WarpIntel live state

Status

Public tools are live first. Private EVE, Discord, email, ads, paid support, and AI lanes stay gated until the matching provider approval, project credential, and user-consent boundary is ready.

Ready services5/12

Production-safe lanes available now.

Gated setup7

External or approval-bound lanes still held behind flags.

Live tools17

Public or browser-local workflows users can open today.

Local-only lanes12

Data stays in the visitor's browser unless exported.

Private responsesNo-store

Auth, account, intake, admin, and cron responses avoid browser caching.

High-trust upgrades8

Future private/corp lanes needing stricter review.

Smoke targets165

Public production checks tracked by health and live smoke.

Intake guard6/6

Manual queue submissions are covered by hashed quota checks.

Security baseline6 checks

Browser security headers are exposed and smoke-verified.

Service State

EVE SSO

Credentials are configured, but sign-in is hidden by feature flag.

partial
Neon Postgres

The dedicated database connection is present for runtime queries.

ready
OpenAI

AI feature flag is off; tools use deterministic analysis.

off
warpintel.app

Custom domain is live on Vercel-managed HTTPS.

ready
zKillboard Public Data

Bounded public killmail and profile-stat lookups are used with attribution, caching, and human-review boundaries.

ready
Public Route Smoke

Protected health checks probe key public pages and feeds so broken routes are visible from the ops dashboard.

ready
Stripe

Kept off until donation links are created inside the WarpIntel Stripe account.

off
Resend

The email provider account is under provider review after our 2026-06-13 reply; choose an approved fallback before sending.

blocked
AdSense

Google verification is required before site review can finish.

blocked
Discord

Discord human verification is required before bot credentials can be created.

blocked
Growth Telemetry

Vercel Analytics and Speed Insights are rendering for aggregate traffic and performance visibility.

ready
Sentry Error Monitoring

Sentry SDK instrumentation and scrub rules are installed, but capture remains gated until WarpIntel DSNs and the feature flag are approved.

partial

Production Checks

Route smoke coverage is mirrored into public health as counts only, so uptime monitors can confirm coverage without touching private account data.

Smoke Targets165

Public pages, tool routes, workflow pages, trust pages, and public feed endpoints.

MVP FloorReady

All 8 route-smoke MVP floors are met.

Public Tools36

Public ESI, browser-local, and advisory tool routes covered by production checks.

Workflow Pages9

SRP, access, recruitment, mining, fleet, reports, guides, and support intake pages.

Trust / Policy49

Trust, sources, attribution, privacy, terms, data rights, ads, and referral boundaries.

Public Feeds51

Health JSON, release, roadmap, integration, source, trust, security, scope, report, tool, local-tool, ads, manifest, sitemap, and robots feeds.

Account Boundary9

Dashboard, permissions, EVE session, and consent-preview account boundary routes.

Intake POSTs6/6

Manual queue POST routes are smoke-checked with safe invalid submissions.

Analyzer API2/2

Analyzer POST responses are smoke-checked as invalid and valid private no-store JSON.

Analytics API2/2

First-party analytics POST responses are smoke-checked as private no-store JSON.

EVE Tool APIs16/16

Public EVE tool POST responses are smoke-checked as invalid and valid private no-store JSON.

EVE Read APIs2/2

PI template and sovereignty overview GET responses are smoke-checked as private no-store JSON.

Discord APIs2/2

Discord command manifest and interaction status responses are smoke-checked as private no-store JSON.

Revenue Boundary6/6

Support, project-support, ad-choice, terms, privacy, and ads.txt pages are checked for public-launch monetization boundaries.

Account Controls5/5

Unsigned session, export, delete, disconnect, and logout controls are verified as private responses.

Protected Exports44/44

Ops review, launch blockers JSON/Markdown, JSON snapshot, and queue CSV routes are verified as private status/header checks.

Setup Packets22/22

External-service setup packet routes are verified as private status/header checks.

