{"success":true,"message":"Operation successful","data":{"methodologyVersion":"1.10","reportSchemaVersion":"2.0","summary":"Scores are deterministic. Every scored finding carries its point impact; totals are clamped to 0–100.","gradeThresholds":{"F":"0-49","E":"50-59","D":"60-69","C":"70-79","B":"80-89","A":"90-100"},"principles":[{"id":"reproducible","description":"Identical normalized evidence yields the same score."},{"id":"explainable","description":"Every deduction references a finding and evidence ID."},{"id":"versioned","description":"Report schema and report revision are returned with every stored scan."},{"id":"claim-to-evidence","description":"AI output separates direct observation from inference and marks claims without valid report evidence as unsupported."},{"id":"honest-failure","description":"Upstream failures produce partial errors, never fabricated scores."},{"id":"relevance-aware","description":"Checks a domain deliberately does not need are reported as not relevant with zero score impact, never as defects."}],"changelog":[{"version":"1.10","date":"2026-08-11","change":"Missing OCSP stapling is only deducted when the certificate names an OCSP responder; certificates whose CA publishes revocations via CRL are no longer penalised for a setting that cannot be enabled."},{"version":"1.9","date":"2026-08-08","change":"Mail findings are only scored for domains that use e-mail; probe failures yield an unknown state instead of an error; score values carry an explicit unit."},{"version":"1.8","date":"2026-07-29","change":"Added atomic claim-to-evidence AI output with explicit basis and support status."},{"version":"1.7","date":"2026-07-29","change":"Published methodology; evidence IDs and report version are part of the score audit trail."},{"version":"1.6","date":"2026-07-29","change":"Domain Health includes all measured scores and caps critical aggregates at 79."}]},"timestamp":"2026-08-31T19:37:07.274478381Z"}