Security

Narrow access and fixed evidence are product controls.

IssueProbe connects public website reports to source evidence. Each boundary uses an explicit limit and fails closed when authority or evidence does not match.

Exact website origins

A copied public widget key cannot read configuration or submit a report from another origin.

Fixed browser evidence

Website settings can disable categories, but cannot add fields or enable cookie, form, or local-storage values.

Visitor screenshot approval

A screenshot needs a visible visitor action, a preview, and explicit inclusion approval.

Read-only repository key

Each website receives one separate public deploy key for read-only source access.

Bounded investigation

Each eligible report has time, source, file, and action limits. The result can state that the cause is unknown.

Human review

A human reviews every draft response and production action. IssueProbe does not send a visitor reply.

Scoped agent access

An agent needs explicit owner approval, narrow scopes, an expiry, and a revocable API credential.

Hosted billing

Checkout and subscription management use exact Stripe-hosted HTTPS pages. IssueProbe does not receive card data.

Evidence and certainty

A conclusion cannot outrun its evidence.

A likely or confirmed conclusion needs registered source evidence. A confirmed conclusion also needs direct visitor-browser evidence. Important unknown facts stay visible.

See the result structure

Owner control remains final

  • Review the visitor report and safe evidence.
  • Read each source citation and conclusion limit.
  • Edit the draft response without changing the result.
  • Approve every response and production action.
  • Revoke each agent credential when access ends.

Need the exact public API contract?

The reference documents authentication, scopes, idempotency, request limits, and safe errors.

Read the API reference