Customer-Directed • Consent-Bound • Registry-Based • Institutionally GovernedSecure URLSigned RecordsBrowser Trust

Institutional Domain Authority & Secure Checkout Infrastructure

Customer-directed inspection, verified checkout authority, and evidence-grade domain governance.

A polished WordPress authority surface for lawful online premise inspections, merchant-origin allow lists, DNS/TLS posture checks, lookup tools, immutable evidence records, support tickets, API/webhook records, and consent-bound checkout approval.

TCBON Institutional Trust Seal

Ledger Core • Settlement Nexus • Authority Node

DNSSECTLSSVTWebAuthn

Taurus Land Lord / Online Premise Inspection Layer

Authority is raised or reduced through recorded posture, consent, and lawful review.

Domain & Merchant Posture

Maintain merchant-origin allow lists, deny lists, DNSSEC posture checks, TLS downgrade detection, WHOIS lookup, reverse IP lookup, reverse host lookup, hostname lookup, blacklist lookup, and certificate evidence.

Open DNS/TLS Checks

Checkout Detection & Approval

Detect iframe checkout surfaces and payment pages through MutationObserver, then require customer-directed authorization, QR fallback, WebAuthn/passkey approval, and short-lived signed approval tokens.

Open Secure Checkout

Evidence Records & Notices

Capture internal records for inspections, notices, summons-style records, penalties, tickets, service notes, reference IDs, digest displays, API traces, and webhook delivery logs.

Open Evidence Records

Consent Boundary

Designed around explicit approval, not invisible action.

Allowed System Behavior

  • Lawful, customer-directed inspections
  • Allow and deny lists for merchant origins
  • DNS/TLS checks and certificate posture records
  • Session-bound delegated authority
  • Merchant-specific approval
  • Optional host permissions only
  • QR and passkey approval fallback
View Lawful Use Policy

Explicitly Not Permitted

  • No invisible unauthorized purchasing
  • No silent credential replay
  • No hidden persistent purchasing authority
  • No unrestricted browser-side execution
  • No checkout finality without backend approval
  • No raw JWT placed into redirect URLs
View Merchant Approval Controls

Pay with Payments Pro

Secure Checkout Authority

Detects checkout context and requests backend-signed session authority. No raw JWT is placed in redirect URLs.

Open Secure Checkout Architecture

Online Admin Desk

Customer Service Center & Immutable Intake/Outtake Desk

Theme UI only. Production checkout authority, JWT verification, SVT issuance, and webhook signing must run on the application server.

Live Inquiry Window

Outer premises can post support inquiries, payment-session references, record hashes, and callback references for administrative review.

Secure Value Token Layer

JWT-authenticated checkout requests are proxied to the backend, bound to merchant, amount, nonce, digest, and callback URL before provider session creation.

JWT RequiredSHA-256 DigestWebhook SignatureMutation Observer

External HTML/JSON Immutable Records

TimeRouteDigestStatus
Server Time/checkout/sessionsha256:pendingAwaiting Backend
Webhook/webhooks/providersignature-requiredVerification Layer

Support Tickets

Ticket Intake

Smaller public-facing ticket view for customers beneath the administrative teller desk.

Open Service Landing Page