HIP scanners
HIP collects supported transport, certificate, DNS, ownership and public website evidence through its own adapters.
Evidence providers
HIP accepts evidence from direct checks, privacy-safe client observations, reviewed HIP sources and optional third-party security providers. Every result crosses the same bounded normalization boundary before rules or scoring can use it.
First-party evidence
HIP collects supported transport, certificate, DNS, ownership and public website evidence through its own adapters.
The browser extension can submit bounded structural observations and counts without passwords, form values, cookies, private messages or raw private page content.
Bounded feedback and authorized review evidence can add context. Feedback is not a vote, and review decisions keep their provenance and reasons.
Optional external evidence
Contributes deeper TLS configuration evidence. Availability, freshness and errors remain visible operational facts rather than hidden assumptions.
Can contribute matched phishing or threat-intelligence evidence. A clean response is supporting evidence, not proof of safety.
Can contribute malware or malicious-URL indicators from its supported reputation response. HIP retains normalized evidence rather than raw provider bodies.
Provider boundary
HIP verifies the registered provider identity, provider type, normalized domain and required URL-hash binding.
Evidence counts, score and confidence ranges, text lengths, timestamps, latency and enum values are validated before use.
Results are classified as succeeded, partial, timed out or failed, and as fresh, stale or expired where applicable.
The normalized contract retains public domain metadata, canonical hashes or bounded privacy-safe signals, not raw provider bodies or private page values.
An optional provider failure lowers available confidence without taking down public lookup. Failed evidence carries no risk or trust authority, and no provider directly sets the final HIP score.