{"ok":true,"data":{"service":"pentest","version":"1.2.0","environment":"production","status":"ok","timestamp":"2026-07-21T08:53:51.470Z","database":{"status":"ok","configured":true,"driver":"neon","message":"Database query succeeded"},"mcp":{"status":"ok","endpoint":"/api/mcp"},"routeComplianceScore":63,"discoveryStatus":"ok","rssStatus":"ok","sitemapStatus":"ok","llmsStatus":"ok","openapiStatus":"ok","trustedDomainStatus":"platphormnews.com only by default","traceEnabled":true,"traceExportEnabled":false,"traceContextAccepted":true,"traceContextPropagated":true,"redactionStatus":"x-vercel-ja4-digest and IP-like headers are hashed/redacted","vercelMetadataCaptured":true,"functionRuntime":{"runtime":"nodejs","provider":"@vercel/functions","waitUntil":true,"backgroundAuditEvents":true},"providerSelection":{"version":1,"service":{"id":"pentest","name":"JC PenTest Harness","purpose":"Evidence-first, human-in-the-loop web cockpit for the Jean-Claude multi-model pentest harness.","productionUrl":"https://pentest.platphormnews.com","defaultSiteUrl":"https://pentest.platphormnews.com","trustedDomainSuffix":".platphormnews.com"},"selected":{"platform":"platphorm","deployment":"vercel","database":"neon-postgres","storage":"local-plus-platphorm-files","sandbox":"platphorm-sandbox","webhooks":"vercel-functions","aiGateway":"vercel-ai-gateway"},"providers":{"platform":{"id":"platphorm","label":"PlatPhorm","kind":"operator-platform","status":"selected","authEnv":"PLATPHORM_API_KEY","baseDomain":"platphormnews.com","services":[{"id":"docs","label":"PlatPhorm Docs","url":"https://docs.platphormnews.com","capability":"publish reports and operator documentation"},{"id":"sheets","label":"PlatPhorm Sheets","url":"https://sheets.platphormnews.com","capability":"export structured findings and scorecards"},{"id":"files","label":"PlatPhorm Files","url":"https://files.platphormnews.com","capability":"store protected run artifacts"},{"id":"trace","label":"PlatPhorm Trace","url":"https://trace.platphormnews.com","capability":"trace and span inspection"},{"id":"webhooklab","label":"PlatPhorm WebhookLab","url":"https://webhooklab.platphormnews.com","capability":"webhook simulation and delivery verification"},{"id":"sandbox","label":"PlatPhorm Sandbox","url":"https://sandbox.platphormnews.com","capability":"safe replay, bounded command validation, and evidence handoff"},{"id":"browserops","label":"PlatPhorm BrowserOps","url":"https://browserops.platphormnews.com","capability":"trusted browser journey preview, screenshots, accessibility, console, network, and trace evidence"},{"id":"agentops","label":"PlatPhorm AgentOps","url":"https://agentops.platphormnews.com","capability":"agent operation review and optional workflow telemetry"},{"id":"trustops","label":"PlatPhorm TrustOps","url":"https://trustops.platphormnews.com","capability":"trust, authorship, disclosure, correction, attribution, and policy validation"},{"id":"evals","label":"PlatPhorm Evals","url":"https://evals.platphormnews.com","capability":"release gates, quality scoring, and eval suite handoff"},{"id":"agentui","label":"PlatPhorm AgentUI","url":"https://agentui.platphormnews.com","capability":"agent-facing workflow UI and form validation"},{"id":"webhooks","label":"PlatPhorm Webhooks","url":"https://webhooks.platphormnews.com","capability":"event delivery, signature replay, and async evidence"},{"id":"spec","label":"PlatPhorm Spec","url":"https://spec.platphormnews.com","capability":"OpenAPI validation, schema examples, and contract workbench handoff"},{"id":"mcp","label":"PlatPhorm MCP","url":"https://mcp.platphormnews.com","capability":"MCP