Public Pages
Homepage, CAPPS routes, Guardian Shield, Health Shield, Trust Scanner, reports, proof pages and selected public docs.
CAPPS Access Boundary
This boundary separates the public CAPPS proof layer from repository files, deployment scripts, package metadata, validator code, private books, logs, admin APIs and source directories.
Allowed Surface
Homepage, CAPPS routes, Guardian Shield, Health Shield, Trust Scanner, reports, proof pages and selected public docs.
Aggregate-only JSON manifests that avoid child records, private identity records, private health records, contact data and raw messages.
Only explicitly routed public API endpoints are exposed, with size limits, JSON boundaries and sanitized responses where applicable.
Denied Surface
Hardening Gates
Fails if denied files or source directories appear inside the public bundle.
Fails if denied live paths return success instead of 404.
Public responses keep CSP, frame blocking, referrer blocking, nosniff, HSTS and permissions restrictions.
Private access must be separately approved, authenticated, audited and kept out of public fallback routing.