{
  "tool": {
    "name": "api-audit",
    "version": "0.1.0"
  },
  "timestamp": "2026-07-29T12:02:21.743Z",
  "baseUrl": "https://api.lughonline.com",
  "evidence": [
    {
      "endpoint": "GET /healthz",
      "method": "GET",
      "path": "/healthz",
      "samples": [
        163.8456759999999,
        164.72028500000033,
        166.41535599999997,
        168.65806199999997,
        166.15070100000003,
        169.21137899999985,
        165.73846000000003,
        163.9927319999997,
        164.5061029999997,
        164.62111800000002,
        165.3781200000003,
        164.12641600000006,
        163.3572780000004,
        170.56527499999993,
        163.95989499999996,
        163.00788199999988,
        164.95241400000032,
        162.69279199999983,
        163.7010710000004,
        164.08277499999986,
        163.72233099999994,
        163.7047279999997,
        165.44490599999972,
        163.42836499999976,
        164.56393099999968,
        166.1168370000005,
        163.59008699999958,
        164.61745799999971,
        164.2143329999999,
        164.2012020000002
      ],
      "ttfb": [
        163.388551,
        164.33575599999995,
        166.1804960000004,
        168.139091,
        165.766212,
        169.04191200000014,
        165.56818199999998,
        163.8343460000001,
        164.27229599999964,
        164.39661799999976,
        165.20487600000024,
        163.9584219999997,
        163.14939800000047,
        170.42292899999939,
        163.79608800000005,
        162.844967,
        164.80128100000002,
        162.53254199999992,
        163.53436800000054,
        163.93569900000057,
        163.5079999999998,
        163.55394499999966,
        165.30556499999966,
        163.27313499999946,
        164.4045130000004,
        165.96023400000013,
        163.43095899999935,
        164.4725959999996,
        163.98574499999995,
        164.0599769999999
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 15
    },
    {
      "endpoint": "GET /api/admin/leads",
      "method": "GET",
      "path": "/api/admin/leads",
      "samples": [
        165.48961899999995,
        166.30975800000033,
        169.43614200000047,
        164.16397799999868,
        164.75813000000016,
        164.56863899999917,
        164.3047630000001,
        164.53694299999916,
        164.31472500000018,
        164.279238000001,
        165.00158799999917,
        164.4769529999994,
        163.11408999999912,
        165.46593399999983,
        165.23794999999882,
        164.31466,
        164.94295799999963,
        164.47198099999878,
        163.84909900000093,
        164.91444500000034,
        164.33303100000012,
        164.39002299999993,
        164.503643,
        164.74279100000058,
        163.95451499999945,
        164.27799400000004,
        164.97524000000158,
        164.11682500000097,
        164.9955030000001,
        164.07386399999996
      ],
      "ttfb": [
        165.3219049999998,
        166.1634439999989,
        169.28286500000104,
        163.9557879999993,
        164.53022299999975,
        164.4233869999989,
        164.15219699999943,
        164.40160999999898,
        164.05497900000046,
        164.08092600000055,
        164.78205699999853,
        164.32954699999937,
        162.95056399999885,
        165.32426900000064,
        165.0971869999994,
        164.17145100000016,
        164.7780299999995,
        164.3168310000001,
        163.6880770000007,
        164.7776990000002,
        164.170798000001,
        164.23061400000006,
        164.33724099999927,
        164.6008150000016,
        163.782772999999,
        164.12324500000068,
        164.81741500000135,
        163.92723000000115,
        164.69834699999956,
        163.94226699999854
      ],
      "status": 401,
      "expectedStatus": 401,
      "bytes": 24
    },
    {
      "endpoint": "GET /api/call/availability",
      "method": "GET",
      "path": "/api/call/availability",
      "samples": [
        165.89031599999907,
        163.9857460000003,
        164.46487500000148,
        163.59455700000035,
        165.44743000000017,
        164.87031399999978,
        164.2608820000005,
        164.22194900000068,
        164.50261200000023,
        165.1934999999994,
        164.83699200000046,
        164.052823,
        164.7659760000006,
        163.65530899999976,
        165.2984319999996,
        164.71192800000063,
        164.23891600000024,
        164.37111300000106,
        164.71435199999905,
        163.57688899999994,
        165.3495449999973,
        163.97527600000103,
        162.84166099999857,
        164.74653600000238,
        164.24977099999887,
        164.5751909999999,
        165.33311999999933,
        163.98213000000032,
        164.04810200000065,
        164.08802999999898
      ],
      "ttfb": [
        165.74010500000077,
        163.83579500000087,
        164.3121289999999,
        163.4418509999996,
        165.30637600000045,
        164.72174500000074,
