C.E.R.T.O. — Certification and Online Trace Collection — AcquisizioniForensi.it

==================================================================
         WEB PAGE ACQUISITION REPORT
==================================================================

ACQUISITION INFORMATION
-------------------------
Acquired URL: https://example.com/
Domain: example.com
Remote server IP: 104.20.23.154
Acquisition code: c6269c8a-fca9-46d9-ac0f-cb8ba079e57b

TIME INFORMATION
----------------------
Start time (UTC): 2026-09-28 15:18:10.622Z
Navigation end (UTC): 2026-09-28 15:18:40.270Z
Start time (Europe/Rome): 2026-09-28 17:18:10 GMT+2
Navigation end (Europe/Rome): 2026-09-28 17:18:40 GMT+2
Note: the end shown is when the operator closed the navigation. The full-page re-capture, the network checks, the timestamp and the packaging happen afterwards, each dated in the log.

TIME SYNCHRONIZATION (NTP)
--------------------------------
NTP server: time.google.com
NTP synchronized: Yes
System offset: 14 ms
NTP round-trip: 73 ms
Assessment: Clock synchronized (3/3 sources, consensus offset: 14ms, max dev.: 22ms)

CLIENT NETWORK INFORMATION
--------------------------
LAN IP address: 192.168.1.20
Public IP address: 93.67.184.82
Default gateway: 192.168.1.1

SERVER AND CONTENT DELIVERY NETWORK
-----------------------------------
Acquired host:                   example.com
Contacted address:               104.20.23.154
                                 (observed by the browser during the connection)
Content delivery network (CDN):  Cloudflare — probable identification
Edge node:                       FCO
Origin server:                   not observable from this capture point
                                 (this is precisely what an interposed CDN conceals: the contacted address is the edge node, not the origin server)
DNS A records:                   172.66.147.243, 104.20.23.154
DNS AAAA records:                2606:4700:10::6814:179a, 2606:4700:10::ac42:93f3
DNS records measured at:         2026-09-28T15:18:48.499Z

Signals detected:
  - header cf-ray: a423b825294eea4e-FCO
  - header cf-cache-status: HIT
  - server: cloudflare

The contacted address is a datum observed during the capture and can be
verified in network/network.har (serverIPAddress field). The DNS records and
the signals can be verified in network/dns-lookup.txt and
network/http-headers.txt.

==================================================================
                    FILE INVENTORY
==================================================================

ACQUISITION FILE
-----------------
logs/acquisition-log.at-report.txt
  Size: 23.08 Kb
  MD5:    8c7284e81f099552e52aea13a90e52f7
  SHA1:   813796af51a6e79340bc9aede8f950f5adc6550c
  SHA256: 103a6edeaa59ad7091f3750cef19d338bf9ecfd00a1deca7f50296e52b7068cf
  SHA512: 02ee3354d83a4b68e6ae86ca70d4847e5b3645e280c93b48b0398d1889d1b7c3d82696c84352510c769792c99816f3371b0a54c53f23cc5465acfada42fe6d31
  Snapshot of the log at report time. The full log (logs/acquisition-log.txt) continues until the bundle is closed and is covered by the signed manifest.

HTML CODE
-----------
resources/site-structure/example.com/dom-snapshot.html
  Size: 755 Bytes
  MD5:    1674f8ff742cb17dcfea0e97786f64c8
  SHA1:   7e6fa144f158aed134c0f864827455983f61d715
  SHA256: 5a3234114b48e03924eb5299894516bc76aed8d9fb14c31100c6a1e85ddf93ce
  SHA512: 3f09d800784b7522a0164cb85c0b3749941c4209146ee2526346ccb704029949a21d6d05fc753436632510bc0e729d0c59cac13673170aaa610ab30719384ede

HTTP HEADERS
-----------------
network/http-headers.txt
  Size: 1.42 Kb
  MD5:    3dfb60d4213b840f9be2a2cfca4d42ba
  SHA1:   3870a03052615f88e78fc52c34cdd941aa3c48c0
  SHA256: c464a7aa21bc7df2c62085aaf7742d8307e288bbca9f1c8fb26e4de1290d35f7
  SHA512: 3ea56f302d61a3b520ebdcd1d83279ea79fae9609db3f2fbda853e2fea52fc3c0f1013763368d7185d5807699599937acbb330640188586de6f21af85aae8aef

