Skip to content

docs: make site copy, docs and privacy policy describe what ships - #254

Merged
ralyodio merged 4 commits into
masterfrom
fix/site-copy-honesty
Sep 26, 2026
Merged

ralyodio merged 4 commits into
masterfrom
fix/site-copy-honesty

Conversation

@ralyodio

@ralyodio ralyodio commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

What

Site, docs and README copy now describe only what ThreatCrush does after the in-flight launch PRs. Nothing about prices or the pricing model changed; only false statements were removed or corrected. The privacy policy and terms changes need owner/legal review before merge.

  1. Homepage (apps/web/src/app/page.tsx): rewrote capabilities from the code (CRS + libinjection web rules, SSH/sudo/journal/network/DNS watchers, custom JSON rules, auto-bans via nftables/iptables/fail2ban with escalating ban lengths, hardening checks, code scanner with OSV + SARIF, pentest checks, email/Slack/Discord/PagerDuty/webhook alerts, cloud dashboard via threatcrush servers link, desktop app on a local socket, extension page checks + org detection badge). Kept the structure; cut the "open standards" grid, and turned the CTEM / detect-and-respond sections into what each stage actually does today.
  2. Root metadata (apps/web/src/app/layout.tsx): title/description/OG/Twitter text, JSON-LD featureList/descriptions/offer text, removed the stale softwareVersion: "0.2.0". Replaced alternates: { canonical: "/" } (every page without its own canonical declared the homepage canonical, and every og:url was the homepage) with canonical: "./" and openGraph.url: "./", which Next resolves against each route's own path. Pages that set their own canonical (blog posts, /hire, /about, …) still win.
  3. /docs: command reference rebuilt from node apps/cli/dist/index.js --help and every subcommand's --help (v0.13.9): 31 entries in 7 groups, all marked Shipped except servers link / servers unlink (from the daemon↔cloud contract), marked New. Dropped activate (BillingFixes removes it). The "planned" list is now what really isn't available (signed desktop builds, store listings, SDK on npm). Added page metadata.
  4. README.md (+ the same install line in apps/cli/README.md): community modules that don't exist are now listed as ideas; "Build and sell" → free to publish, listings go live after review; /pricing → /hire; features table adds bans, hardening, cloud dashboard; extension text matches what it does; desktop install lines match install.sh (it installs the CLI everywhere and only points to the desktop app download).
  5. Privacy policy: lists every data flow and processor found in code — self-hosted Supabase, CoinPayPortal/Stripe, Telnyx, Resend, GitHub OAuth + GitHub App (repo contents read via API, findings stored incl. matched line), public publication of public-repo findings on /discovery + /.well-known/openthreat.json (on by default, per-installation switch), /investors "Recent backers", Module Store, push tokens (Expo/APNs/FCM, web push), Sentry (opt-in), alert destinations, OSV.dev from scan --deps, the analytics/third-party scripts in layout.tsx (DataFast, Robauto pixel + beacon, Crawlproof, Profullstack feedback widget, Google Fonts), linked-server uploads (hostname, version, heartbeats, detections with source IP + username + ≤16 KB metadata, hardening results, bans). Retention = what code states (10-minute phone codes; everything else until deleted) and the self-serve account deletion AuthAccountFixes adds (what it deletes and keeps). Removed "encrypted storage at rest" (not verifiable for the self-hosted box).
  6. Terms: "Lifetime licenses are payable…" → "Purchases are payable…" (license_status gates nothing and activate is being removed); service description no longer says "threat intelligence … active defense". Refund text unchanged. No governing law or new legal terms added.
  7. Status docs: docs/PRE_LAUNCH.md is now a short current launch checklist (engineering in flight, owner-only items, post-deploy checks) pointing at RELEASE_STATUS.md / SURFACES.md; TODO.md points at it; root PRE_LAUNCH.md (Twilio, "phone verification is STUBBED") deleted. docs/SURFACES.md: Railway → dev2 deploy, CLI v0.13.9 and feat(cli): port CRS 942100/941100 on libinjection compiled to WebAssembly #239 merged, alert channels, mobile/SDK rows.
  8. Layout fixes found while checking: homepage hero overflowed 390 px screens (clipped text) and the CLI card's install command spilled out of its card; /docs started under the fixed header; three privacy sentences lost the space after an inline tag.
  9. Tests: deleted assertions that pinned the old wording of files changed here (docs-pages.test.ts /docs + homepage blocks, install-docs.test.ts desktop lines + homepage block). No new tests: copy has no behavior to test.

