generated: '2026-08-09' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: avora-agent-forge.netlify.app https: true tls_version: TLSv1.3 cert_expires: Mar 19 23:59:59 2027 GMT hsts: true hsts_max_age: 31536000 domain_ownership_caveat: >- AVORA does not operate a branded apex domain - the service is hosted at avora-agent-forge.netlify.app, so the registrable domain below is netlify.app, the hosting platform's. The DNSSEC, CAA, SPF, and DMARC records recorded under `domains` are Netlify's posture, NOT AVORA's, and must not be read as this provider's own domain security. Only the `hosts` block (TLS and HSTS on the serving host) reflects a configuration AVORA is responsible for, and even HSTS is a platform default. AVORA controls no DNS zone of its own and therefore publishes no CAA, SPF, or DMARC. domains: - domain: netlify.app owner: Netlify (hosting platform, not the API provider) dnssec: false caa: - 128 iodef "mailto:security@netlify.com" - 128 issue "digicert.com;account=2d83e9ac9b6776c3f215150f6ebceea8cefe3bc2e1fb5efffb1d71e200575226" spf: true dmarc: true dmarc_policy: reject