Setup Actions23/23

EVE SSO dry run, EVE SSO activation rehearsal, EVE token revocation drill, external feature activation dry run, Discord command registration, Discord command dry run, Discord activation rehearsal, OpenAI dry run, OpenAI activation rehearsal, Growth dry run, Vercel/GitHub dry run, backup recovery dry run, reports webhook dry run, transactional email dry run, transactional email activation rehearsal, Stripe support dry run, Stripe support activation rehearsal, AdSense config dry run, AdSense activation rehearsal, Sentry config dry run, and Sentry activation rehearsal are verified as admin-only private setup actions.

Admin Actions10/10

Queue, rules, health, and fleet action routes are verified as admin-only private responses.

Admin Auth3/3

Ops login page plus failed-login and logout redirects are verified as private responses.

EVE Callback1/1

EVE SSO callback state-failure redirects are verified as private responses.

Consent PreviewCovered

6/6 human-readable and JSON EVE consent-preview routes.

Public status shows route-smoke coverage counts only; protected and intake checks store status, header, and redirect evidence only and never read response bodies, cookies, EVE tokens, provider secrets, pasted form text, or private account data.

Intake Guard

Public manual queue submissions have a shared abuse guard before they write to the review queues.

Intake Routes6/6

Support, access, SRP, recruitment, buyback, and mining submission routes share the guard.

Default Quota8/hour

Tunable through PUBLIC_INTAKE_RATE_LIMIT and PUBLIC_INTAKE_RATE_LIMIT_WINDOW_SECONDS.

Identity PrivacyHashed

Requester identity is salted and hashed before any quota event is stored.

Ops VisibilityCounted

Exceeded requests are recorded as rate_limit audit events for protected ops review.

Manual intake quota events store the route, cost, timestamp, and salted requester hash only; they do not store raw IP addresses, raw user-agent strings, form messages, EVE tokens, provider secrets, or pasted tool inputs.

Security Baseline

Browser security headers are checked in production smoke and mirrored into public health as counts only.

TransportHSTS

Production responses require Strict-Transport-Security with includeSubDomains.

FramingDenied

X-Frame-Options and CSP frame-ancestors keep WarpIntel out of hostile frames.

Browser PolicyLocked

Content sniffing, referrer, camera, microphone, geolocation, payment, USB, and topics are restricted.

CSP ModeReport-only

Launch CSP is visible and smoke-verified without blocking approved public integrations yet.

The public security baseline reports header categories and policy mode only; it does not expose cookies, sessions, admin paths, provider secrets, EVE tokens, or visitor identifiers.

Launch Action Queue

The top gated launch actions stay visible here as sanitized priorities while the full queue remains in the launch readiness manifest.

Action Queue9

3 waiting; 5 staged; 0 planned.

Next ActionWaiting

Discord Bot And Role Sync: Complete Discord human verification on Zeus, then add the app public key, client ID, bot token, and guild ID.

Owner Categories3

Queue items stay grouped by public owner category rather than internal account names.

Public ManifestCount-only

The launch readiness manifest mirrors sanitized queue counts for public monitors.

Priority 1 - WaitingDiscord Bot And Role Sync

Complete Discord human verification on Zeus, then add the app public key, client ID, bot token, and guild ID.

Comms / Project owner review / Waiting on provider review, account verification, or owner action.
Priority 2 - WaitingGoogle AdSense

Complete Google verification on Zeus, then finish AdSense submission and store the publisher/client ID.

Ads / Project owner review / Waiting on provider review, account verification, or owner action.
Priority 3 - WaitingTransactional Email

Use the protected email setup packet, then wait for Resend approval or choose another approved sender before enabling transactional mail.

Email / Provider review / Waiting on provider review, account verification, or owner action.
Priority 4 - StagedAnalytics And Search Verification

Use the protected Growth packet when setting up Vercel Analytics, Speed Insights, Search Console, or Bing Webmaster Tools.

Growth / WarpIntel build team / Staged for final verification before public activation.

Public status launch action queue exposes only sanitized priorities, public state, public owner category, area, next-step summaries, launch-impact text, and aggregate counts; it does not expose provider credentials, API keys, passwords, payment profile details, EVE tokens, private EVE data, raw submissions, setup packets, internal account names, or separate-project account details.