        164.1128950000002,
        164.06903299999976,
        164.35563700000057,
        165.03624599999966,
        164.64584400000058,
        163.91645699999935,
        164.61669599999914,
        163.46967199999926,
        165.15720799999872,
        164.55605699999978,
        164.09253200000057,
        164.22373700000026,
        164.57528100000127,
        163.44434100000217,
        165.21758699999918,
        163.84532200000103,
        162.69074799999726,
        164.60955000000104,
        164.11599099999876,
        164.41883799999778,
        165.1819770000002,
        163.84181700000045,
        163.91482199999882,
        163.9356450000014
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 61
    },
    {
      "endpoint": "POST /api/audit/start",
      "method": "POST",
      "path": "/api/audit/start",
      "samples": [
        163.8410760000006,
        165.13716900000145,
        163.40232800000013,
        165.63861800000086,
        164.8775969999988,
        163.92707800000062,
        164.61320100000012,
        165.9738240000006,
        164.5402380000014,
        166.4510450000016,
        164.8795680000003,
        168.1398670000017,
        166.21793699999762,
        164.56238499999745,
        164.4854919999998,
        165.2615020000012,
        164.60456799999884,
        165.2648310000004,
        164.77939299999707,
        166.72725900000296,
        164.59580800000185,
        165.9073759999992,
        165.9364289999976,
        165.8161250000012,
        165.05313999999998,
        165.43119600000136,
        166.8583319999998,
        164.2963009999985,
        165.4290890000011,
        167.2523050000018
      ],
      "ttfb": [
        163.65865399999893,
        165.00050399999964,
        163.264991,
        165.48766500000056,
        164.72628299999997,
        163.7962230000012,
        164.44714999999997,
        165.8337619999984,
        164.39124900000024,
        166.29113599999982,
        164.7429520000005,
        168.00440300000264,
        166.08076999999685,
        164.38336999999956,
        164.33582199999728,
        165.03875400000106,
        164.4569620000002,
        165.05069000000003,
        164.6305339999999,
        166.57784900000115,
        164.4592130000019,
        165.7476569999999,
        165.76601999999912,
        165.60526000000027,
        164.80529600000227,
        165.28928000000087,
        166.70247000000018,
        164.1564389999985,
        165.29494700000214,
        167.1011520000029
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 89
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "method": "POST",
      "path": "/api/audit/capture-email",
      "samples": [
        167.6308710000012,
        164.45305999999982,
        168.45413199999894,
        166.18109000000186,
        165.78152000000046,
        165.30579600000056,
        166.994412,
        165.9320289999996,
        166.3062890000001,
        167.25369899999714,
        166.67582499999844,
        166.1418620000004,
        166.8576350000003,
        166.2909099999997,
        166.84833000000071,
        165.90292699999918,
        165.18844700000045,
        164.96568000000116,
        165.66812699999718,
        165.172760999998,
        164.11245300000155,
        165.13054999999804,
        165.5036289999989,
        166.71572799999922,
        166.93994799999928,
        164.96894600000087,
        166.30401600000187,
        165.05476099999942,
        166.14922599999773,
        166.2443009999988
      ],
      "ttfb": [
        167.4803890000003,
        164.30565399999978,
        168.3237279999994,
        166.03205099999832,
        165.62906400000065,
        165.15726799999902,
        166.86659299999883,
        165.785484,
        166.15138899999874,
        167.10951899999782,
        166.48748200000045,
        166.00948300000164,
        166.63184199999887,
        166.14640899999722,
        166.7022560000005,
        165.75878700000249,
        165.04200299999866,
        164.83538600000247,
        165.5173649999997,
        165.02779999999984,
        163.96441600000253,
        164.98003799999788,
        165.35688400000072,
        166.55879500000083,
        166.7942550000007,
        164.818725000001,
        166.10026500000095,
        164.9110720000026,
        165.99928499999805,
        166.09969999999885
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 34
    },
    {
      "endpoint": "POST /api/call/book",
      "method": "POST",
      "path": "/api/call/book",
      "samples": [
        165.62020499999926,
        166.324867000003,
        166.11402299999827,
        164.79711499999758,
        164.05641599999944,
        167.0998010000003,
        164.5474979999999,
        164.0286070000002,
        164.35976499999742,
        165.50848000000042,
        165.21685699999944,
        165.0973309999972,
        164.5953690000024,
        164.2305600000036,
        163.94305000000168,
        165.62024000000383,
        166.1541600000055,
