Public-surface scans
Readiness scans inspect publicly accessible pages and signals
such as robots.txt,
sitemap.xml,
llms.txt, JSON-LD, forms, and API
references.
Arachne observes public business surfaces, extracts capabilities, and maps them into governed agent interfaces where appropriate. The system scans only authorized public surfaces, requires domain verification before write-class workflows, and keeps agent activity auditable through tokens, logs, drift checks, and artifact history.
The default posture is read-only and draft-only until the customer verifies control and explicitly enables stronger capabilities.
Arachne applies governance to capabilities before protocol exposure. The same action retains its risk, confirmation, and audit requirements whether exposed through MCP, browser-native tools, APIs, or another supported interface.
Readiness scans inspect publicly accessible pages and signals
such as robots.txt,
sitemap.xml,
llms.txt, JSON-LD, forms, and API
references.
Arachne does not log into private accounts, defeat paywalls, bypass access controls, or crawl behind authentication unless a customer authorizes a separate integration.
State-changing workflows are compiled as governed actions. They remain draft-only or approval-gated until domain ownership and policy controls are in place.
See how policy, authorization, safe denial, and audit evidence fit the GOVERNED stage of the Agent Journey.
Every production-grade endpoint needs more than a manifest. Arachne adds verification, approval policy, token identity, logging, and change tracking around the generated surface.
Customers prove ownership with a DNS TXT record or a file served
under
/.well-known/arachne-verification.txt.
Verified domains unlock higher-trust workflows.
Hosted actions can require capability tokens, approval gates, expiration, scope limits, and revocation instead of anonymous, unbounded calls.
Usage events, billing quantities, capability-token activity, and approval events are recorded so operators can review what agents touched and when.
Page content is treated as data, not instruction. Evidence maps and risk profiles separate source observations from executable policy.
Rescans compare the live site with the compiled baseline and flag route, tool, selector, confidence, and risk changes before agents depend on stale assumptions.
Compiled artifacts are versioned with Delta-backed snapshots, making it possible to inspect exactly what changed between compiles or drift checks.
Arachne does not sell customer scan data or use customer-submitted website data to train public AI models. Reports, logs, generated artifacts, and hosted endpoint records are used to provide, secure, audit, support, and improve the Arachne service.
Hosted customers can request exported deliverables, endpoint deactivation, token revocation, audit records, or deletion of Arachne-related records by contacting Solstice AI Studio.
Download the manifest, MCP config, evidence map, normalized capabilities, risk profile, reports, and customer README.
Hosted endpoints can be disabled without changing the customer website. Self-hosting remains possible from the exported bundle.
Security, privacy, deletion, and audit-log requests can be sent to [email protected].