EXTRACTED LINKS
-------------
reports/links.txt
  Size: 747 Bytes
  MD5:    3a8282d47e979f4ca43d125e75f1d2f5
  SHA1:   d2deecee1e05bab79c745c04fe047687c6727ff0
  SHA256: f4b137f000ce2c0522f89b3105dfe39076d29a65ca33c52bb727cc02d8743380
  SHA512: fbdef0066645f63a4d1a4a3b068e8669ecd15352327825b6fc958f89ea1e147755da86c9c43be7dd5b147399bf2be2725b6e049e75aae657f27d78aa0e4db9e8

COOKIES
------
reports/cookies.txt
  Size: 1.03 Kb
  MD5:    bc647046a22fed3f305b36d1f159d3bc
  SHA1:   c294f51de511d0be824d6748b52be3967b817b8f
  SHA256: 159af30633ea8080ba4e95a2b39ad9fe849879489014048d4bebcddb7656eb8f
  SHA512: 47458bf31b159d95a60cc601138e366b358c00d4b6004fba2eb10e95033698c14d7eaa70d5072c433cbd17e48b4c967de82e2dc492f8485f522b0bd36e0d21ba

HAR NETWORK ARCHIVE
-----------------
network/network.har
  Size: 4.77 Kb
  MD5:    30ca0d08c8f86f5cd61ae5c0938eb1a6
  SHA1:   d431d1d9f23f315ea3fa222c84114207b837c370
  SHA256: f57caebcbbec8ae0799e64391d32887e55aeea24b91cb7f9e999ae3374c684c0
  SHA512: fcb2da45ab8db5be853591611d861417f3383235fe804cf41d357e988debea5dc786153f42f7bcee9c79488af5cf5ef4b93d56615397ff5ac6a9ecf373070980

DNS QUERY
---------
network/dns-lookup.txt
  Size: 389 Bytes
  MD5:    ed781034617584de563f4f1982a99f2a
  SHA1:   0cf1cee870fd446478b3abf77732ebd51b3e190e
  SHA256: 7613ae018649a8e039e49fbc207ea56443a5a205708f843a740844544125481a
  SHA512: d01a8e7f8981bfefaf1ac8ad81e59487eb47eacda7e404696e61bf03cda9239b96e55d1279b1be8e78fb8be7e27aca451d03b272fae8973cf6865712706f5b1b

VIDEO RECORDING
-------------------
evidence/video/recording_2026-09-28T15-18-14-560Z.webm
  Size: 794.76 Kb
  MD5:    eba137b8309bf6da5c964fd4f9f3103b
  SHA1:   97e1da3af34a820498050256e91951b4fbf30447
  SHA256: 9acd91bcc1ee6f11b55973cfa43e5ed71760e92f7d86f963e58541b130765c56
  SHA512: 15ed026ed263efc6783bcc723aa617f07f808281596c8c3333ad2611e0034dac15971de4f56327d2fe2cca859cc7524c591f72908dbbd56dcee9844b10ea46d5


SCREENSHOTS
----------
reports/screenshots.txt
  Size: 2.69 Kb
  MD5:    3bae1b7cb1f0e97cd00a66445442ed0d
  SHA1:   600134b04ac4e72cd3b5fc4f1cc35c896d6229f1
  SHA256: 9af9ae2da13f1d6a775735c0003a743ab419d789c4b90e0e26eb0e4f6dc07f04
  SHA512: 06cd2cb0542bc56156e5c937047a9d6ab3db7157ef0cc6786366ddc92f70483ae21866a1f41d23a387329461d50038cf77c031552ceda3303343d3c163c826e7

DOWNLOADED RESOURCES
-----------------
reports/downloads.txt
  Size: 1.73 Kb
  MD5:    e37f8e29caae14fbdac2090868901398
  SHA1:   527a6d0ac6ea7688d35f25efb0c841a1d12b13e9
  SHA256: bc696e37bb1dd5394ae62155de244562ba342ca0819c81bf3d5c2467561fb4bd
  SHA512: 79a8560cf211823d5c91e46ab8b0d40fc2f63526a3462af184e0ebbab09f805318f84f0e47dbc9d9975c25a0fee9118fe49e33739f855e439d2ebc12572c620a