Removed / corrected claims (file:line on master)

apps/web/src/app/page.tsx

  • :33 SMS alerts, "push alerts to your phone" (no SMS alerting exists)
  • :36-39 "Active Defense — Strike Back": tar pits, honeypots, deception, auto-reports (only firewall auto-ban exists)
  • :54 "Expected Q3 2026" (today is 2026-09-25)
  • :62 payment FAQ rendered its <a …> HTML as literal text → plain text
  • :69-71 "Full API access with generous rate limits"
  • :73-75 AI modules "usage-based… metered separately" (nothing meters usage; top-ups are being disabled)
  • :78 air-gapped + "on-prem hardware appliances", "designed for FedRAMP, FIPS 140-2, ITAR", "GSA Schedule pricing"
  • :87 "email + SMS alerts"; :89 "Active defense — tar pits, honeypots, deception"; :91 "Full CLI, desktop & mobile apps" (mobile unreleased); :93 "Priority support"
  • :149-153 "SIEM / EDR / SOC capabilities", "Built on the open standards… ATT&CK, D3FEND, Sigma, OCSF, NIST CSF"
  • :192 "Windows… connects to a ThreatCrush server elsewhere" (desktop app talks only to a local daemon socket)
  • :247, :558 stale "after the basic housekeeping work… marketplace first" messaging
  • :337-340 "marketplace ASM", "Exploitability × reachability × blast radius", "automated active defense, API for SOAR/ticketing"
  • :375 correlation, "known-bad domains, lateral movement signatures"; :379-380 "Event correlation modules", "OCSF / ECS-shaped events"
  • :384-389 daemon "watches processes, files", "kill, isolate, tar-pit, or rotate credentials", "ATT&CK-tagged detections"
  • :395-399 SMS, "D3FEND-mapped runbooks", "SOAR / ticketing webhooks"
  • :427 "feeding telemetry up" into Splunk/Sentinel/Elastic/CrowdStrike/SentinelOne/Defender/SOAR
  • :434-522 open-standards grid: ATT&CK technique ID on every detection, D3FEND, Sigma, YARA, osquery, OCSF/ECS, CTEM-EXP IDs, NIST CSF, CIS mapping (guide CTA kept)
  • :629 threatcrush monitor "runs as a daemon" (it's foreground; step now install-service)
  • :739 desktop installs "interfacing with a ThreatCrush server"
  • :766 desktop "threat analytics", "E2E encrypted connection to your daemon"
  • :807 mobile "instant push alerts", "manage modules"
  • :840 extension "real-time alerts… monitor your servers"; :857 broken tree/master/extension link → apps/extension
  • :874 "All apps connect via end-to-end encryption…"
  • :901 "AI-enhanced modules billed on usage"
  • :932 "on-prem hardware appliances"; :940 "FedRAMP-ready, FIPS 140-2, ITAR compliant, GSA Schedule compatible"

apps/web/src/app/layout.tsx

  • :17-19, :64-66, :73-75 "Real-Time Threat Intelligence Platform", "threat feeds… threat actor intelligence", "Lifetime access to real-time threat intelligence"
  • :30 canonical: "/" on every page; :67 og:url = homepage on every page
  • :164 softwareVersion: "0.2.0"; :166 "active defense"; :181-184 SMS alerts, "tar pits, honeypots, deception", "ATT&CK, D3FEND, Sigma, OCSF, NIST CSF tagging"; :192 "AI-enhanced modules billed by usage"

apps/web/src/app/docs/page.tsx

  • :19-88 stale notes ("gated behind the waitlist", "real TUI is still planned", "daemon/service lifecycle is still being built", "scanning… still planned"); :89-93 activate; :96-104 "planned" items that have shipped; :133 Windows "connects to a ThreatCrush server elsewhere"

