Skip to content
Code Recycle

Solution bundle · for humans & their agents

Is This Counterparty Who They Say They Are?

basic checks · first-partyactively maintained$0 during beta (was $73)

The site says Acme Corp. The domain is registered to someone else. A look-alike of your domain resolves. The listing photo is already published somewhere else.

by dropbear · Code Recycle reviewer

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Three keyless-first checks on the things a counterparty controls — their domain's registration record, look-alikes of yours, and whether an image is already published elsewhere. Each answers a question a website cannot answer about itself, and each refuses rather than guessing when it cannot tell.

The failure these share

Every one of them is a claim you were handed, that you have no independent way to check. The site describes a company. The email looks like it came from your domain. The photo looks like theirs.

  • Domain Registration Check — the registry names a different identifiable company than the one you were told. A site can describe any company; the registration record is not the counterparty's to edit.
  • Domain Exposure Watch — which addresses on YOUR domains appear in breaches, and which look-alikes of your domain somebody has registered and pointed at a live host.
  • Reverse Image Search — whether an image is already published elsewhere, with the lane that answered reported honestly rather than a quiet downgrade.

Why buy them together

They share one architecture, so you learn it once: keyless first (every one has a lane that costs nothing and needs no account), bring your own key (the paid lanes are optional and never proxied through us), fail soft (a timeout returns `null`, never a clean bill of health), and pluggable (providers are injected, so no lane is mandatory).

That last point is what makes them compose. Each returns "could not determine" as a distinct outcome from "determined: nothing" — so a caller can combine three signals without any of them silently voting "fine" on an outage.

What none of them do

None takes a person as input. Two operate on domains, one on an image you supply. There is no people-search anywhere in the set, and the breach lane refuses in code — not merely in its terms — to look up an address outside the domains you have declared you control.

Proof

36 tests across the three. 16 deliberate defects applied to real source, 16 caught — including the one that removes the breach lane's ownership boundary, and a genuine fail-soft bug found and fixed during extraction.

Delivery

One private repository invite covering all three, within 24 hours of purchase. Single-product commercial license across the set: use and modify in any number of products; no redistribution or resale of the source.

01Capabilities

Does

  • + Entity resolution
  • + Content provenance
  • + Compliance audit

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

react typescript css

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Basic checks · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across listing text only — no source artifact published
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 10, 2026First release of the suite.