Skip to content
HIPHuman Interactive Protocol
Menu

Evidence providers

See where HIP's website evidence comes from.

HIP accepts evidence from direct checks, privacy-safe client observations, reviewed HIP sources and optional third-party security providers. Every result crosses the same bounded normalization boundary before rules or scoring can use it.

First-party evidence

Signals HIP can collect and govern directly.

Direct checks

HIP scanners

HIP collects supported transport, certificate, DNS, ownership and public website evidence through its own adapters.

Client observation

Browser-observed signals

The browser extension can submit bounded structural observations and counts without passwords, form values, cookies, private messages or raw private page content.

Human evidence

Weighted feedback and review

Bounded feedback and authorized review evidence can add context. Feedback is not a vote, and review decisions keep their provenance and reasons.

Optional external evidence

Independent sources, when configured.

TLS scanner

SSL Labs / Qualys TLS

Contributes deeper TLS configuration evidence. Availability, freshness and errors remain visible operational facts rather than hidden assumptions.

Threat intelligence

Google Web Risk / Safe Browsing

Can contribute matched phishing or threat-intelligence evidence. A clean response is supporting evidence, not proof of safety.

URL reputation

VirusTotal

Can contribute malware or malicious-URL indicators from its supported reputation response. HIP retains normalized evidence rather than raw provider bodies.

Provider boundary

What happens before evidence affects a score.

  1. 01 · Bind

    Confirm source and target

    HIP verifies the registered provider identity, provider type, normalized domain and required URL-hash binding.

  2. 02 · Bound

    Validate size and meaning

    Evidence counts, score and confidence ranges, text lengths, timestamps, latency and enum values are validated before use.

  3. 03 · Classify

    Record status and freshness

    Results are classified as succeeded, partial, timed out or failed, and as fresh, stale or expired where applicable.

  4. 04 · Minimize

    Keep only the safe projection

    The normalized contract retains public domain metadata, canonical hashes or bounded privacy-safe signals, not raw provider bodies or private page values.

Provider outages do not become verdicts.

An optional provider failure lowers available confidence without taking down public lookup. Failed evidence carries no risk or trust authority, and no provider directly sets the final HIP score.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.