What it is
Prototype public-web intelligence with SSRF-safe fetches, severity classes, and portal history — not a penetration product.
Architecture
Portal initiates runs under CSRF and rate limits. Node analyzes when available; PHP samples headers when Node is down. Results persist under data/audits.
Capabilities
- SSRF-safe public observation
- Header and CSP signal collection
- Finding severity taxonomy
- Audit history in the portal
Security
Blocks private IPs, loopback, and metadata endpoints. No exploitation modules ship in Continuum.
Research focus
How should severity language be calibrated so empty findings never become false assurance?