← Site DNACapture methodology

Evidence is bounded, attributable, and honest about gaps.

Discovery

Public capture begins with the target origin’s robots.txt, then checks an optional coverage contract and declared or conventional sitemaps only when policy allows. Routes found in rendered same-origin links extend the graph within the selected route and depth budgets. Dynamic IDs are grouped into route families. Cross-origin, download, non-page, mutation-looking, blocked, and inaccessible routes remain explicit rather than silently disappearing.

robots.txt behavior

Site DNA identifies itself with the SiteDNA product token, combines matching groups, applies the most specific matching allow or disallow rule, and prefers allow on equal specificity. A missing robots.txt permits traversal; a server or network failure is treated as a temporary complete disallow. The optional authorized override is recorded and should be used only by an operator with authority over the target.

Rendered capture

Each public route is loaded with a selected capture budget and measured across its declared responsive and color-scheme states. Reports contain structured DOM, computed-style, layout, accessibility, motion, implementation, runtime-health, and environment evidence. Timings are measured from actual work, including browser-capacity wait; no simulated phase progress is shown.

Authenticated companion

The local Chrome companion measures approved app origins inside the user’s existing browser session. Credentials, cookies, OTP values, form values, response bodies, and screenshots are not exported. Authentication-provider origins are skipped. Automatic navigation is GET-oriented and rejects mutation-looking routes; optional state exploration is limited to controls with a reversible state target and verifies restoration.

Completeness and uncertainty

“Complete” means every route template discovered inside the selected policy and budget was captured. “Complete with gaps” means routes are accounted for but one or more were blocked, excluded, failed, or discovery was truncated. Neither status proves an unlinked, undisclosed, permission-inaccessible, feature-flagged, or differently personalized route does not exist. The confidence frontier preserves those limits in exported artifacts.

Storage and sharing

Coverage sessions are saved in browser-local IndexedDB and companion evidence in extension-local storage. Public manifests and briefs can omit origins, redact query values and dynamic path identifiers, truncate or omit captured text, and replace private terms. The exact public JSON can be reviewed before download. Full session archives intentionally remain unredacted for local recovery.