Public web only
Localhost, private networks, internal names, embedded credentials, and non-web protocols are rejected.
TraceLattice is constrained to bounded passive analysis of public web origins.
Bounded defensive analysis. TraceLattice samples up to three public same-origin pages plus visible DNS, TLS, header, cookie, and resource signals. It does not execute target JavaScript, authenticate, exploit, or determine legal compliance.
Localhost, private networks, internal names, embedded credentials, and non-web protocols are rejected.
DNS results and every redirect destination are validated before a request proceeds.
Three redirects, nine seconds, standard ports, and a 1.5 MB response ceiling.
No HTML is retained. Cookie values are discarded. Browser history stores summaries only.
No broad crawling, exploitation, brute force, bypass, payload injection, or vulnerability attacks.
Findings are educational, evidence-based, and paired with limitations rather than compliance claims.
Use TraceLattice on public websites for educational review, defensive engineering, and vendor evaluation. Do not use it to harass operators, evade controls, target private systems, or represent heuristic output as a professional audit or legal conclusion.