        165.34702500000276,
        164.26258399999642,
        164.89844399999856,
        164.91266100000212,
        164.23801100000128,
        164.31813200000033,
        164.6328149999972,
        164.5697629999995,
        164.82827299999917,
        164.2569119999971,
        166.25126900000032,
        166.01918499999738,
        166.08403700000054
      ],
      "ttfb": [
        165.49066200000016,
        166.1817090000004,
        165.9703640000007,
        164.65498899999875,
        163.91052299999865,
        166.954479,
        164.4044099999992,
        163.88048900000285,
        164.20792099999744,
        165.37732400000095,
        165.07510200000252,
        164.95377200000075,
        164.4486939999988,
        164.10591600000043,
        163.8022770000025,
        165.4855880000032,
        166.01755400000548,
        165.15406300000177,
        164.1372199999969,
        164.7517399999997,
        164.76936299999943,
        164.096626999999,
        164.17278000000078,
        164.49141999999847,
        164.44197300000087,
        164.6264749999973,
        164.10867499999586,
        166.1064069999993,
        165.8712880000021,
        165.92191399999865
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 99
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "method": "POST",
      "path": "/api/reports/{reportId}/retry-platform/{platform}",
      "samples": [
        164.64658800000325,
        163.32355299999472,
        164.32827499999985,
        164.46880800000508,
        163.1026899999997,
        163.87926400000288,
        164.65323299999727,
        164.351588000005,
        163.78038799999922,
        162.41430399999808,
        165.0705039999957,
        163.9937179999979,
        163.99465000000055,
        163.29209399999672,
        163.563854,
        163.89752399999998,
        165.40400900000532,
        163.76978800000506,
        163.9039399999965,
        164.76912100000482,
        165.80253500000254,
        164.76752799999667,
        164.5913270000019,
        166.10895000000164,
        164.5846259999962,
        163.45695400000113,
        166.66397000000143,
        163.67074299999513,
        164.74289200000203,
        163.41509499999665
      ],
      "ttfb": [
        164.50641500000347,
        163.18119599999773,
        164.18214100000478,
        164.34408400000393,
        162.96641399999498,
        163.73903199999768,
        164.50846199999796,
        164.22439000000304,
        163.6341539999994,
        162.22523999999976,
        164.92673500000092,
        163.85797399999865,
        163.84844599999633,
        163.14707199999975,
        163.4321970000019,
        163.7049840000036,
        165.27367600000434,
        163.61355600000388,
        163.7771320000029,
        164.56865500000276,
        165.55438100000174,
        164.62797599999612,
        164.45816800000466,
        165.98154100000102,
        164.45596499999374,
        163.31373500000336,
        166.49324000000342,
        163.4609399999972,
        164.58783199999743,
        163.27246799999557
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 55
    }
  ],
  "audits": [
    {
      "endpoint": "GET /healthz",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.772209965319825,
      "weight": 3,
      "advice": "GET /healthz: reduce p95 latency (169ms) toward 100ms."
    },
    {
      "endpoint": "GET /healthz",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.5107593192984657,
      "weight": 1,
      "advice": "GET /healthz: reduce p95 time to first byte (169ms) toward 50ms."
    },
    {
      "endpoint": "GET /healthz",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /healthz",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "cache-headers",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "payload-size",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /healthz",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "GET /healthz",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "GET /healthz",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "GET /healthz",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "GET /healthz: add X-Content-Type-Options: nosniff and Strict-Transport-Security."
    },
    {
      "endpoint": "GET /healthz",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.7800470941322052,
      "weight": 3,
      "advice": "GET /api/admin/leads: reduce p95 latency (166ms) toward 100ms."
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.5176182250798641,
      "weight": 1,
      "advice": "GET /api/admin/leads: reduce p95 time to first byte (166ms) toward 50ms."
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "cache-headers",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "payload-size",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "error-envelope",
      "category": "contract",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "GET /api/admin/leads: add X-Content-Type-Options: nosniff and Strict-Transport-Security."
