Defensive boundaries

Useful intelligence without crossing the line.

TraceLattice is constrained to bounded passive analysis of public web origins.

Bounded defensive analysis. TraceLattice samples up to three public same-origin pages plus visible DNS, TLS, header, cookie, and resource signals. It does not execute target JavaScript, authenticate, exploit, or determine legal compliance.

Public web only

Localhost, private networks, internal names, embedded credentials, and non-web protocols are rejected.

Redirect-aware SSRF defense

DNS results and every redirect destination are validated before a request proceeds.

Bounded requests

Three redirects, nine seconds, standard ports, and a 1.5 MB response ceiling.

Data minimization

No HTML is retained. Cookie values are discarded. Browser history stores summaries only.

No offensive behavior

No broad crawling, exploitation, brute force, bypass, payload injection, or vulnerability attacks.

Responsible output

Findings are educational, evidence-based, and paired with limitations rather than compliance claims.

Acceptable use

Use TraceLattice on public websites for educational review, defensive engineering, and vendor evaluation. Do not use it to harass operators, evade controls, target private systems, or represent heuristic output as a professional audit or legal conclusion.