generated: '2026-08-09' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI servers[] hosts probed: '2026-08-09' hosts: - host: atk.tvarka.pro role: api + developer portal https: true tls_version: TLSv1.3 cert_expires: Sep 18 13:31:31 2026 GMT hsts: true hsts_max_age: 15552000 hsts_include_subdomains: true hsts_preload: false - host: tvarka.pro role: company site, terms, privacy, security, llms.txt https: true tls_version: TLSv1.3 cert_expires: Sep 18 13:31:31 2026 GMT hsts: true hsts_max_age: 15552000 hsts_include_subdomains: true hsts_preload: false - host: sign.tvarka.pro role: pairing landing host referenced by AuthPairingHint.pairingUrl https: true tls_version: TLSv1.3 cert_expires: Sep 18 13:31:31 2026 GMT hsts: true hsts_max_age: 15552000 hsts_include_subdomains: true hsts_preload: false domains: - domain: tvarka.pro dnssec: false caa: [] spf: false dmarc: true dmarc_policy: quarantine dmarc_record: >- v=DMARC1; p=quarantine; rua=mailto:dmarc@tvarka.pro; ruf=mailto:dmarc@tvarka.pro; fo=1; adkim=r; aspf=r notes: >- All three hosts sit behind Cloudflare (104.21.24.241 / 172.67.221.53) on one wildcard certificate, TLS 1.3 with HSTS including subdomains on each. Gaps observed and recorded as absences, not assumptions: no DNSSEC DS record, no CAA record set, and no SPF TXT record on tvarka.pro (DMARC is published at p=quarantine with aggregate and forensic reporting, but without SPF it rests on DKIM alignment alone). No /.well-known/security.txt on any host.