Sources & provenance
This site's core promise: you can always answer "where does that claim come from?". Five source documents inform it; only the two public ones are ever quoted.
Source documents
| Key | Document | Status | SHA-256 (recorded 2026-07-19) |
|---|---|---|---|
| S1 | Kindsight Integrations API — Postman collection Distributed to customers for download (per S2, Step 3). The sole source for every endpoint, parameter, body and response example on this site. |
public — quoted verbatim | 7ed4473950cb3a754339dfdc3b804a2bf9aa01f1113c4abc277ab32a85271ba1 |
| S2 | Kindsight Integrations API: Onboarding & Quick Start Guide Customer-facing (distributed via a published-to-web link). Source for OAuth 2.0 configuration values. |
public — quoted verbatim | 1e3ca2c3505e3613d6495b7d81972196280f52e71bb7c15a838c6128d969221b |
| S3 | Internal reference document A Not distributed. Cited by reference key only. |
internal — reference key only | c5ae3eefe6a9cfac9e28383f93d5621f17010c4b69b3f1333557c3e0b0c2c77a |
| S4 | Internal reference document B Not distributed. Cited by reference key only. |
internal — reference key only | c283c7576c6f68c6b3dc2e2075c899d10959f895b479092b0e6b7febbebc9094 |
| S5 | Internal reference document C Not distributed. Cited by reference key only. |
internal — reference key only | 8b3420046293e803e3a799c2f11bdb822851bcb3cc488227845845e0fc4df3d9 |
Hashes let anyone holding a copy of a document verify it is the same file this analysis used — including the internal ones, without their content ever appearing here.
Reference keys (internal citations)
Some conclusions are corroborated by internal documents. Those citations appear as keys with no content. Internal staff can resolve them via the key mapping kept outside this repository; for everyone else the key is an honest marker that says "there is a source, and you can't read it here."
| Key | What it substantiates (public-safe summary) |
|---|---|
| INT-01 | Corroborates that this API version's key elements are individual profiles, screening projects and credit counts. |
| INT-02 | Independently corroborates finding G1: the collection's auth variables were known to be empty/unconfigured. |
| INT-03 | Locates the authoritative OpenAPI specification, which would resolve gaps G3 and likely G4. |
| INT-04 | Documents the rationale for the scores→profiles deprecation and the origin of mostRecentScore. |
The quoting rule, enforced in code
Evidence rows for public sources must carry a verbatim quote;
evidence rows for internal sources cannot — the database model
rejects them at save time (FindingEvidence.clean()), and the test
suite verifies the constraint. Publishing an internal quote here isn't a
policy violation; it's a ValidationError.