Integration Action Queue

The top gated integration actions stay visible here as sanitized priorities while the full provider queue remains in the integrations manifest.

Integration Queue7

3 waiting; 2 staged; 2 feature-gated; 0 planned.

Next IntegrationWaiting

AdSense: Finish Google verification and keep ad slots hidden until publisher and slot IDs are approved.

Critical Lanes5

EVE, revenue, and communications integration lanes still needing gated follow-up.

Public ManifestCount-only

The integrations manifest mirrors sanitized queue counts for public monitors.

Priority 1 - WaitingAdSense

Finish Google verification and keep ad slots hidden until publisher and slot IDs are approved.

Revenue And Growth / Provider or account review / Cannot activate public provider behavior until verification or approval clears.
Priority 2 - WaitingDiscord

Complete Discord app verification, then validate the signed interaction endpoint.

Comms / Provider or account review / Cannot activate public provider behavior until verification or approval clears.
Priority 3 - WaitingResend

Wait for approved sending provider or fallback before enabling transactional sends.

Comms / Provider or account review / Cannot activate public provider behavior until verification or approval clears.
Priority 4 - StagedEVE SSO

Enable public EVE login only after callback, scope map, and live test gates are ready.

EVE Private Data / WarpIntel setup verification / Staged for final configuration, link validation, or smoke testing.

Public status integration action queue exposes only sanitized priorities, public state, public owner category, provider category, next-step summaries, launch-impact text, public links, and aggregate counts; it does not expose provider credentials, payment profile details, API keys, EVE tokens, private EVE data, account data, raw submissions, private logs, setup packets, internal account names, or separate-project account details.

AI Readiness

AI assistance is staged with deterministic fallback, protected setup review, and no-provider-call dry runs while provider keys, prompts, spend records, and private EVE data stay out of public surfaces.

Eligible Tools3

Intel Desk, Fit Coach, and Loss Reviewer can use deterministic analysis now and AI later.

Protected Checks3

Setup packet, dry-run, and activation rehearsal stay behind protected admin routes.

Activation Rehearsal5/8

Owner review can package first-tool AI activation evidence without provider calls or token spend.

FallbackReady

Public tools keep returning deterministic local analysis if AI is disabled or unavailable.

Provider CallsDry-run only

Readiness checks do not call OpenAI, submit prompts, or spend tokens.

Public AI readiness exposes aggregate first-tool counts, feature-gate booleans, activation criteria, activation-rehearsal counts, protected-check booleans, deterministic fallback status, and no-provider-call dry-run status only; it does not expose provider keys, model environment values, billing details, raw prompts, raw pasted analyzer inputs, EVE tokens, private account data, or token-spend records.

Backup Readiness

Recovery posture is public as aggregate counts while database URLs, cron secrets, migration tags, SQL dumps, provider-console artifacts, and restore evidence stay protected.

CoverageReady

Recovery prerequisites are tracked as public-safe counts while restore artifacts stay protected.

Migration Ledger25 recorded

Migration count is visible without exposing migration tags, SQL bodies, or database connection values.

Protected Review3 checks

Setup packet, recovery dry-run, and restore-drill rehearsal coverage stay behind protected admin routes.

Restore DrillReady

The app is ready for an owner-reviewed drill; the public page does not claim a real restore is verified.

Acceptance Criteria5 required

A real restore drill must prove release fingerprint, route smoke, migration ledger, ops snapshot, and tracker evidence before it is marked verified.

Owner Handoff6 steps

The restore drill has a secret-free handoff covering baseline, provider boundary, isolated restore, migration reconcile, proof review, and tracker record.

Rollback Decisions3 paths

Deployment, data-restore, and environment-boundary rollback decisions are documented without exposing provider artifacts.