SYSTEM INFORMATION
------------------------
reports/system-info.txt
  Size: 6.63 Kb
  MD5:    97275043abc4f7a1b0271a7bfc63b3b8
  SHA1:   0618c39ce1400d4fe932f95447f4d21628e3281d
  SHA256: 6f175c46213dd41fd64bb4818e083c6273c6c8a3930ec68a31392139e6d66f94
  SHA512: 641b0639cf1d74abea3d0e0ad6ff6fc6c2f658ac90885d37f3e802eede8aac529fbd54986b785b4e65cd64f9b00197a4d12a1b3912c1f4f17d3668554e05e4cb

TRACEROUTE
----------
network/traceroute.txt
  Size: 598 Bytes
  MD5:    02a1f3194e8a1a8f4ce913468700b012
  SHA1:   5862dcbaf8295807e121ad997057649fd5a72e94
  SHA256: 96836544fdba868a8e313d8417e1f5f4f8393c52a71226d1392a9848b55e4a46
  SHA512: b9d5e6fee33513d461e0bbebf4b1ddb470ce4e19a1934b2f3843f3073010b6b346025e511d687120a430d0c90522719adf3d542e4c3d4dc87e45f6db45bd5eb0

WHOIS
-----
network/whois.txt
  Size: 300 Bytes
  MD5:    b95d003c93e54adcfcbd9978ac99fcee
  SHA1:   7e42edf9255d029e31b6d4062856045ae9e7e552
  SHA256: 3e83b97fd7fc54ec244c6524fe284b84cc81ed867381e988c0133129b82a068f
  SHA512: cd423ccd13a6cb89b1b89a6a07ea04b8a23d15ffa6280a5c828f8db88262bb626918086f15fd573657d48bc7d1d014da66958444b6027d261e0d071e4c59cdef

SSL/TLS CERTIFICATES
-------------------
tls/ssl.txt
  Size: 1.23 Kb
  MD5:    8bf295af7010e7eff68708c842a7d0ad
  SHA1:   96ece1bcdf81d90828ae6dabb59fec920c911227
  SHA256: 5603980f4dc50cb6e151b65d456765acaf57c25795d62a7841c94d4906d8fd7a
  SHA512: e475ab5c9f20c8414b773fe6824966cc7d0c0728872fe32e4f64c01a907fb8a2305ba15d26f4bd75e7ee1929e1e751d588c130ae0bf612913144d7016e46d979


==================================================================
                  ACQUISITION OPERATOR
==================================================================

Identification of the subject who performed the acquisition, for
chain of custody purposes (ISO/IEC 27037 §6.5). Data retrieved
from the /app/auth-app endpoint associated with the API key used.

-- Identification data --
Name:               Giovanni
Surname:            Carrieri
Username:           giovannicarrieri
Account ID:         1
Email:              email@acquisizioniforensi.it
PEC:                n/d

-- Professional data --
Business name:      Giovanni Carrieri
Tax code:           [omesso]
VAT number:         07669810728



==================================================================
                  DECLARED FORENSIC SCOPE
==================================================================

Reference best practices: ISO/IEC 27037:2012 §6.4 (Justifiability),
NIST SP 800-86 §3.1, ACPO Good Practice Guide for Digital Evidence.
The operator declared in advance the object, the scope and the
acquisition method BEFORE starting. This declaration is an integral
part of the evidence and is reported here for forensic completeness.

Scope mode:         Domain and subdomains
Initial URL:        https://example.com/
Object:             Demonstrative forensic acquisition of a test web page via web page capture software
Method:             Viewport and full-page screenshot + DOM HTML snapshot + Referenced resources + Network HAR + Session video + WACZ replay archive + Timestamp Public TSA RFC 3161 (Sectigo/DigiCert/GlobalSign)
Declared moment:    2026-09-28 17:15:28 (UTC+02:00)

-- Scope statistics --
Logical pages visited:         1 (recommended limit: 10)
In-scope navigations:          0
Out-of-scope navigations:      0
Blocked navigations (operator refusal): 0
Auth-flow navigations (login/OAuth):    0

------------------------------------------------------------------
                  LOGICAL PAGES VISITED (1)
------------------------------------------------------------------

For each visited page the forensic artifacts are collected in the
dedicated sub-directory (pages/NNN_domain_path/). Hybrid strategy:
  - viewport + DOM: captured real-time at the moment of the visit
  - fullpage: captured post-hoc at the end of the acquisition,
    by navigating again to the URL (temporal drift noted).

