docs: make site copy, docs and privacy policy describe what ships - #254
Merged
Merged
Conversation
The homepage, root metadata, /docs, README and legal pages advertised capabilities that do not exist (tar pits/honeypots, SMS alerts, ATT&CK/ D3FEND/Sigma/OCSF tagging, SIEM/EDR integrations, E2E-encrypted apps, FedRAMP/FIPS/ITAR, metered AI modules, a Windows client for remote servers) and missed what does (auto-bans, hardening checks, cloud dashboard via `servers link`). The privacy policy named four processors; the code uses many more, and publishes public-repo findings by default. The root layout's `canonical: "/"` made every page without its own canonical point at the homepage; "./" resolves per route instead. Stale v0.1.0-era checklists (Railway, Twilio, stubbed phone verification) are replaced by one current launch checklist.
…paces The unbreakable install command set the hero's min-content width to ~466px, so on a 390px screen the centered hero text was clipped on both sides (the section hides overflow). Let the container shrink and the command break. Three privacy-policy sentences rendered without the space after an inline tag; spell the space out.
ThreatCrush Security Scan15 finding(s) HIGH/CRITICAL: 1 | MEDIUM: 6 | LOW: 8
Snippets are redacted; ThreatCrush never prints matched credential material. |
…mepage doc-claims.test.ts requires every public page to state how many OWASP CRS rules and ThreatCrush rules the engine loads; the rewrite dropped both.
# Conflicts: # README.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Site, docs and README copy now describe only what ThreatCrush does after the in-flight launch PRs. Nothing about prices or the pricing model changed; only false statements were removed or corrected. The privacy policy and terms changes need owner/legal review before merge.
apps/web/src/app/page.tsx): rewrote capabilities from the code (CRS + libinjection web rules, SSH/sudo/journal/network/DNS watchers, custom JSON rules, auto-bans via nftables/iptables/fail2ban with escalating ban lengths, hardening checks, code scanner with OSV + SARIF, pentest checks, email/Slack/Discord/PagerDuty/webhook alerts, cloud dashboard viathreatcrush servers link, desktop app on a local socket, extension page checks + org detection badge). Kept the structure; cut the "open standards" grid, and turned the CTEM / detect-and-respond sections into what each stage actually does today.apps/web/src/app/layout.tsx): title/description/OG/Twitter text, JSON-LDfeatureList/descriptions/offer text, removed the stalesoftwareVersion: "0.2.0". Replacedalternates: { canonical: "/" }(every page without its own canonical declared the homepage canonical, and everyog:urlwas the homepage) withcanonical: "./"andopenGraph.url: "./", which Next resolves against each route's own path. Pages that set their own canonical (blog posts, /hire, /about, …) still win./docs: command reference rebuilt fromnode apps/cli/dist/index.js --helpand every subcommand's--help(v0.13.9): 31 entries in 7 groups, all marked Shipped exceptservers link/servers unlink(from the daemon↔cloud contract), marked New. Droppedactivate(BillingFixes removes it). The "planned" list is now what really isn't available (signed desktop builds, store listings, SDK on npm). Added page metadata.apps/cli/README.md): community modules that don't exist are now listed as ideas; "Build and sell" → free to publish, listings go live after review;/pricing→/hire; features table adds bans, hardening, cloud dashboard; extension text matches what it does; desktop install lines matchinstall.sh(it installs the CLI everywhere and only points to the desktop app download)./.well-known/openthreat.json(on by default, per-installation switch), /investors "Recent backers", Module Store, push tokens (Expo/APNs/FCM, web push), Sentry (opt-in), alert destinations, OSV.dev fromscan --deps, the analytics/third-party scripts inlayout.tsx(DataFast, Robauto pixel + beacon, Crawlproof, Profullstack feedback widget, Google Fonts), linked-server uploads (hostname, version, heartbeats, detections with source IP + username + ≤16 KB metadata, hardening results, bans). Retention = what code states (10-minute phone codes; everything else until deleted) and the self-serve account deletion AuthAccountFixes adds (what it deletes and keeps). Removed "encrypted storage at rest" (not verifiable for the self-hosted box).license_statusgates nothing andactivateis being removed); service description no longer says "threat intelligence … active defense". Refund text unchanged. No governing law or new legal terms added.docs/PRE_LAUNCH.mdis now a short current launch checklist (engineering in flight, owner-only items, post-deploy checks) pointing atRELEASE_STATUS.md/SURFACES.md;TODO.mdpoints at it; rootPRE_LAUNCH.md(Twilio, "phone verification is STUBBED") deleted.docs/SURFACES.md: Railway → dev2 deploy, CLI v0.13.9 and feat(cli): port CRS 942100/941100 on libinjection compiled to WebAssembly #239 merged, alert channels, mobile/SDK rows./docsstarted under the fixed header; three privacy sentences lost the space after an inline tag.docs-pages.test.ts/docs + homepage blocks,install-docs.test.tsdesktop lines + homepage block). No new tests: copy has no behavior to test.Removed / corrected claims (file:line on