Public backup readiness exposes aggregate recovery counts, activation criteria, migration count, protected-check booleans, proof-target counts, safe-export counts, restore-drill acceptance-criteria counts, owner-handoff counts, rollback decision counts, restore-drill status, and no-provider-mutation dry-run status only; it does not expose database connection values, cron secret values, migration tags, Neon passwords, SQL dumps, Vercel rollback targets, provider-console backup artifacts, token ciphertext, raw IP addresses, raw user-agent strings, EVE tokens, private account data, or raw pasted analyzer inputs.

Growth Readiness

Growth setup is staged with explicit telemetry flags, search-verification gates, protected dry runs, and no-provider-call boundaries while analytics IDs, verification token values, and provider accounts stay out of public surfaces.

CoverageReady

Growth telemetry and search verification prerequisites are tracked as aggregate counts.

Telemetry Gates2 gated

Analytics and Speed Insights stay behind explicit public feature flags.

Search Verification2 gates

Google and Bing verification values are never echoed from public readiness surfaces.

Activation Criteria7 required

Telemetry and search submission cannot be marked launch-ready until every no-secret criterion passes.

Provider CallsDry-run only

Readiness checks do not call analytics, Search Console, Webmaster Tools, or provider accounts.

Public growth readiness exposes aggregate telemetry counts, search-verification counts, activation-criteria counts, owner-handoff counts, rollback decision counts, installed-component counts, protected-check booleans, and no-provider-call dry-run status only; it does not expose analytics IDs, verification token values, Google or Bing account details, provider cookies, Search Console screenshots, raw pageview data, workflow-click payloads, EVE tokens, private account data, or raw pasted analyzer inputs.

SEO Readiness

Search discovery is public and count-only: sitemap, robots, app manifest, guide metadata, tool metadata, and search-verification gates are monitored without exposing provider tokens or private EVE data.

Sitemap Routes107 live

Public discovery routes are listed without private or protected URLs.

Crawler Guards5 guarded

Protected account, ops, dashboard, API, and preview paths stay blocked from crawlers.

Guide Metadata8/8

Guide detail pages expose reviewed titles, descriptions, canonical links, and Open Graph data.

Tool Metadata17/17

Public tool pages have static discovery metadata while analyzer inputs remain unstored.

Public SEO readiness health exposes aggregate sitemap, robots, web-app-manifest, guide, guide-detail metadata, tool-detail metadata, and search-verification gate counts only; it does not expose verification token values, analytics IDs, Search Console accounts, provider cookies, EVE tokens, private EVE data, admin exports, raw logs, or raw pasted analyzer inputs.

Capability Readiness

Capability readiness rolls up public tools, browser-local workflows, protected review queues, EVE consent gates, and provider-gated lanes without exposing private EVE data or setup details.

Live Public28 ready

No-login tools and public EVE data surfaces that users can open today.

Browser Local11 local

Planning workflows that keep working state in the visitor browser unless exported.

Protected Review6 queued

Manual intake and review lanes that stay behind protected reviewer surfaces.

Consent + Providers15 gated

EVE SSO and external-provider features remain staged until approval, credentials, and consent are ready.

Public capability readiness exposes aggregate capability counts, route-link counts, consent-preview counts, provider-gate counts, link counts, and safety-boundary counts only; it does not expose provider credentials, EVE tokens, private EVE data, account data, raw submissions, private logs, hidden setup packets, internal account names, or separate-project account details.

EVE Login Gate

EVE sign-in stays hidden until the callback, first-login scope, and live test gate are all ready.

Launch GateOff

EVE sign-in is feature-flagged off until the production callback is confirmed and a test sign-in succeeds.

CallbackMatched

Expected callback: https://warpintel.app/api/auth/eve/callback

First ScopepublicData

First sign-in must remain limited to public identity before private modules ask for more.

Private Scopes1/2

High-trust and write/action scopes stay feature-specific, consent-previewed, and human-reviewed.

Scope MapReview

9/10 permission group(s) are fully allowed; 1 partial and 0 missing.

Feature Consent8

8 preview-only feature path(s) staged before OAuth; 1 high-trust action lane(s).