#001 [ IN  ] https://example.com/
         First visit:      2026-09-28T15:18:10.622Z
         Last visit:       2026-09-28T15:18:52.130Z
         Trigger:          initial
         Sub-directory:    pages/001_example.com_0f115db0/
         Artifacts:
            - pages/001_example.com_0f115db0/screenshot-viewport.jpeg (real-time @ 2026-09-28T15:18:18.135Z)
            - pages/001_example.com_0f115db0/page.html (560 bytes, real-time @ 2026-09-28T15:18:17.986Z)
            - pages/001_example.com_0f115db0/screenshots-fullpage/ (1 sections, post-hoc @ 2026-09-28T15:18:54.445Z, drift 41s)

------------------------------------------------------------------
End of forensic scope section.
------------------------------------------------------------------


==================================================================
                    SSL/TLS CERTIFICATES
==================================================================

SSL/TLS CERTIFICATES SUMMARY
---------------------------
tls/ssl.txt
  Size: 1.23 Kb
  MD5:    8bf295af7010e7eff68708c842a7d0ad
  SHA1:   96ece1bcdf81d90828ae6dabb59fec920c911227
  SHA256: 5603980f4dc50cb6e151b65d456765acaf57c25795d62a7841c94d4906d8fd7a
  SHA512: e475ab5c9f20c8414b773fe6824966cc7d0c0728872fe32e4f64c01a907fb8a2305ba15d26f4bd75e7ee1929e1e751d588c130ae0bf612913144d7016e46d979

tls/certificates/example.com-ssl-ca-3.crt (Domain: example.com)
  Size: 1.50 Kb
  MD5:    39e21aa4132050b0c5a2313ae18ca5dd
  SHA1:   4dda95d57ecfef1eba358516ce1a0da2f3bbaf9e
  SHA256: 24b226bca66d2fd890ea56cf56d9ddd177fd5ed57ff9f9859b073057a96a881b
  SHA512: e4b392f15abcaaa1a5617bc9a4da679e07d9262bd7188fa54d0d83042d480dc276cd01e3da9282642e9c12e6aa2e12d65df0ec00aef682b4e1595f9e6494148f

tls/certificates/example.com-ssl-intermediate.crt (Domain: example.com)
  Size: 1.04 Kb
  MD5:    b27c032689060dbf3c5361b86b310190
  SHA1:   7e2dc14abacf58ed54e4c54a043703a252566c65
  SHA256: 1d3773ca403674d9cbaf899801b315ad0d3647d7ff8833e5b97c6cf67611ad78
  SHA512: 90694afd4251deeec4c12da5b89ed12bbf8eaf9cb6e56c1d9318e4d860d822b8a32241c1fdc9cabeab4910f93f39c30d4dfa22b8085f9bfdaf6a2c745cd6c641

tls/certificates/example.com-ssl-leaf.crt (Domain: example.com)
  Size: 1.38 Kb
  MD5:    70d19fec79902481f250b70c47566a69
  SHA1:   7787aed80924a58242c20be5e381b633bc40f717
  SHA256: 3bc9242e86bff9fb2b409ad80857697ab3d6f03accac30d6cb4710d247c64559
  SHA512: 4f8a1d420ee4c6a108af69e608e4f897c3a19382f28a77bd879e3e81ac84437227d2efb95e78e90e89dcac24d006d5a9386ce631964d7b43f4c99838bcac6725

tls/certificates/example.com-ssl-root.crt (Domain: example.com)
  Size: 1.14 Kb
  MD5:    d273578e45a4eb1a9900179c18bbd52b
  SHA1:   7135ba0c78b34fe49e5573a6c44352a013c2ce87
  SHA256: 6673455bb06ef4fdbbb41d6b86c8b434836448d33b957d1b3ceff0a053787dcd
  SHA512: cef6049054c83962627accfe2fc2a52d50eec814ef44ea1a08d15b834db540304c9def97b2101d28d252215df61aff559f44838802061630b7469cbb698fa025

tls/certificates/example.com_162bd2cd.crt (Domain: example.com)
  Size: 1.38 Kb
  MD5:    e0157eedddf092500cedcbcf83e1d770
  SHA1:   00e7636dc24e11e64c3a9af0556d3a50a4165eff
  SHA256: 9ea6e85373a2380b62d11ce3a855e1aeac775911b4ae27ae3b3e381243d74f2d
  SHA512: ec689656c841f5d3ea2cd1a852208e6ac02ecc358c34247032409f0bfafb2cb2f72eefdcdae81279224d9409c8192ec0dc27f0288f28a169780f8ad2f6b15745