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.7814556153375851,
      "weight": 3,
      "advice": "GET /api/call/availability: reduce p95 latency (165ms) toward 100ms."
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.5188809854017263,
      "weight": 1,
      "advice": "GET /api/call/availability: reduce p95 time to first byte (165ms) toward 50ms."
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "cache-headers",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "payload-size",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "GET /api/call/availability: add X-Content-Type-Options: nosniff and Strict-Transport-Security."
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.7770884856245874,
      "weight": 3,
      "advice": "POST /api/audit/start: reduce p95 latency (167ms) toward 100ms."
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.5148702648237284,
      "weight": 1,
      "advice": "POST /api/audit/start: reduce p95 time to first byte (167ms) toward 50ms."
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "cache-headers",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "payload-size",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "POST /api/audit/start: add X-Content-Type-Options: nosniff and Strict-Transport-Security."
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.7760859473002241,
      "weight": 3,
      "advice": "POST /api/audit/capture-email: reduce p95 latency (167ms) toward 100ms."
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.5139269002981087,
      "weight": 1,
      "advice": "POST /api/audit/capture-email: reduce p95 time to first byte (167ms) toward 50ms."
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "cache-headers",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "payload-size",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "POST /api/audit/capture-email: add X-Content-Type-Options: nosniff and Strict-Transport-Security."
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.7791293017751566,
      "weight": 3,
      "advice": "POST /api/call/book: reduce p95 latency (166ms) toward 100ms."
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.5167404427957785,
      "weight": 1,
      "advice": "POST /api/call/book: reduce p95 time to first byte (166ms) toward 50ms."
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "cache-headers",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "payload-size",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "POST /api/call/book: add X-Content-Type-Options: nosniff and Strict-Transport-Security."
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.7799676238051712,
      "weight": 3,
      "advice": "POST /api/reports/{reportId}/retry-platform/{platform}: reduce p95 latency (166ms) toward 100ms."
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.517609720143387,
      "weight": 1,
      "advice": "POST /api/reports/{reportId}/retry-platform/{platform}: reduce p95 time to first byte (166ms) toward 50ms."
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "cache-headers",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "payload-size",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "POST /api/reports/{reportId}/retry-platform/{platform}: add X-Content-Type-Options: nosniff and Strict-Transport-Security."
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    }
  ],
  "scores": {
    "overall": 85.46655083623928,
    "categories": {
      "performance": 71.24413556330474,
      "reliability": null,
      "efficiency": 100,
      "contract": 100,
      "security": 80
    },
    "endpoints": [
      {
        "endpoint": "GET /healthz",
        "p50": 164.3602179999998,
        "p95": 168.96238634999992,
        "p99": 170.17264515999992,
        "errorRate": 0,
        "bytes": 15,
        "score": 87.61029048339216
      },
      {
        "endpoint": "GET /api/admin/leads",
        "p50": 164.4902979999997,
        "p95": 165.94069545000016,
        "p99": 168.52949064000043,
        "errorRate": 0,
        "bytes": 24,
        "score": 88.6742034998378
      },
      {
        "endpoint": "GET /api/call/availability",
        "p50": 164.41799400000127,
        "p95": 165.40338174999889,
        "p99": 165.7618790599994,
        "errorRate": 0,
        "bytes": 61,
        "score": 87.87590986232948
      },
      {
        "endpoint": "POST /api/audit/start",
        "p50": 165.19933550000133,
        "p95": 167.0750171500009,
        "p99": 167.88247402000172,
        "errorRate": 0,
        "bytes": 89,
        "score": 85.61857149302165
      },
      {
        "endpoint": "POST /api/audit/capture-email",
        "p50": 166.14554399999906,
        "p95": 167.4611435999994,
        "p99": 168.2153863099996,
        "errorRate": 0,
        "bytes": 34,
        "score": 85.58421514955461
      },
      {
        "endpoint": "POST /api/call/book",
        "p50": 164.86335849999887,
        "p95": 166.29174790000178,
        "p99": 166.87507014000107,
        "errorRate": 0,
        "bytes": 99,
        "score": 85.68807259235868
      },
      {
        "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
        "p50": 164.1614625000002,
        "p95": 165.97106325000203,
        "p99": 166.5030142000015,
        "errorRate": 0,
        "bytes": 55,
        "score": 85.71750079616436
      }
    ]
  }
}