Public EVE gate health exposes status booleans, safe counts, permission-group coverage counts, preview-only feature consent metadata, activation criteria, owner-handoff counts, owner proof-target counts, rollback decision counts, the expected callback, and runtime login guard state only; it never exposes client IDs, client secrets, EVE tokens, account data, or private EVE data.

Permission Catalog

Scope catalog readiness stays public and count-only: it shows reviewed groups, known scopes, consent-preview coverage, and OAuth boundaries without exposing credentials or private EVE data.

Permission Groups10

1 available now; 8 future gated group(s).

Known Scopes63

63 known scope(s); 0 unknown.

Feature Consent8/8

8 feature route(s) have dry preview coverage.

High Trust8

8 write/action scope(s) stay feature-gated.

OAuth BoundaryDry

Catalog and consent-preview routes do not start OAuth or contact CCP.

Safety Boundary8/7

Manifest links and safety boundaries stay public and count-only.

Public EVE permission catalog readiness health exposes aggregate scope counts, group counts, consent-preview counts, feature consent route counts, link counts, and safety-boundary counts only; it does not start OAuth, contact CCP, expose EVE tokens, client secrets, private EVE data, account data, raw submissions, internal account names, or separate-project account details.

Data Rights Readiness

Browser-local data controls are public, signed-in account export/delete/disconnect routes stay private, and readiness is exposed as counts only.

Browser Local7 surfaces

Public tools keep local records in the visitor browser until exported or cleared.

Account ExportProtected

Signed-in exports are private no-store JSON and do not include token values.

Delete / DisconnectReady

Account delete, EVE disconnect, and logout paths are smoke-checked as private responses.

Public BoundaryNo secret

Public readiness exposes counts, links, and safety booleans only.

Public data-rights readiness exposes public route counts, account-control route counts, browser-local surface counts, protected smoke counts, and safety booleans only; it does not expose account exports, EVE OAuth token values, token ciphertext, provider secrets, private EVE data, raw pasted inputs, raw visitor identifiers, raw browser agent strings, payment profile details, raw support messages, or manual review queue notes.

Reports Readiness

Local reports stay browser-local by default, public export manifests describe safe formats, and account report saves remain private no-store flows after EVE sign-in.

Local Library34 tools

Report save, copy, download, import, and export stay in the visitor browser by default.

Export Manifest3 formats

Markdown bundle, JSON backup, and account-report JSON boundaries are public-safe.

Account Reports17 tools

Account saves require EVE sign-in and private no-store responses.

WebhooksOff

Outbound delivery waits for signing, replay protection, rate limits, and abuse review.

Public reports readiness exposes aggregate report-format counts, tool counts, endpoint counts, public link counts, workflow-stage counts, webhook safety flags, and exclusion counts only; it does not expose report bodies, raw pasted analyzer inputs, account reports, account exports, EVE OAuth token values, token ciphertext, provider credentials, private EVE data, raw visitor identifiers, raw browser agent strings, webhook signing secrets, or separate-project account details.

Support Readiness

Support requests, voluntary support, Stripe support-link exposure, and email receipts stay public-safe: provider lanes remain gated until review, and support queue details stay protected.

Support Surfaces3 live

Support request, voluntary support, and support readiness pages are public.

Support IntakeManual

Support submissions enter a protected queue for human review.

Provider Gates5 gated

Stripe, email, and revenue providers stay dry-run or public-gated.

No UnlocksEnforced

Voluntary support does not unlock gameplay, EVE data, or dashboard access.

Public support readiness exposes support surface counts, support request route counts, protected review counts, provider-gate counts, workflow-stage counts, and no-live-provider safety booleans only; it does not expose raw support messages, raw support subjects, contact details, email addresses, Discord handles, in-game names, page URLs, admin review notes, reply draft bodies, support queue statuses, rate-limit hashes, browser identifiers, EVE session ids, EVE tokens, Stripe customer records, payment profile details, provider secrets, email message ids, paid unlocks, or account decisions.

Domain Contact Readiness

WarpIntel domain, HTTPS contact, support mailbox, security policy, and provider-boundary disclosures stay public-safe while registrar, DNS, TLS, mailbox, and provider account details remain excluded.

