Two-phase method / GL-2

Verify the crawler. Then compare the response.

GateLab keeps crawler attribution and response-integrity findings separate so each conclusion stays understandable and appropriately limited.

Interpretation boundary

A visitor class is monitoring evidence, not permission to serve different content. Material response differences require their own observation record.

01 / Phase 1

Attribute crawler identity.

GateLab first recognizes an exact crawler-family claim, then verifies it using provider-controlled evidence such as FCrDNS, published network ranges, an ASN registry, or registered cryptographic credentials. A user-agent match alone remains claimed.

The identity is useful for monitoring and explicit per-site access policy. It must not select a marketing claim, destination, price, or page variant.

02 / Output classes

Broad labels, explicit uncertainty.

01

Verified crawler

The crawler claim is supported by provider-controlled network or cryptographic evidence.

02

Claimed crawler

A known crawler token matched, but independent source verification did not complete.

03

Other automation

The request is automated but does not match a supported named crawler identity.

04

Unknown

Evidence is missing, conflicting, or too weak for a reliable identity.

03 / Phase 2

Compare observable responses.

Authorized investigations collect rate-limited public observations across neutral output classes and times. They compare the final destination, redirect chain, visible meaning, content record, and screenshot structure.

A difference is not automatically wrongdoing. Responsive layouts, localization, experiments, and normal publishing changes can all be legitimate. GateLab surfaces the evidence and reasons so a human can review context.

Key distinction: classification describes traffic evidence; response-integrity findings document what the public server returned.

04 / Evidence standard

Comparable, attributable, exportable.

Every finding links back to timed observations. Risk reasons distinguish redirect, content, visual, and timing differences. An export contains the domain, observation times, destinations, content records, and interpretation boundary.

GateLab does not publish reviewer fingerprints, hidden targeting recipes, or instructions for bypassing detection. The investigation view stays focused on defensive verification.

05 / Safe scope

Public pages and authorized domains only.

Scans do not sign in, submit purchases, bypass access controls, or claim the identity or intent of a visitor. The investigation service requires DNS ownership verification, stores normalized evidence in PostgreSQL, and dispatches captures to an isolated Playwright worker.

The production surface is intentionally limited to crawler identity control and authorized response-integrity investigations. Synthetic teaching classifiers are not exposed as product APIs.