Proofs on drop day

Live exit and WebRTC probes over the Sessions you have open.

What it's for

The proof panel answers one question with evidence instead of assurances: do these Accounts actually look separate to a ticket site? It composes each Account's isolation checks — the IP a site sees, a hidden WebRTC leak, clock and region, and the Fingerprint — with the drop set's independence score into one shareable report. Its own standard for itself, in its own words: proof, not promises.

The proof panel: a per-Account table with verdict, exit, WebRTC, region and fingerprint columns, the exit and WebRTC cells reading 'Not checked' until a session is probed.
Static checks are filled in; exit and WebRTC read 'not measured' until you probe an open Session.shot-go · proof panel, 8 accounts, exit and WebRTC columns reading 'Not checked', two rows verdict 'Not fully measured'

Static now, measured live

The checks split into two kinds, and the panel never lets one masquerade as the other.

Static
Fingerprint, clock/region, and independence. These need no open Session — they're properties of how each Account is configured, readable at rest.
Live
The exit IP a site actually sees, and whether WebRTC leaks around it. These read not measured until a Session is open and probed — a claim about the live connection can only be made by measuring the live connection.

Measure the open accounts

The Measure open accounts button probes the Sessions you have open — one per Account — reads the real exit IP each presents, and gathers its WebRTC candidates. It only ever hardens the report: measuring can move an Account from a clean static verdict to an exposed one on a real leak, never the reverse. Rows you haven't probed stay honestly labelled as static-only.

The WebRTC verdict

WebRTC can surface a machine's real or LAN address through its ICE candidates even when traffic rides a proxy — deanonymising the machine and cross-linking every Account on it. The probe tiers each surfaced address: the proxy exit is clean, a private or real-IP address is a leak, and a public address it can't confirm as your exit is a warn — a rotating or untested proxy, not a proven leak.

A clean row is not a measured row

An Account whose static checks all pass but whose exit and WebRTC were never probed does not wear the same green as a fully measured one — its verdict reads Not fully measured. This mirrors the rule the whole product follows: nothing unmeasured is graded as though it had passed.

This drop set, not the whole fleet

The proof is scoped to the Accounts in front of you, but links are detected across your whole fleet — so an Account tied to one outside the set is still flagged. The Anti-Linkage board below the proof counts the whole fleet: same detection, wider denominator. And only the hard links stop a drop.

What the report carries

Copy proof and Export CSV contain exactly what the table shows: Account names, the per-check verdicts, and counts. The card, proxy, cookie and IP values behind those verdicts are not part of the artifact you copy or export.