tls/certificates/example.com_162bd2cd_chain.crt (Domain: example.com)
  Size: 5.06 Kb
  MD5:    9f402b205b3b7cb4ab603e1f2fe80d36
  SHA1:   3e11f61f546cf9031a1471ce25fe3de234c7aaf4
  SHA256: fc16f8f4047889a353bb46ee94e1ce34c4fd1ba57fab1621aa6a352e2caf5b95
  SHA512: 2433c011688c274d41c91d6283a9be577afc464fd98b80ec7b56863e1b777ecc8162e600ba7aef9e376fea92fde4a722cfa3216e28815f6130c0a6a9b517adb8


==================================================================
                    USER INTERACTIONS
==================================================================

USER INTERACTIONS REPORT
------------------------
reports/interactions.txt
  Size: 661 Bytes
  MD5:    24cebb185ef4b4f2bcb6be930e1c1493
  SHA1:   66cf15958e4df313a75fcf02c03f55374ba5c8bf
  SHA256: 09be8c0194e3edb2a4b37b5ff46acf6a8fcf8f2b5fca16f486825bc783cb6a69
  SHA512: 21907be2c30cc6528fbb4ca414ab50ca50c57d9730a9034987edf9311eff6be222396ad3cba76a1f129161953a4fab3a507dc68b04f129e189a71a1a2a0b163d

evidence/interactions/user-interactions.json (Raw data)
  Size: 2.23 Kb
  MD5:    e194475c51a75c0049372683fe9e4ef6
  SHA1:   35ad0b9913195e16cfce9b043efabc764eae9333
  SHA256: a003bc08af5ffc86b5a888037829a3847a6397063707953c5e952bab4b787a6c
  SHA512: 50f35d0b3304ab154a0ca50dab9ce85cbba56b46dbf92cd9f977eaf37be0068fa6811ded80098c43d8275a8fcf518e8361b19dc0314c80ad368be7bf162f7bf1


==================================================================
                    WACZ ARCHIVE
==================================================================

WEB ARCHIVE (WACZ)
-----------------------------
evidence/ReplayWebPage.wacz
  Size: 185.86 Kb
  MD5:    809416dba183a6b051099d3ef1057028
  SHA1:   ca2f7a24c2a33c76f169ea0350abe705de12f932
  SHA256: e2eae6945a263836d96affec8590aae849151988773978038463a2a35e6c5076
  SHA512: b8a720df2e2115868e51b771e32245636cada9af7c7b3f722066e31738d7bb7c199a8764f9f699345390697c14ec5f52d18a0dc6d6a1e74bf776fb1a85cc846d


==================================================================
                    VIDEO RESOURCES
==================================================================

No video resources were reassembled during the session.


==================================================================
                    REPORT METADATA
==================================================================

Report Version: 3.3.1 - 2026-09-28

==================================================================

======================================================================
                    TOOL ATTESTATION
======================================================================

C.E.R.T.O. app version: 3.3.1
Binary type: directory
Binary path: <app>/app.asar
Source files hashed: 1
Binary size: 1446 bytes

Binary SHA-256: a89dc7b018f31d3ffd446cb51fcbb61f37b443d71470ffa531545c1bbb310288
Binary SHA-512: 406954cd4c137edceae68766ec66b3b9f65ddc1e47d1e1cadab95a7525230ae02a3e81fe308e5244b60f937c82026255dbb6f7c2ccf2b7db664e6d060af64db1
Binary MD5:     2b80af9ae555b992124d454b90e8744b

Runtime versions:
  Electron: 39.8.10
  Chrome:   142.0.7444.265
  Node.js:  22.22.1
  V8:       14.2.231.22-electron.0

Platform: darwin/arm64
Electron executable path: /Applications/CERTO.app/Contents/MacOS/CERTO
Attestation computed at: 2026-09-28T15:18:59.917Z
Meaning: this block proves which exact build of the tool produced
the acquisition. If the hash differs from a reference build, the package
was generated by a different version of the software.