README.md

  • :78-80 "Linux desktop → installs the CLI + desktop app", Windows/macOS "connect to a ThreatCrush server"; :132 modules install docker-monitor; :153-158 "Build and sell" + nonexistent community modules; :170 /pricing; :180 extension "real-time alerts… dashboard popup"
  • apps/cli/README.md:78-80 same install lines

apps/web/src/app/privacy/page.tsx: :44-46 incomplete processor list; :62-63 "encrypted storage at rest"; :71-72 cookie statement that ignored the analytics scripts
apps/web/src/app/terms/page.tsx: :30 "threat intelligence… active defense tooling"; :48 "Lifetime licenses"
PRE_LAUNCH.md (deleted): Twilio + "phone verification is currently STUBBED"; TODO.md/docs/PRE_LAUNCH.md: v0.1.0-era checklists and Railway deploy steps; docs/SURFACES.md:24, :52 Railway

How verified

  • pnpm --filter @profullstack/threatcrush build, then node apps/cli/dist/index.js --help, every subcommand's --help, and threatcrush rules list (15 rules) — the /docs reference was written from that output.
  • Checked each replacement claim in code: firewall adapters + Fibonacci backoff + crawler exemption (apps/cli/src/daemon/firewall/), alert channels (daemon/alerts/), harden checks, init service list, desktop daemon-client.ts (Unix socket only), extension page-checks.js, install.sh desktop branch, GitHub App scan/announce migration, license_status usage.
  • next dev -p 3442 with local Supabase and NEXT_PUBLIC_APP_URL=https://threatcrush.com; curl of <link rel="canonical"> / og:url:
    • / → https://threatcrush.com; /docs → /docs; /store and /store?category=x → /store; /privacy → /privacy; /hire → /hire; a throwaway blog post /blog/copyanddocs-canonical-smoke → its own URL (row deleted afterwards).
  • Screenshots with headless Chromium (Playwright), viewport-by-viewport, inspected by eye: homepage at 1440 px (12 frames) and 390 px (19 frames), /docs at 1440 px (7), /privacy at 1280 px (5); document.documentElement.scrollWidth - innerWidth = 0 on all four. The 390 px hero showed a pre-existing clip (the unbreakable install command made the hero ~466 px wide, cutting the centered text on both sides); fixed in the second commit and re-checked: no element under <main> wider than the viewport at 390 or 1440 px, hero text wraps inside the screen, the CLI card's install command no longer spills out of its card. /docs content no longer sits under the fixed header. Three privacy sentences rendered without the space after an inline tag (</span>If…); fixed and re-checked with curl (no </span>/</code>/</a> directly followed by a letter on /privacy, /docs, /terms). Emoji icons render as boxes in this headless build (no emoji font); unrelated to this change.
  • pnpm --dir apps/web exec vitest run src/__tests__/docs-pages.test.ts src/__tests__/install-docs.test.ts src/__tests__/hire-page.test.ts → 10 passed. tsc --noEmit shows no errors outside pre-existing __tests__ typing errors.
  • Pre-commit hook (CLI + web next build) passed on every commit. After CI caught the homepage missing the rule counts doc-claims.test.ts requires, restored "96 OWASP CRS rules … plus 1 ThreatCrush rule" in the detection card; pnpm --filter @profullstack/threatcrush test → 32 files / 365 passed (doc-claims 12/12), pnpm --filter @profullstack/threatcrush-web test → 55 files / 472 passed.

