{
  "surface": "api",
  "tool": {
    "name": "api-audit",
    "version": "0.1.0"
  },
  "timestamp": "2026-08-21T14:42:41.018Z",
  "baseUrl": "https://api.lughonline.com",
  "evidence": [
    {
      "endpoint": "GET /healthz",
      "method": "GET",
      "path": "/healthz",
      "samples": [
        100.48934199999985,
        101.0913549999998,
        101.54663000000005,
        101.68757099999993,
        100.15525900000011,
        101.20760199999995,
        100.0401740000002,
        101.04005199999983,
        100.97179000000006,
        101.61597100000017,
        99.06044400000019,
        99.77169599999979,
        100.39871399999993,
        100.74714600000016,
        99.54843600000004,
        100.95265399999971,
        100.0218719999998,
        100.90919099999974,
        101.16866399999981,
        100.52390299999979,
        99.80726300000015,
        100.59343600000011,
        99.04519800000025,
        99.73142199999984,
        100.11969499999987,
        99.77701799999977,
        100.18460499999946,
        99.41250899999977,
        100.0393839999997,
        100.52647399999933
      ],
      "ttfb": [
        100.14594499999998,
        100.77513899999985,
        101.34279300000003,
        101.05072300000006,
        99.93386599999985,
        101.05594400000018,
        99.88528099999985,
        100.88257499999963,
        100.73111800000015,
        101.4238720000003,
        98.9143939999999,
        99.63302699999986,
        100.25410599999987,
        100.6090479999998,
        99.40946699999995,
        100.80580299999974,
        99.87534199999982,
        100.77040199999965,
        101.02817199999981,
        100.34480299999996,
        99.651069,
        100.45666100000017,
        98.90253299999995,
        99.58462099999997,
        99.97874300000012,
        99.64077300000008,
        100.04173999999966,
        99.26255399999991,
        99.89510700000028,
        100.38634399999955
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 15
    },
    {
      "endpoint": "GET /api/admin/leads",
      "method": "GET",
      "path": "/api/admin/leads",
      "samples": [
        101.18305099999998,
        100.74579699999958,
        100.8537409999999,
        100.78241799999978,
        101.61210699999992,
        100.55207599999994,
        101.39144699999997,
        100.73714699999982,
        101.03667000000041,
        99.47826999999961,
        101.06344499999977,
        100.71100500000011,
        101.08477700000003,
        100.45988500000021,
        99.72564300000067,
        100.42737600000055,
        101.34717,
        100.63939800000026,
        101.6008410000004,
        99.4555849999997,
        101.05020400000012,
        100.42044699999951,
        100.2737159999997,
        100.51682699999947,
        99.80094499999996,
        101.09495599999991,
        101.24601799999982,
        100.86585000000014,
        102.1781949999995,
        100.41123300000072
      ],
      "ttfb": [
        101.04236000000037,
        100.60476500000004,
        100.68854300000021,
        100.6071350000002,
        101.43498999999974,
        100.41601100000025,
        101.25108600000021,
        100.60283499999969,
        100.896479,
        99.33670700000039,
        100.92203199999949,
        100.53805499999999,
        100.90440500000022,
        100.32164699999976,
        99.59511600000042,
        100.28800599999977,
        101.21020399999998,
        100.499057,
        101.46588800000063,
        99.27165799999966,
        100.91348800000014,
        100.28993100000025,
        100.09501699999964,
        100.37845899999957,
        99.65710899999976,
        100.96055399999932,
        101.10557699999936,
        100.72587899999962,
        101.95740299999943,
        100.273236
      ],
      "status": 401,
      "expectedStatus": 401,
      "bytes": 24
    },
    {
      "endpoint": "GET /api/call/availability",
      "method": "GET",
      "path": "/api/call/availability",
      "samples": [
        100.25856399999975,
        101.18137000000024,
        101.04089100000056,
        101.5787309999996,
        100.65834800000084,
        101.2931410000001,
        101.40472899999986,
        101.1120749999991,
        100.605818,
        101.01290999999947,
        100.56517699999858,
        100.95262999999977,
        101.31379600000037,
        100.89844900000026,
        99.2048219999997,
        101.5248589999992,
        100.3319960000008,
        100.80952500000058,
        100.38025900000139,
        100.6950029999989,
        100.31853600000068,
        100.73042499999974,
        100.76158000000032,
        100.76195299999927,
        99.3890279999996,
        100.70261399999981,
        100.21130599999924,
        100.80855700000029,
        100.7939809999989,
        101.35514499999954
      ],
      "ttfb": [
        100.04646499999944,
        101.05049400000098,
        100.91151700000046,
        101.44574099999954,
        100.48012000000017,
        101.16179399999965,
        101.18982599999981,
        100.91345700000056,
        100.46377500000017,
        100.8752029999996,
        100.3613809999988,
        100.80410600000141,
        101.17282399999931,
        100.76077199999963,
        99.06003400000009,
        101.38491900000008,
        100.17743400000109,
        100.65655500000139,
        100.19140599999992,
        100.5483320000003,
        100.16995300000053,
        100.5510549999999,
        100.61093400000027,
        100.62162200000057,
        99.15718899999956,
        100.55666500000007,
        100.01103499999954,
        100.67665900000065,
        100.65497200000027,
        101.16792300000088
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 61
    },
    {
      "endpoint": "POST /api/audit/start",
      "method": "POST",
      "path": "/api/audit/start",
      "samples": [
        102.16288800000075,
        102.0916699999998,
        101.76858600000014,
        101.7872040000002,
        101.62622899999951,
        101.23009699999966,
        102.22097600000052,
        101.54880199999934,
        102.14228800000092,
        100.86179300000003,
        100.82518799999889,
        101.1595410000009,
        101.39866999999867,
        101.04979399999866,
        101.4626960000005,
        101.18046999999933,
        101.69020799999998,
        99.67877399999998,
        102.1890059999987,
        101.54421899999943,
        101.28520800000115,
        100.17418600000019,
        101.80330900000081,
        100.57146699999976,
        104.8948049999999,
        101.10873399999946,
        101.19599600000038,
        101.57751800000005,
        102.16189700000177,
        101.27463100000023
      ],
      "ttfb": [
        101.99594699999943,
        101.91544600000088,
        101.63545599999998,
        101.6562470000008,
        101.49492199999986,
        101.08088299999872,
        102.08245800000077,
        101.41898600000059,
        102.01347499999974,
        100.7350920000008,
        100.69529200000034,
        101.03113800000028,
        101.23124800000005,
        100.85431099999914,
        101.32007200000044,
        101.05140599999868,
        101.55826900000102,
        99.54643600000054,
        102.05749899999864,
        101.37017699999888,
        101.15215800000078,
        100.04575300000033,
        101.67197099999976,
        100.39809599999899,
        104.71287200000006,
        100.97749699999986,
        101.06928499999958,
        101.40956499999993,
        102.02202600000055,
        101.14335399999982
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 89
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "method": "POST",
      "path": "/api/audit/capture-email",
      "samples": [
        101.73183100000097,
        102.00496100000055,
        101.85991400000057,
        102.3117999999995,
        102.11127099999976,
        101.01274000000012,
        100.62948400000096,
        102.27792399999817,
        102.82728700000007,
        103.05881600000066,
        100.69858799999929,
        102.4447390000023,
        101.74882400000206,
        103.13206299999729,
        102.02838399999746,
        102.86705399999846,
        101.94862400000056,
        102.89219199999934,
        101.48713999999745,
        102.41414300000179,
        101.68872199999896,
        103.45818300000246,
        102.72383400000035,
        104.02194099999906,
        102.0132909999993,
        102.314534000001,
        102.15536400000201,
        102.59690899999987,
        102.56115499999942,
        101.19977799999833
      ],
      "ttfb": [
        101.59293200000138,
        101.84632199999942,
        101.67386400000032,
        102.1806830000005,
        101.98079499999949,
        100.88557899999978,
        100.50088099999994,
        102.14938099999927,
        102.69859400000132,
        102.92444400000022,
        100.52990399999908,
        102.31221000000005,
        101.6202200000007,
        103.00438099999883,
        101.89380099999835,
        102.73683899999742,
        101.82023099999788,
        102.75329399999828,
        101.33737399999882,
        102.27443300000232,
        101.5511860000006,
        103.30886900000041,
        102.58381400000144,
        103.88472499999989,
        101.86464799999885,
        102.13777900000059,
        102.01048599999922,
        102.46789499999795,
        102.4301979999982,
        101.06634699999995
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 34
    },
    {
      "endpoint": "POST /api/call/book",
      "method": "POST",
      "path": "/api/call/book",
      "samples": [
        101.8284530000019,
        100.99394799999936,
        101.94651000000158,
        101.64841299999898,
        102.59270200000174,
        100.16130600000179,
        102.35424299999795,
        101.216633,
        102.89346300000034,
        100.93722300000081,
        101.77539199999956,
        101.70926400000099,
        102.15232000000105,
        100.81772099999944,
        102.60917699999845,
        100.99121399999785,
        102.76455999999962,
        101.25279700000101,
        101.86515700000018,
        100.74711799999932,
        101.85654599999907,
        101.7865810000003,
        101.76097200000004,
        101.15937800000029,
        101.84814199999892,
        102.04012099999818,
        102.48016299999654,
        100.41996599999766,
        101.34687900000063,
        101.06780900000012
      ],
      "ttfb": [
        101.63539300000048,
        100.85124399999768,
        101.76315500000055,
        101.50140199999805,
        102.38317700000334,
        100.03778100000272,
        102.19338100000095,
        101.09275699999853,
        102.76973699999871,
        100.80415300000095,
        101.60590800000136,
        101.58350500000233,
        101.98106299999927,
        100.69230299999981,
        102.4816350000001,
        100.86605599999893,
        102.6374790000009,
        101.12199999999939,
        101.73303899999883,
        100.61713299999974,
        101.7241159999976,
        101.61849799999982,
        101.63097699999707,
        100.98182100000122,
        101.71996999999828,
        101.87419199999931,
        102.35197999999946,
        100.25101199999699,
        101.21890700000222,
        100.94078799999988
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 99
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "method": "POST",
      "path": "/api/reports/{reportId}/retry-platform/{platform}",
      "samples": [
        100.72328199999902,
        104.36916299999939,
        100.73249399999986,
        100.96907099999953,
        102.065419999999,
        101.35129500000039,
        100.50784799999747,
        101.27527900000132,
        100.6338969999997,
        101.05110400000194,
        100.43930399999954,
        101.39233700000113,
        100.76565199999823,
        101.3850560000028,
        100.64087700000164,
        100.81196500000078,
        100.87103299999944,
        101.50586800000019,
        100.52011599999969,
        101.1480389999997,
        100.4559960000006,
        101.38885899999877,
        100.52213800000027,
        101.49892600000021,
        100.75153099999807,
        101.01229500000045,
        100.70869799999855,
        101.27710300000035,
        101.41316700000243,
        101.49003100000118
      ],
      "ttfb": [
        100.58165899999949,
        104.24715999999898,
        100.56423100000029,
        100.78858000000037,
        101.9271719999997,
        101.22670800000196,
        100.32394099999874,
        101.15243499999997,
        100.45241399999941,
        100.92109900000287,
        100.31293399999777,
        101.22753899999952,
        100.63949299999877,
        101.26165100000071,
        100.47514800000135,
        100.68811899999855,
        100.74646600000051,
        101.37844700000278,
        100.39709099999891,
        100.9840320000003,
        100.24992700000075,
        101.22189799999978,
        100.40151599999808,
        101.31844500000079,
        100.61550699999862,
        100.8810369999992,
        100.51909299999897,
        101.06411300000036,
        101.28050799999983,
        101.32232899999872
      ],
      "status": 200,
      "expectedStatus": 200,
      "bytes": 55
    }
  ],
  "audits": [
    {
      "endpoint": "GET /healthz",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.9931714088329782,
      "weight": 3
    },
    {
      "endpoint": "GET /healthz",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.7162021253378068,
      "weight": 1,
      "advice": "GET /healthz: reduce p95 time to first byte (101ms) toward 50ms."
    },
    {
      "endpoint": "GET /healthz",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /healthz",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "cache-headers",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "payload-size",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /healthz",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "GET /healthz",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "GET /healthz",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /healthz",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "GET /healthz",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "GET /healthz: add Strict-Transport-Security."
    },
    {
      "endpoint": "GET /healthz",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.9930762117891385,
      "weight": 3
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.7152558563280947,
      "weight": 1,
      "advice": "GET /api/admin/leads: reduce p95 time to first byte (101ms) toward 50ms."
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "cache-headers",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "payload-size",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "error-envelope",
      "category": "contract",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "GET /api/admin/leads: add Strict-Transport-Security."
    },
    {
      "endpoint": "GET /api/admin/leads",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.9936589134762306,
      "weight": 3
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.715870595918656,
      "weight": 1,
      "advice": "GET /api/call/availability: reduce p95 time to first byte (101ms) toward 50ms."
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "cache-headers",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "payload-size",
      "category": "efficiency",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "GET /api/call/availability: add Strict-Transport-Security."
    },
    {
      "endpoint": "GET /api/call/availability",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.9905211033086112,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.7128069729502942,
      "weight": 1,
      "advice": "POST /api/audit/start: reduce p95 time to first byte (102ms) toward 50ms."
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "cache-headers",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "payload-size",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "POST /api/audit/start: add Strict-Transport-Security."
    },
    {
      "endpoint": "POST /api/audit/start",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.985851631267669,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.7084908467934271,
      "weight": 1,
      "advice": "POST /api/audit/capture-email: reduce p95 time to first byte (103ms) toward 50ms."
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "cache-headers",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "payload-size",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "POST /api/audit/capture-email: add Strict-Transport-Security."
    },
    {
      "endpoint": "POST /api/audit/capture-email",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.9884522331292677,
      "weight": 3
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.7108556803111539,
      "weight": 1,
      "advice": "POST /api/call/book: reduce p95 time to first byte (103ms) toward 50ms."
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "cache-headers",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "payload-size",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "POST /api/call/book: add Strict-Transport-Security."
    },
    {
      "endpoint": "POST /api/call/book",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "latency-p95",
      "category": "performance",
      "score": 0.992194114042859,
      "weight": 3
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "ttfb-p95",
      "category": "performance",
      "score": 0.7143514270820415,
      "weight": 1,
      "advice": "POST /api/reports/{reportId}/retry-platform/{platform}: reduce p95 time to first byte (102ms) toward 50ms."
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "burst-error-rate",
      "category": "reliability",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "burst-degradation",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "rate-limit-grace",
      "category": "reliability",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "compression",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "cache-headers",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "payload-size",
      "category": "efficiency",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "openapi-valid",
      "category": "contract",
      "score": null,
      "weight": 3
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "expected-status",
      "category": "contract",
      "score": 1,
      "weight": 3
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "no-stack-traces",
      "category": "contract",
      "score": 1,
      "weight": 2
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "error-envelope",
      "category": "contract",
      "score": null,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "https",
      "category": "security",
      "score": 1,
      "weight": 1
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "auth-required",
      "category": "security",
      "score": null,
      "weight": 2
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "security-headers",
      "category": "security",
      "score": 0.5,
      "weight": 1,
      "advice": "POST /api/reports/{reportId}/retry-platform/{platform}: add Strict-Transport-Security."
    },
    {
      "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
      "id": "no-powered-by",
      "category": "security",
      "score": 1,
      "weight": 0.5
    }
  ],
  "scores": {
    "overall": 93.3097460074934,
    "categories": {
      "performance": 92.15932268664906,
      "reliability": null,
      "efficiency": 100,
      "contract": 100,
      "security": 80,
      "seo": null,
      "accessibility": null
    },
    "endpoints": [
      {
        "endpoint": "GET /healthz",
        "p50": 100.44402799999989,
        "p95": 101.58476755000012,
        "p99": 101.666807,
        "errorRate": 0,
        "bytes": 15,
        "score": 94.04234334693882
      },
      {
        "endpoint": "GET /api/admin/leads",
        "p50": 100.76410749999968,
        "p95": 101.60703730000014,
        "p99": 102.01402947999962,
        "errorRate": 0,
        "bytes": 24,
        "score": 94.44472063238283
      },
      {
        "endpoint": "GET /api/call/availability",
        "p50": 100.77796699999908,
        "p95": 101.4708004999995,
        "p99": 101.56310811999948,
        "errorRate": 0,
        "bytes": 61,
        "score": 94.05072100998035
      },
      {
        "endpoint": "POST /api/audit/start",
        "p50": 101.50345749999997,
        "p95": 102.2065894999997,
        "p99": 104.11939459000008,
        "errorRate": 0,
        "bytes": 89,
        "score": 92.90756767718372
      },
      {
        "endpoint": "POST /api/audit/capture-email",
        "p50": 102.21664400000009,
        "p95": 103.31142900000013,
        "p99": 103.85845118000005,
        "errorRate": 0,
        "bytes": 34,
        "score": 92.74822383127335
      },
      {
        "endpoint": "POST /api/call/book",
        "p50": 101.7681819999998,
        "p95": 102.6946376499991,
        "p99": 102.85608113000013,
        "errorRate": 0,
        "bytes": 99,
        "score": 92.83662938868657
      },
      {
        "endpoint": "POST /api/reports/{reportId}/retry-platform/{platform}",
        "p50": 100.99068299999999,
        "p95": 101.81362159999954,
        "p99": 103.70107752999928,
        "errorRate": 0,
        "bytes": 55,
        "score": 92.96464147139669
      }
    ]
  }
}
