v1.0.651 — Sentinel Signal Systems homepage rebrand
Context
sentinelsignal.io read as a healthcare-claims API doc page ("Workflow intelligence for healthcare claims") while Verify had grown into a full agent-trust product family. The parent brand no longer represented what the company builds. This ships a full redesign of the root domain as the Sentinel Signal Systems corporate/product-family homepage, per a detailed user brief, reconciled against what actually exists in the codebase (see "What was found" below).
What was found (didn't match the brief's assumptions)
sentinelsignal.iois a single static file (marketing/site/index.html+styles.css) served by plain nginx — no framework, no build step./portalis not a path — it's a separate subdomain,portal.sentinelsignal.io, served by the existing FastAPIapiservice (app/main.py, templates inapp/ui/*.html). It's already rich and populated: MCP quickstart, full API docs, pricing, governance, blog, status. No portal content needed to be built.- Real pre-existing bug: the old homepage already linked to
sentinelsignal.io/portal/..., but Caddy never routed that path anywhere — the whole primary domain hit the static marketing container, which has no/portalcontent, silently falling through toindex.html. - No SEO metadata, no analytics, no CSP, no robots.txt/sitemap existed anywhere on the root domain.
- No public Verify JSON endpoint exposed the catalog-wide numbers (discovered/endpoints) needed for a homepage proof strip.
- No Playwright or browser-test infrastructure exists in this repo — only pytest content-assertion tests.
What shipped
Marketing site (marketing/site/) — full rewrite, still zero framework/build step:
- New homepage (
index.html): hero (Sentinel Signal Systems / "Signal Before Action." / evidence→decision copy), product family overview (Verify + Healthcare Intelligence cards), "Intelligence before execution" lifecycle (Observe→Understand→Decide→Act→Learn), flagship Verify section (Discover→Verify→Decide→Enforce→Prove) with a proof strip, Healthcare Intelligence section, four platform principles, one-code-example developer section, final CTA. The old MCP quickstart/curl examples/workflow schema list/pricing card are removed from this page — not deleted, that content already lives in full depth at/portal/mcp,/portal/docs-home,/portal/pricing. - Four new pages:
healthcare.html,about.html,security.html,developers.html(flat files, not directories — see below). - Shared header/footer/SEO-meta/SignalLine partials in
_partials/, included via nginx SSI (ssi on;inmarketing/nginx.conf) — the one new mechanism introduced, chosen specifically to avoid adding a frontend framework or build step. _js/site.js: mobile-nav toggle, the Verify proof-strip fetch (graceful degradation — see below), and low-noise analytics event firing.styles.cssrewritten to a dark industrial palette (existing CSS custom-property names kept, values changed), reusing the site's existing fonts (Space Grotesk + IBM Plex Mono already matched the target typography).robots.txtandsitemap.xmladded (root domain had neither).
A real routing bug found and fixed mid-build: initially built /healthcare etc. as healthcare/index.html directories. Live-tested via a local Docker build of the actual marketing nginx image before deploying, and found nginx's automatic trailing-slash redirect for directory URIs echoes its own internal listen port/host in the Location header — not the public-facing one Caddy proxies through, which would have sent visitors to a broken URL in production. Fixed by flattening to sibling .html files (healthcare.html, not healthcare/index.html) with try_files $uri $uri.html /index.html; in nginx.conf — clean URLs with zero redirects.
Verify (verify/src/mcp_verify/) — small, additive, no redesign:
- New public
GET /v1/coverage-summary— wraps the existingbuild_public_coverage_stats()/_get_cached_coverage_stats()(already used by/and/trust-index), no new computation. Scoped CORS (Access-Control-Allow-Origin: https://sentinelsignal.ioonly, never a wildcard) so the homepage can fetch it cross-origin. - New
OPTIONS/CORS handling on the existingPOST /api/analytics/events, same origin scoping, so the homepage can post analytics events to Verify's existing analytics infrastructure rather than standing up a new backend. - Nine new
home_*event names added toAnalyticsEvents/ANALYTICS_EVENT_NAMES(analytics.py). - Minimal cross-branding: Verify's existing site footer ("Sentinel Signal Systems {year}") now links back to
sentinelsignal.io/— no Verify navbar changes.
Deploy (deploy/ionos/Caddyfile): fixes the pre-existing broken-link bug — sentinelsignal.io/portal/* and /status now 301-redirect to https://portal.sentinelsignal.io{uri} (single-hop, path preserved unchanged, since portal routes keep their literal /portal/ prefix on every domain per app/main.py's route registrations).
Not done (explicit scope decisions, resolved with the user before implementation)
- Verify stats: added the new endpoint rather than a static number or omitting it — the safest of the three options since it's a pure wrapper around existing, already-cached logic and the homepage fetch has a 1.5s timeout + silent fallback if it's ever unavailable.
- Portal routing: fixed via Caddy redirect rather than just changing link targets — closes the pre-existing bug and matches the brief's own architecture diagram.
- Test infrastructure: extended the existing pytest content-assertion pattern (
tests/unit/test_product_messaging.py) rather than introducing Playwright. A manual QA pass (device emulation, axe, Lighthouse) is still recommended before/after launch but isn't part of this commit.
Verification
python -m pytest -m unit -q— 202 passed (was 194; net new coverage for the new homepage copy, the four new pages, SEO metadata presence, robots/sitemap, the SSI/nginx config, and the Caddyfile redirect — plus explicit assertions that the removed healthcare-API content is actually gone from the homepage).PYTHONPATH=verify/src:verify/tests python -m pytest verify/tests -q— 823 passed (new tests for/v1/coverage-summary's shape/caching/CORS-origin-scoping and the analytics endpoint's CORS preflight/response behavior).- Local Docker smoke test of the actual
marketingnginx image before deploy: all five pages return 200 with no redirects, zero SSI processing errors,robots.txt/sitemap.xml/styles.css/_js/site.jsall reachable,_partials/blocked (404,internal;), SEO meta/canonical/OG tags render correctly per-page via SSI variables. - Production smoke test after deploy:
GET /200,/healthcare//about//security//developersall 200,sentinelsignal.io/portal/dashboardredirects toportal.sentinelsignal.io/portal/dashboard,/v1/coverage-summaryon Verify returns data (or the homepage degrades gracefully), Verify/API/MCP endpoints unaffected.