Production Domainwarpintel.app

The public app canonical domain is documented for checks and disclosure pages.

HTTPS ContactRequired

Security policy and security.txt point to the public support contact path.

Support MailboxPublished

support@warpintel.app is the public contact lane for support and security intake.

Provider Boundaries5 guarded

Registrar, DNS, TLS, mailbox, payment, ad, and API provider details stay out of public output.

Public domain readiness exposes only the production domain, public support contact, route counts, policy/contact route lists, provider-boundary counts, and no-secret safety booleans; it does not expose registrar account details, DNS zone records, TLS certificate private keys, mailbox credentials, provider console account ids, payment account details, ad account details, email provider API keys, database URLs, OAuth client secrets, EVE access tokens, private EVE data, admin notes, raw support messages, or separate-project account details.

Market Readiness

Market Command and Appraisal Desk stay public and manual, browser-local watchlists remain local, and private market/asset/wallet context waits for feature-specific consent.

Market CommandLive

Public market comparison works without EVE sign-in or private orders.

Appraisal DeskLive

Item-list pricing uses public market data and user-entered text only.

WatchlistBrowser-local

Saved market reminders stay in the browser and never become trade instructions.

Future Data8 scopes

Private assets, orders, wallets, contracts, and jobs wait for feature consent.

Public market readiness exposes public route counts, public API route counts, workflow-stage counts, consent-preview links, and safety booleans only; it does not expose private market orders, wallet journals, asset locations, contract records, market order ownership, industry jobs, character contact details, raw saved watchlist entries, EVE tokens, provider secrets, private EVE data, or automated trade actions.

PI Readiness

PI planning is public and advisory, market estimates use public data, and future colony review waits for feature-specific EVE consent.

PI PlannerLive

13 reviewed PI templates can be planned without EVE sign-in.

Market EstimatePublic

Optional price checks use public ESI market estimates and stay advisory.

Colony Review1 scope

Private colony review waits for feature-specific consent and clear wording.

PI ActionsHuman-only

Colony routing, client actions, hauling, and tax decisions stay manual.

Public PI readiness exposes PI template counts, public route counts, public API route counts, protected setup route counts, workflow-stage counts, consent-preview links, and safety booleans only; it does not expose private colony layouts, planet pin positions, extractor routes, storage levels, customs office ownership notes, private assets, wallet journals, industry job history, EVE tokens, provider secrets, private EVE data, colony read automation, or colony write automation.

Navigation Readiness

Systems, routes, maps, sovereignty, structures, and wormhole views stay public-data first while private live-intel context waits for feature-specific consent.

Navigation Pages7 live

Systems, routes, map, sovereignty, structures, and wormholes stay public-data ready.

Public APIs4 checked

System risk, route scout, sovereignty, and readiness endpoints are smoke-covered.

Private Intel5 scopes

Location, online state, ship type, and private killmail context wait for consent.

Route ActionsHuman-only

Travel decisions, fleet movement, scouting, and in-game actions stay manual.

Public navigation readiness exposes public page counts, public route counts, public API route counts, workflow-stage counts, consent-preview links, and safety booleans only; it does not expose pilot location, online state, ship type, private route history, private bookmarks, private fleet membership, fleet participation ledgers, private killmails, structure access lists, EVE tokens, provider secrets, private EVE data, location read automation, or fleet action automation.

Access Readiness

Access requests, first-login scope, feature consent previews, and grant boundaries are public-safe while raw request details, reviewer notes, role sync, and private EVE data stay protected.

Access IntakeLive

Access requests can be submitted publicly and enter protected manual review.

First LoginpublicData

Basic sign-in stays limited to public identity; private scopes are feature-specific.

Feature Consent8 plans

High-trust and write-action permissions remain previewed before any provider redirect starts.

Access GrantsManual

Approvals, expiries, Discord role sync, and grants are never automated from public request data.