Blocked on the owner

  • Legal review of /privacy and /terms before merge. Especially: the processor list, "not directed at children under 13", and whether the default-on /discovery publication needs more prominent disclosure.
  • Confirm which provider sends Supabase Auth emails in production (the policy names Resend for the email we send; GoTrue's SMTP is configured on the server, which I can't see).
  • Cookie-consent decision for DataFast / Robauto / Crawlproof (the policy now says they may set their own cookies).
  • The "Lifetime Access" FAQ and "One Price. Forever." heading are pricing-model statements, kept as-is per "don't change the pricing model". Nothing a purchase grants is enforced in code today.

Decisions

  • Root canonical "./" instead of per-route metadata: the homepage is a client component and can't export metadata, and this gives every current and future route a self-canonical without touching dozens of pages; routes that set one explicitly keep theirs.
  • Cut rather than rewrite the "open standards" grid; kept the CTEM guide CTA since the guide itself is real.
  • Did not state certification absence (FedRAMP etc.) on the site — just removed the claims and pointed to gov@.
  • Deleted root PRE_LAUNCH.md rather than keeping two checklists; docs/PRE_LAUNCH.md keeps its path because PRDs link to it.
  • Files other agents also touch: README.md/apps/cli/README.md install lines 78-80 and install-docs.test.ts (InstallerFix fix(install): put mise's Node on PATH and refuse Node older than 22.6 #245 edits neighbouring lines — agreed with them; whichever merges second rebases). Copy assumes these in-flight PRs land: cloud pipeline (servers link), CloudAlerts (server-side alerts + push), ExtensionAlerts (badge), AuthAccountFixes (self-serve deletion), MarketplaceReview (review queue), BillingFixes (activate removed). If one is dropped, the matching sentence here needs reverting.

The homepage, root metadata, /docs, README and legal pages advertised
capabilities that do not exist (tar pits/honeypots, SMS alerts, ATT&CK/
D3FEND/Sigma/OCSF tagging, SIEM/EDR integrations, E2E-encrypted apps,
FedRAMP/FIPS/ITAR, metered AI modules, a Windows client for remote
servers) and missed what does (auto-bans, hardening checks, cloud
dashboard via `servers link`). The privacy policy named four processors;
the code uses many more, and publishes public-repo findings by default.

The root layout's `canonical: "/"` made every page without its own
canonical point at the homepage; "./" resolves per route instead.

Stale v0.1.0-era checklists (Railway, Twilio, stubbed phone
verification) are replaced by one current launch checklist.
…paces

The unbreakable install command set the hero's min-content width to
~466px, so on a 390px screen the centered hero text was clipped on both
sides (the section hides overflow). Let the container shrink and the
command break. Three privacy-policy sentences rendered without the space
after an inline tag; spell the space out.
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

ThreatCrush Security Scan

15 finding(s)

HIGH/CRITICAL: 1 | MEDIUM: 6 | LOW: 8

Severity Rule Location
HIGH secret-aws-access-key prd/0003-detect-hardcoded-secrets-before-they-are-committed-or-served.md:126
MEDIUM js-open-redirect apps/web/src/app/auth/login/page.tsx:66
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:104
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:108
MEDIUM js-open-redirect apps/web/src/components/funding/FundingClient.tsx:97
MEDIUM js-unescaped-html-sink apps/web/src/components/GuideReader.tsx:265
MEDIUM js-uninitialized-buffer packages/scan/src/node-rules.ts:456
LOW secret-generic-credential apps/web/src/app/api/auth/refresh/route.ts:17
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:26
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:27
LOW secret-generic-credential PRD.md:269
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:121
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:122
LOW sh-remote-script-execution scripts/smoke-test.sh:47
LOW secret-aws-access-key scripts/smoke-test.sh:112

Snippets are redacted; ThreatCrush never prints matched credential material.

…mepage

doc-claims.test.ts requires every public page to state how many OWASP CRS
rules and ThreatCrush rules the engine loads; the rewrite dropped both.
@ralyodio
ralyodio merged commit 5bb02f1 into master Sep 26, 2026
12 checks passed
@ralyodio
ralyodio deleted the fix/site-copy-honesty branch September 26, 2026 01:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant