# IPBot Proxy Verification Design-Partner Interview

Use generalized, de-identified notes only. Do not include customer IP addresses, access logs, API keys, account identifiers, device data, personal data, or confidential customer names. If an example address is necessary, use an IANA documentation range such as `192.0.2.0/24`, `198.51.100.0/24`, or `2001:db8::/32`.

## Decision and owner

- Generalized workflow:
- Decision this evidence informs:
- Action when a controlled proxy exit is detected:
- Action when the system abstains:
- Team or role that owns review:

## Failure cost

- False-positive impact:
- False-negative impact:
- Cost or delay of manual review:
- Reversible fallback:

## Current alternative

- Provider, rules, or internal method used today:
- Useful output from that method:
- Missing or unreliable output:
- Reason to consider a change:

## Independent evidence

- Evidence source independent from IPBot inputs:
- Right or license to use it for evaluation:
- De-identification and aggregation method:
- Observation window and expiry:
- IPv4, IPv6, and relevant network cohorts:
- Known limitations or conflicts:

## Evaluation boundary

- Controlled-proxy-egress question being tested:
- Minimum useful sample (do not attach the sample):
- Success and abstention criteria:
- Human approval required before any external claim:

## Data handling confirmation

- [ ] These notes contain no customer IP addresses or access logs.
- [ ] These notes contain no API keys, account identifiers, device data, or personal data.
- [ ] Any counts are aggregated and rounded.
- [ ] Any example addresses use documentation-only ranges.
- [ ] Evidence rights and retention limits are documented.