Public access readiness exposes access surface counts, public route counts, protected review route counts, consent-route counts, workflow-stage counts, feature-consent counts, and no-secret safety booleans only; it does not expose raw access request rows, character names, corporation or alliance labels from submitted rows, raw access reasons, contact details, Discord handles, evidence URLs, sponsor references, admin reviewer notes, access grant state, rate-limit hashes, browser identifiers, EVE session ids, EVE tokens, private EVE data, role-sync payloads, provider secrets, automated approvals, or access grants.

Operations Intake Readiness

Access, recruiting, and support intake are public and guarded, while request rows, reviewer notes, and account decisions stay protected and human-reviewed.

Public Forms3 live

Access, recruiting, and support intake pages are public.

Quota GuardHashed

Manual submissions use shared abuse protection before queue writes.

Ops ReviewProtected

Status changes and reviewer notes stay behind admin access.

AutomationManual

Emails, approvals, denials, access grants, and account decisions stay human-approved.

Public intake readiness exposes public route counts, submission route counts, protected review route counts, workflow-stage counts, and safety booleans only; it does not expose raw access requests, recruitment applications, support messages, applicant names, contact details, vouch notes, admin review notes, audit event metadata, rate-limit hashes, EVE session ids, EVE tokens, provider secrets, private EVE data, notification sends, or account decisions.

SRP Readiness

SRP intake is public, review stays protected, and future proof context waits for feature-specific EVE consent.

Manual IntakeLive

Loss requests can be submitted without private EVE data.

Admin ReviewProtected

Queue review and decision notes stay behind admin access.

Reserve PlannerAdmin-only

Reserve exports use aggregate guidance and exclude raw queue details.

Future Proof5 scopes

Private SRP proof context waits for feature-specific EVE consent.

Public SRP readiness exposes public route counts, protected route counts, workflow-stage counts, consent-preview links, and safety booleans only; it does not expose pilot names, killmail URLs, raw SRP queue notes, wallet balances, contract data, EVE tokens, provider secrets, private EVE data, or payout actions.

Fleet Readiness

Fleet scheduling is public and manual, publishing stays protected, and future fleet context/action scopes wait for feature-specific consent.

Fleet BoardLive

Public ops can be reviewed without EVE sign-in or private fleet reads.

PublishingProtected

Fleet/timer publishing remains admin-only and smoke-checked as private.

Fleet Context5 scopes

Participation and SRP proof context waits for feature-specific consent.

Write ActionsDisabled

Fleet write/client actions require high-trust consent and a human confirmation flow.

Public fleet readiness exposes public route counts, protected publish route counts, workflow-stage counts, consent-preview links, and safety booleans only; it does not expose private fleet membership, fleet participation ledgers, FAT links, pilot location, online state, ship type, private killmails, fleet invitation tokens, EVE tokens, provider secrets, private EVE data, or fleet write actions.

Mining Readiness

Mining intake is public and manual, queue review stays protected, and future mining/wallet/contract reconciliation waits for feature-specific consent.

Mining IntakeLive

Ore, loot, proof, and split notes can be submitted for manual review.

Admin ReviewProtected

Mining queue decisions and payout notes stay behind admin access.

Mining Data8 scopes

Private mining history, assets, contracts, and wallet context wait for consent.

PayoutsHuman-only

ISK movement, contracts, and corp cuts are never automated by the public lane.

Public mining readiness exposes public route counts, intake route counts, protected review route counts, workflow-stage counts, consent-preview links, and safety booleans only; it does not expose raw ore or loot lines, proof URLs, payout character notes, wallet journals, contract records, asset locations, corporation mining ledgers, member mining history, EVE tokens, provider secrets, private EVE data, ISK movement, or contract automation.

Buyback Readiness

Buyback calculator and request intake are public and manual, review stays protected, and future asset/contract/wallet reconciliation waits for feature-specific consent.

CalculatorLive

Public buyback estimates work without EVE sign-in or stored account data.

Manual IntakeGuarded

Buyback requests enter a protected review queue through the shared intake guard.

Future Data8 scopes

Private assets, contracts, wallets, and market context wait for feature consent.

