  • Vercel Blob evidence storageLive

    Server-side private artifact storage for OSINT run packets, evidence bundles, exports, and screenshots.

    config: server secret

  • AWS evidence vaultLive

    Server-side AWS object-store credentials for evidence vault workflows.

    config: aws access id, server secret

  • HunchlyLive

    Local Hunchly export indexer for protected evidence review when a desktop export directory is configured.

    config: hunchly export dir

Auditability

  • TraceLive

    Export protected operation lifecycles, tool calls, W3C parentage, and public-safe evidence into Trace.

    config: server operator credential, protected handoff flag

  • MonitorLive

    Availability and recurrence monitoring for the public-safe Cloak Harbor surface.

    config: server operator credential, protected handoff flag

Exposure Discovery

  • BrowserOpsLive

    Run browser journeys, screenshots and public-safe capture workflows for authorized cases.

    config: server operator credential, protected handoff flag

  • SearchOpsLive

    Bounded exposure discovery and recurrence monitoring for authorized identifiers.

    config: server operator credential, protected handoff flag

  • Wayback evidenceMissing env

    Server-side archive checks for authorized public evidence and historical source links.

    config: server secret · missing server secret

  • Numverify phone validationLive

    Server-side APILayer Numverify validation for authorized onboarding phone identifiers, with evidence, Kanban, webhook, and Sandbox records.

    config: server secret

  • ACE correlation mapLive

    Local graph-aware correlation scoring over authorized client identifiers with explainable remediation planning.

    config: aurora/postgres connection

  • Sherlock ProjectMissing env

    Local Sherlock CLI adapter for authorized username and alias correlation checks.

    config: sherlock bin · missing sherlock bin

  • SpiderFootMissing env

    Local SpiderFoot command adapter for authorized domain, email, and entity pivots.

    config: spiderfoot bin · missing spiderfoot bin

  • EpieosLive

    Human-review queue for authorized email and phone checks until an approved server API contract is added.

    config: aurora/postgres connection

  • IntelTechniquesLive

    Cloak-owned source playbook automation inspired by public OSINT workflows; generates evidence links and approval tasks for authorized identifiers.

    config: aurora/postgres connection

  • Recovery-answer exposure reviewLive

    Defensive LLM-assisted review queue for public clues that may weaken password recovery questions. It never stores actual answer values.

    config: aurora/postgres connection

  • Overpass TurboLive

    Bounded OpenStreetMap address-surface review for authorized address identifiers.

    config: aurora/postgres connection

Evidence Validation

  • TrustOpsLive

    Evidence confidence, false-positive review and trusted-domain validation.

    config: server operator credential, protected handoff flag

  • SpecLive

    Local schema and contract validation for findings, evidence and action packets.

  • EvalsLive

    Score risk-rubric consistency, release readiness and action-packet quality.

    config: server operator credential, protected handoff flag

  • Public filings / PACERLive

    SEC EDGAR and PACER-style source-link queue for authorized entity, domain, and name review.

    config: aurora/postgres connection

Agent-Safe Operations

  • ClawsLive

    Agentic remediation requests that remain protected and human-gated.

    config: server operator credential, protected handoff flag

  • SandboxLive

    Safe replay and dry-run execution for action packets.

    config: server operator credential, protected handoff flag

  • WebhookLabLive

    Webhook simulation and delivery testing for protected events.

    config: server operator credential, protected handoff flag

  • WebhooksLive

    Protected local event emission, HMAC signing, optional delivery target, and Postgres delivery ledger for case lifecycle events.

    config: aurora/postgres connection

  • AgentUILive

    Agent-facing workflow validation and human-machine handoff review surfaces.

    config: server operator credential, protected handoff flag

  • Vercel Sandbox diagnosticsLive

    Optional isolated diagnostics for redacted OSINT run packets using deny-all network policy.

    config: cloak enable vercel sandbox

  • Drafting gatewayPlanned

    Provider routing for human-reviewed drafts. Template fallback remains available when missing.

    config: server secret

  • Drafting provider fallbacksMissing env

    Server-side fallback credentials for provider-specific workflows when Gateway is unavailable.

    config: server secret · missing server secret

  • PentestLive

    Authorized OSINT and surface-assessment handoff through the JC PenTest Harness MCP.

    config: server operator credential, protected handoff flag

Topology

  • AtlasLive

    Cross-site topology and relationship context for Cloak Harbor workflows.

    config: server operator credential, protected handoff flag

Payment

  • Stripe paywallPlanned

    Server-side Stripe Checkout, webhook receipts, and paid-plan entitlement handoff for Custom Cloak.

    config: server secret

  • Stripe MCPPlanned

    Optional server-side Stripe MCP credential for operator-assisted billing investigation and future entitlement automation.

    config: server secret

Communications

  • Twilio communicationsMissing env

    Approved phone verification and client-notification workflows from server-side routes.

    config: server secret · missing server secret