master)apps/web/src/app/page.tsx<a …>HTML as literal text → plain textthreatcrush monitor"runs as a daemon" (it's foreground; step nowinstall-service)tree/master/extensionlink →apps/extensionapps/web/src/app/layout.tsxcanonical: "/"on every page; :67og:url= homepage on every pagesoftwareVersion: "0.2.0"; :166 "active defense"; :181-184 SMS alerts, "tar pits, honeypots, deception", "ATT&CK, D3FEND, Sigma, OCSF, NIST CSF tagging"; :192 "AI-enhanced modules billed by usage"apps/web/src/app/docs/page.tsxactivate; :96-104 "planned" items that have shipped; :133 Windows "connects to a ThreatCrush server elsewhere"README.mdmodules install docker-monitor; :153-158 "Build and sell" + nonexistent community modules; :170/pricing; :180 extension "real-time alerts… dashboard popup"apps/cli/README.md:78-80 same install linesapps/web/src/app/privacy/page.tsx: :44-46 incomplete processor list; :62-63 "encrypted storage at rest"; :71-72 cookie statement that ignored the analytics scriptsapps/web/src/app/terms/page.tsx: :30 "threat intelligence… active defense tooling"; :48 "Lifetime licenses"PRE_LAUNCH.md(deleted): Twilio + "phone verification is currently STUBBED";TODO.md/docs/PRE_LAUNCH.md: v0.1.0-era checklists and Railway deploy steps;docs/SURFACES.md:24, :52 RailwayHow verified
pnpm --filter @profullstack/threatcrush build, thennode apps/cli/dist/index.js --help, every subcommand's--help, andthreatcrush rules list(15 rules) — the/docsreference was written from that output.apps/cli/src/daemon/firewall/), alert channels (daemon/alerts/),hardenchecks,initservice list, desktopdaemon-client.ts(Unix socket only), extensionpage-checks.js,install.shdesktop branch, GitHub App scan/announce migration,license_statususage.next dev -p 3442with local Supabase andNEXT_PUBLIC_APP_URL=https://threatcrush.com;curlof<link rel="canonical">/og:url:/→https://threatcrush.com;/docs→/docs;/storeand/store?category=x→/store;/privacy→/privacy;/hire→/hire; a throwaway blog post/blog/copyanddocs-canonical-smoke→ its own URL (row deleted afterwards)./docsat 1440 px (7),/privacyat 1280 px (5);document.documentElement.scrollWidth - innerWidth= 0 on all four. The 390 px hero showed a pre-existing clip (the unbreakable install command made the hero ~466 px wide, cutting the centered text on both sides); fixed in the second commit and re-checked: no element under<main>wider than the viewport at 390 or 1440 px, hero text wraps inside the screen, the CLI card's install command no longer spills out of its card./docscontent no longer sits under the fixed header. Three privacy sentences rendered without the space after an inline tag (</span>If…); fixed and re-checked withcurl(no</span>/</code>/</a>directly followed by a letter on /privacy, /docs, /terms). Emoji icons render as boxes in this headless build (no emoji font); unrelated to this change.pnpm --dir apps/web exec vitest run src/__tests__/docs-pages.test.ts src/__tests__/install-docs.test.ts src/__tests__/hire-page.test.ts→ 10 passed.tsc --noEmitshows no errors outside pre-existing__tests__typing errors.next build) passed on every commit. After CI caught the homepage missing the rule countsdoc-claims.test.tsrequires, restored "96 OWASP CRS rules … plus 1 ThreatCrush rule" in the detection card;pnpm --filter @profullstack/threatcrush test→ 32 files / 365 passed (doc-claims 12/12),pnpm --filter @profullstack/threatcrush-web test→ 55 files / 472 passed.Blocked on the owner
/privacyand/termsbefore merge. Especially: the processor list, "not directed at children under 13", and whether the default-on /discovery publication needs more prominent disclosure.Decisions
"./"instead of per-route metadata: the homepage is a client component and can't export metadata, and this gives every current and future route a self-canonical without touching dozens of pages; routes that set one explicitly keep theirs.PRE_LAUNCH.mdrather than keeping two checklists;docs/PRE_LAUNCH.mdkeeps its path because PRDs link to it.README.md/apps/cli/README.mdinstall lines 78-80 andinstall-docs.test.ts(InstallerFix fix(install): put mise's Node on PATH and refuse Node older than 22.6 #245 edits neighbouring lines — agreed with them; whichever merges second rebases). Copy assumes these in-flight PRs land: cloud pipeline (servers link), CloudAlerts (server-side alerts + push), ExtensionAlerts (badge), AuthAccountFixes (self-serve deletion), MarketplaceReview (review queue), BillingFixes (activateremoved). If one is dropped, the matching sentence here needs reverting.