ContractsHuman-only

Contracts, accepted locations, hauling decisions, and ISK movement are never automated by the public lane.

Public buyback readiness exposes public route counts, intake route counts, quote route counts, protected review route counts, workflow-stage counts, consent-preview links, and safety booleans only; it does not expose raw item list rows, proof URLs, character contact details, requested locations, contract character notes, raw buyback queue notes, wallet journals, contract records, asset locations, corporation buyback ledgers, EVE tokens, provider secrets, private EVE data, ISK movement, or contract automation.

Tool Boundaries

LocalBrowser local
Dashboard Command State

Reads reports, fits, watchlists, market watches, plans, skills, learning, and wormhole boards from this browser.

No local notes, fits, reports, or planning state are sent to the server.
LocalBrowser local
Local Report Library

Copies, downloads, filters, imports, exports, and deletes browser-local WarpIntel reports.

Stores generated summaries locally; raw pasted inputs are not stored server-side.
LocalBrowser local
Fit Lab

Parses pasted fits, saves local fit records, compares two fits, and routes into Fit Coach review.

No private skills, implants, hangars, or EVE fitting writes are used.
LocalBrowser local
Character Audit

Maps manual notes for identity, skills, clones, assets, wallet, contracts, industry, PI, and fleet/SRP context.

Manual review shell only; no private EVE character data is pulled yet.
LocalBrowser local
Corp Stats

Parses pasted roster notes into registration, main/alt, activity, role coverage, follow-ups, and exports.

Roster snapshots stay in the browser unless manually exported.
LocalBrowser local
Corp Audit

Reviews manual director notes for access, roles, wallets, assets, contracts, structures, industry, markets, and security.

No corporation wallets, assets, contracts, or member data are read from EVE yet.
LocalBrowser local
Structure Watch

Tracks pasted fuel, timers, POCOs, starbases, bridges, facilities, moon pulls, and director actions.

Manual notes only; no corp structures or fuel data are fetched.
LocalBrowser local
Skill Planner

Builds manual doctrine readiness plans for tackle, DPS, logistics, wormholes, industry, and PI.

Manual level selectors stay local; no private skill queue is read yet.
LocalBrowser local
Public Watchlists

Stores local pilots, corps, alliances, systems, items, fits, fleet notes, tags, priorities, and backups.

Watchlists remain local and portable through manual export/import.
LocalBrowser local
New Player Mission Control

Tracks beginner mission paths, practical habits, safety warnings, and links into live public tools.

Learning progress is local and does not create server-side profile data.
LocalBrowser local
PvE Site Helper

Guides manual PvE prep with danger signals, fit checks, route checks, and copyable briefings.

No client automation, no site detection, and no private character reads.
LocalBrowser local
Manual Wormhole Ops

Builds local chain maps, system notes, signatures, mass/lifetime states, scout briefs, and backups.

Manual chain data stays local unless exported or later synced by choice.
Public dataPublic ESI
Market Command

Uses public market orders for hub comparison and keeps item watchlists in browser storage.

Public ESI prices plus local watchlists; no trading action or order writes.
Public dataPublic ESI
Public Profiles

Resolves exact public characters, corporations, and alliances with ESI identity facts, image-server portraits/logos, alliance corporation samples, and bounded zKillboard stats.

Public ESI and zKillboard advisory data only; no private character, corporation, wallet, role, or activity data is read.
Public dataPublic ESI
Intel Map

Draws a visual route-risk map from public ESI route, system security, kill, pod, jump, and watchpoint data.

Public advisory map only; no client destination setting, location tracking, or private character data.
Public dataPublic ESI
Industry Lab

Uses reviewed SDE blueprint data, user-entered materials, public prices, and local blueprint workspace backups.

Manual planning only; it does not start jobs, move items, or read private hangars.
Public dataPublic ESI
PI Planner

Plans reviewed P0-P3 production chains with raw extraction estimates, user inputs, tax reserve, and public price estimates.

Public calculator only; no colony reads, edits, or EVE client actions.