tool registry discovery and JSON-RPC validation"},{"id":"phorm","label":"Phorm","url":"https://phorm.platphormnews.com","capability":"interface prototypes and workflow UI prompts"},{"id":"ascii","label":"PlatPhorm ASCII","url":"https://ascii.platphormnews.com","capability":"ASCII artifact inspection and transformation handoff"},{"id":"desa","label":"PlatPhorm Desa","url":"https://desa.platphormnews.com","capability":"optional deASCII/desa artifact transformation checks"},{"id":"xml","label":"PlatPhorm XML","url":"https://xml.platphormnews.com","capability":"XML, RSS, Atom, and sitemap validation"},{"id":"json","label":"PlatPhorm JSON","url":"https://json.platphormnews.com","capability":"JSON validation and formatting"},{"id":"markdown","label":"PlatPhorm Markdown","url":"https://markdown.platphormnews.com","capability":"Markdown report parsing and validation"},{"id":"searchops","label":"PlatPhorm SearchOps","url":"https://searchops.platphormnews.com","capability":"technical search monitoring and crawl evidence"},{"id":"sitemapops","label":"PlatPhorm SitemapOps","url":"https://sitemapops.platphormnews.com","capability":"index policy and sitemap validation"}]},"deployment":{"id":"vercel","label":"Vercel","kind":"serverless-web","status":"selected","productionUrl":"https://pentest.platphormnews.com","capabilities":["nextjs","functions","webhooks","sandbox","ai-gateway","oidc","edge-network"],"envAny":["VERCEL_OIDC_TOKEN","VERCEL_TOKEN","VERCEL_URL","VERCEL_PROJECT_PRODUCTION_URL","VERCEL_AUTOMATION_BYPASS_SECRET"],"notes":"Current production target. Keep provider-specific behavior behind adapters and config."},"database":{"id":"neon-postgres","label":"Neon Postgres","kind":"postgres","status":"selected","envAny":["DATABASE_URL","POSTGRES_URL","DATABASE_URL_UNPOOLED","POSTGRES_URL_NON_POOLING","PGHOST","PGUSER","PGPASSWORD","PGDATABASE","POSTGRES_URL_NO_SSL"],"notes":"Primary persistent backend for run, finding, scorecard, event, and audit state."},"storage":{"id":"local-plus-platphorm-files","label":"Local storage plus PlatPhorm Files","kind":"hybrid-artifact-storage","status":"selected","envAny":["PLATPHORM_API_KEY"],"notes":"Local function state remains honest and ephemeral; protected artifact upload can hand off to PlatPhorm Files."},"sandbox":{"id":"platphorm-sandbox","label":"PlatPhorm Sandbox","kind":"safe-replay","status":"selected","envAny":["PLATPHORM_API_KEY"],"notes":"Selected platform handoff target for replay, schema validation, and safe execution workflows."},"webhooks":{"id":"vercel-functions","label":"Vercel Functions Webhooks","kind":"http-functions","status":"selected","envAny":["VERCEL","VERCEL_URL"],"notes":"Current webhook receiver/delivery surface for the Next.js app."},"aiGateway":{"id":"vercel-ai-gateway","label":"Vercel AI Gateway","kind":"model-gateway","status":"selected","envAny":["VERCEL_OIDC_TOKEN","AI_GATEWAY_API_KEY","VERCEL_AI"],"notes":"Current provider-neutral model gateway for Vercel-hosted and local pulled environments. VERCEL_AI is accepted as the deployed PlatPhorm alias for AI_GATEWAY_API_KEY presence."}}},"integrations":[{"id":"vercel","label":"Vercel","status":"configured","summary":"Current production target. Keep provider-specific behavior behind adapters and config."},{"id":"neon-postgres","label":"Neon Postgres","status":"configured","summary":"Primary persistent backend for run, finding, scorecard, event, and audit state."},{"id":"vercel-ai-gateway","label":"Vercel AI Gateway","status":"configured","summary":"Current provider-neutral model gateway for Vercel-hosted and local pulled environments. VERCEL_AI is accepted as the deployed PlatPhorm alias for AI_GATEWAY_API_KEY presence."},{"id":"platphorm-sandbox","label":"PlatPhorm Sandbox","status":"configured","summary":"Selected platform handoff target for replay, schema validation, and safe execution workflows."},{"id":"vercel-functions","label":"Vercel Functions Webhooks","status":"configured","summary":"Current webhook receiver/delivery surface for the Next.js app."},{"id":"local-plus-platphorm-files","label":"Local storage plus PlatPhorm Files","status":"configured","summary":"Local function state remains honest and ephemeral; protected artifact upload can hand off to PlatPhorm Files."},{"id":"platphorm-docs","label":"PlatPhorm Docs","status":"configured","summary":"publish reports and operator documentation"},{"id":"platphorm-sheets","label":"PlatPhorm Sheets","status":"configured","summary":"export structured findings and scorecards"},{"id":"platphorm-files","label":"PlatPhorm Files","status":"configured","summary":"store protected run artifacts"},{"id":"platphorm-trace","label":"PlatPhorm Trace","status":"configured","summary":"trace and span inspection"},{"id":"platphorm-webhooklab","label":"PlatPhorm WebhookLab","status":"configured","summary":"webhook simulation and delivery verification"},{"id":"platphorm-sandbox","label":"PlatPhorm Sandbox","status":"configured","summary":"safe replay, bounded command validation, and evidence handoff"},{"id":"platphorm-browserops","label":"PlatPhorm BrowserOps","status":"configured","summary":"trusted browser journey preview, screenshots, accessibility, console, network, and trace evidence"},{"id":"platphorm-agentops","label":"PlatPhorm AgentOps","status":"configured","summary":"agent operation review and optional workflow telemetry"},{"id":"platphorm-trustops","label":"PlatPhorm TrustOps","status":"configured","summary":"trust, authorship, disclosure, correction, attribution, and policy validation"},{"id":"platphorm-evals","label":"PlatPhorm Evals","status":"configured","summary":"release gates, quality scoring, and eval suite handoff"},{"id":"platphorm-agentui","label":"PlatPhorm AgentUI","status":"configured","summary":"agent-facing workflow UI and form validation"},{"id":"platphorm-webhooks","label":"PlatPhorm Webhooks","status":"configured","summary":"event delivery, signature replay, and async evidence"},{"id":"platphorm-spec","label":"PlatPhorm Spec","status":"configured","summary":"OpenAPI validation, schema examples, and contract workbench handoff"},{"id":"platphorm-mcp","label":"PlatPhorm MCP","status":"configured","summary":"MCP tool registry discovery and JSON-RPC validation"},{"id":"platphorm-phorm","label":"Phorm","status":"configured","summary":"interface prototypes and workflow UI prompts"},{"id":"platphorm-ascii","label":"PlatPhorm ASCII","status":"configured","summary":"ASCII artifact inspection and transformation handoff"},{"id":"platphorm-desa","label":"PlatPhorm Desa","status":"configured","summary":"optional deASCII/desa artifact transformation checks"},{"id":"platphorm-xml","label":"PlatPhorm XML","status":"configured","summary":"XML, RSS, Atom, and sitemap validation"},{"id":"platphorm-json","label":"PlatPhorm JSON","status":"configured","summary":"JSON validation and formatting"},{"id":"platphorm-markdown","label":"PlatPhorm Markdown","status":"configured","summary":"Markdown report parsing and validation"},{"id":"platphorm-searchops","label":"PlatPhorm SearchOps","status":"configured","summary":"technical search monitoring and crawl evidence"},{"id":"platphorm-sitemapops","label":"PlatPhorm SitemapOps","status":"configured","summary":"index policy and sitemap validation"}]}}