======================================================================
                    MANIFEST INTEGRITY
======================================================================

Manifest file: hashes/file-hashes.json
Number of included files: 78
Total size of included files: 3580926 bytes
Manifest size: 12415 bytes

Manifest SHA-256: 225bd83cb07f89d06ccf5e10b9157ba935fbd78c1d52e5192049fb7f25a01ab6
Manifest SHA-512: 5ad46033a6754faaaad9cab9ddd395e16a91dd383cf95c9ceaf3f22732ff7db907afed4711bd3b0ece3d511b9d64948836ceee5e1cad020bf5ec602372082f05

INTEGRITY CHAIN:
  1. Each acquisition file → SHA-256 → hashes/file-hashes.json
  2. hashes/file-hashes.json → SHA-256 → this report (above)
  3. This report → RFC 3161 timestamp → reports/report.tsr
  4. Conclusion: the manifest hash, inserted here BEFORE the TSA signature,
     is cryptographically covered by the timestamp. Verification:
       sha256(hashes/file-hashes.json) == 225bd83cb07f89d0...
       openssl ts -verify -in reports/report.tsr -data reports/report.txt

EXCLUSIONS from the manifest:
  - reports/report.txt: this is the CURRENT file, including it would be recursive.
    Its hash is certified directly by the RFC 3161 timestamp.
  - reports/report.tsr/.tsq: artifacts of the timestamp itself.
  - hashes/file-hashes.json: the manifest itself (anti-recursive).
  - interactive.html: derived view of the manifest, not a primary artifact.
  - System files (.DS_Store, Thumbs.db, desktop.ini) and metadata/mysql.json
    (upload payload, not part of the acquisition).


======================================================================
                    EXPLICIT FORENSIC STATEMENTS
======================================================================

1. ISOLATED BROWSER ENVIRONMENT
   The Forensic Browser used for this acquisition runs in an Electron
   partition separate from the operator's personal browser. At startup:
     - Cookies: none pre-existing
     - localStorage / sessionStorage: empty
     - HTTP cache: empty
     - Browser extensions: none user-installable
     - User-agent: standard Chrome/142 with C.E.R.T.O. identifying suffix
   The browser's pre-acquisition state did not influence the capture.

2. POST-HOC FULLPAGE CAPTURE
   The scroll-and-stitch fullpage screenshot of each visited page is taken
   AFTER the user navigation ends, by re-navigating to every already-visited
   URL (hybrid strategy: real-time for viewport+DOM+HAR, post-hoc for the
   complete fullpage scroll). Forensically relevant consequences:
     - Post-hoc pages executed: 1 of 1 visited
     - Time elapses between the original visit and the fullpage capture (drift),
       documented in each page's pages/NNN_…/page-metadata.json (fullpageDriftMs field).
     - HTTP requests made during the re-navigation are SEPARATE from the
       official HAR (already frozen): they do not pollute the primary network
       evidence. The acquired site's server logs may however record requests
       beyond the main acquisition duration.
     - The real-time viewport screenshot and real-time HTML DOM snapshot
       remain the AUTHORITATIVE references for the "at time of visit" state.
       The fullpage is an additional visual representation at T+drift.

3. EXCLUSION OF THE INTERACTIVE DASHBOARD FROM THE MANIFEST
   The interactive.html file is a VIEW of the manifest (it reads the
   metadata and presents it in a navigable UI). It is NOT a primary forensic
   artifact:
     - Generated AFTER the manifest (it could not include itself)
     - Not signed by the timestamp (it derives from already-signed artifacts)
     - If modified, the change does NOT affect the evidence: the data is in
       the manifest and in the timestamped report.
   Always verify the primary artifacts (reports/report.txt + reports/report.tsr + manifest) as the
   authoritative source.

4. SCOPE-BOUNDARY ENFORCEMENT
   Declared mode: domain-and-subdomains
   Enforcement layers applied:
     - Client-side hooks (history.pushState/replaceState, anchor click)
     - Electron will-navigate event
     - setWindowOpenHandler for target="_blank"
     - did-navigate-in-page rewind for SPA pushState
     - webRequest.onBeforeRequest at the network level (mainFrame block)
   Any out-of-scope navigations blocked or authorized are recorded in
   metadata/scope-summary.json with a textual rationale.

5. MULTI-SOURCE NTP TIME SYNCHRONIZATION
   The system clock was compared against multiple NTP servers
   (time.google.com, pool.ntp.org, time.cloudflare.com) in parallel query.
   The consensus offset is the median of the measured offsets. The maximum
   deviation across sources is documented in the NTP_MAX_DEVIATION_MS field in
   metadata/data.json: if >100ms, synchronization is marked "warning".

