Priority remediation, same day
The follow-up to the exposure watch. Findings raised in the morning run, acted on the same day under a bounded authority, then verified from outside. Every identifier of the organisation has been removed.
Mission summary
Apply the safe, immediately actionable priorities from the previous day's external exposure watch, under an explicit operator authority to act alone on what could be acted on alone. Anything requiring credentials, tenant administration or DNS changes across third-party providers was left for joint close-out rather than attempted.
- Mission type
- Defensive remediation
- Execution path
- Repository implementation delegated to the platform's engineering agent; canonical inventory update and independent external verification retained by Ghostline
- Overall status
- Partial completion by design. Safe web controls deployed; mail and identity changes retained for joint close-out
Changes deployed
01Canonical public asset inventory
The two application hostnames flagged in the watch as uncanonicalised were recorded in the project's asset inventory, marked client-owned and scoped to defensive passive and low-impact external monitoring. This closes the inventory gap that made the previous run's scope a judgement call rather than a lookup.
02Hard not-found handling for sensitive-looking paths
The watch had recorded that sensitive-looking probe paths returned the generic application shell with a 200 status, so absence of an artefact had to be inferred from body content rather than read from a status code. The request gate now returns an explicit plain-text 404 with no-store handling for the approved probe set and for false local identity metadata endpoints.
- Environment file path on the application host returned 404 with a plain-text body
- Identity configuration path on the marketing host returned 404
- The real login page continued to return 200, so the change did not overreach
03Security response headers
The watch could not assess header posture at all, because the fetch path exposed status and body but not a complete header set. Rather than leave a blind spot unaddressed, the standard set was added at the application config: strict transport security, content-type options, frame options, referrer policy and permissions policy. The delegate confirmed the headers present in production.
Build and regression verification
Deploying a security control that breaks authentication is worse than the exposure it closed, so the checks below ran before and after.
Held for joint close-out
Six items were deliberately not actioned. Each one needs a credential, a tenant administrator, a third-party DNS change or a commercial procurement decision that sits outside the authority granted for this run. They are listed rather than quietly dropped.
- A vulnerability-intake contact file, held until a monitored mailbox is provisioned and confirmed. Publishing a contact route nobody watches is worse than publishing none
- Provider mail signing on the primary domain, which requires tenant configuration and DNS selector values
- Sender authentication enforcement, which must follow signing and alignment validation rather than being switched on directly from monitoring mode
- Transport security policy across both mail domains, which requires policy hosting and DNS changes at two separate providers
- Confirmation of the identity tenancy association, which requires an administrator
- Certificate-transparency and commercial breach telemetry sources, which require selection and approval
Risk and authority status
- No secrets, mailbox identities, DNS records, tenant settings or mail policies were invented or changed
- No active testing or exploitation was performed at any point
- Deployed changes are bounded web hardening, with passed build and type checks and independent external status verification
- Verification was performed from outside the estate rather than trusted from the delegate's own report
Verification status
Partial completion, verified. Web and inventory priorities are complete and externally confirmed. Mail, identity, vulnerability-intake and telemetry-source items remain intentionally deferred for controlled joint action, and carry forward to the next watch as known open posture rather than as new findings.

