{
  "url": "https://cibnext.icici.bank.in",
  "auditedAt": "2026-07-18T14:52:49.756Z",
  "mode": "report",
  "status": "completed",
  "statusDetail": "The supplied root URL consistently returned a bare HTTP 404 to normal and Chrome clients. The audit therefore judges that reachable error representation; no additional page archetypes could be discovered because it has no links and both robots.txt and sitemap.xml return 404.",
  "page": {
    "appType": "unknown",
    "framework": "none detected",
    "notes": "Static six-element Apache-style 404 response for browser clients. A crawler user agent received a different 200 error document with an incident ID."
  },
  "evidenceUsed": [
    "screenshot",
    "DOM",
    "evaluate probes",
    "layout metrics",
    "performance trace",
    "HAR",
    "discoverability browser/crawler comparison",
    "headers via CDP and curl",
    "cookies",
    "trackers",
    "secrets scan",
    "images audit",
    "heap summary",
    "Lighthouse attempted (aborted on HTTP 404)",
    "Modern Web Guidance 0.0.172 search/retrieve"
  ],
  "guidanceConsulted": [
    "accessibility",
    "accessible-error-announcement",
    "language-detection",
    "language-model",
    "summarizer",
    "translator",
    "css",
    "highlight-text-ranges",
    "css-layout",
    "animated-select-picker",
    "autofill-address-form",
    "autofill-highlight-inputs",
    "autofill-payment-form",
    "autofill-sign-in-form",
    "autofill-sign-up-form",
    "brand-consistent-forms",
    "branded-select-styling",
    "custom-select-picker-layouts",
    "form-fields-automatically-fit-contents",
    "forms",
    "required-field-feedback",
    "rich-media-picker",
    "select-menu-interaction",
    "validate-input-after-interaction",
    "html",
    "passkey-authentication",
    "passkey-conditional-create",
    "passkey-management",
    "passkey-reauthentication",
    "passkey-registration",
    "passkeys",
    "batch-analytics-events",
    "break-up-long-tasks",
    "calculate-total-foreground-time",
    "conditional-async-dependencies",
    "defer-rendering-heavy-content",
    "defer-work-until-scroll-ends",
    "deprioritize-background-fetches",
    "detect-initial-visibility-state",
    "efficient-background-processing",
    "faster-spa-view-transitions",
    "full-session-analytics",
    "identify-heavy-scripts",
    "identify-inp-causes",
    "improve-next-page-load-performance",
    "interactions-in-complex-layouts",
    "optimize-image-priority",
    "optimize-preload-priority",
    "optimize-script-priority",
    "performance",
    "resolution-optimized-pseudo-elements",
    "schedule-tasks-by-priority",
    "sequence-distributed-events",
    "privacy",
    "security",
    "adapt-scrollbar-to-contrast-preferences",
    "anchor-positioning-tab-underline",
    "animate-element-entry-exit",
    "animate-to-from-top-layer",
    "animate-to-intrinsic-sizes",
    "apply-webgl-shaders",
    "calculate-event-differentials",
    "calculate-with-intrinsic-sizes",
    "capture-location-agnostic-data",
    "carousel-slide-effects",
    "carousel-snap-highlights",
    "child-state-based-styling",
    "complex-shapes",
    "component-specific-light-dark-theme",
    "consistent-cross-document-transitions",
    "content-based-styling",
    "coordinate-global-events",
    "cross-document-transitions",
    "customize-scrollbar-color-and-thickness",
    "dark-mode",
    "declarative-button-actions",
    "declarative-dialog-popover-control",
    "deliver-optimized-decorative-images",
    "design-token-reactivity",
    "directional-navigation-transitions",
    "dynamic-sibling-animations",
    "dynamic-sibling-styling",
    "export-html-media-from-canvas",
    "expose-canvas-content-to-browser-features",
    "flicker-free-client-side-ab-testing",
    "fluid-scaling",
    "format-human-readable-durations",
    "group-element-transitions",
    "improve-text-layout-and-legibility",
    "individual-transform-properties",
    "interactive-content-in-3d-scenes",
    "interactive-content-reveal",
    "interest-triggered-action-previews",
    "interest-triggered-tooltips",
    "light-dismiss-a-dialog",
    "manage-recurring-intervals",
    "model-partial-time-concepts",
    "move-dom-element-without-losing-state",
    "navigation-drawer",
    "overflow-clipping-control",
    "parallax-scroll-effects",
    "persistent-app-tours",
    "persistent-toast-notifications",
    "persistent-top-layer-ui",
    "physics-based-easing",
    "platform-controls-dismiss-dialog",
    "position-aware-tooltips",
    "precise-text-alignment",
    "prevent-text-wrapping",
    "pull-to-reveal",
    "reduce-style-repetition",
    "resilient-context-menus-and-nested-dropdowns",
    "same-document-transitions",
    "scroll-entry-exit-effects",
    "scroll-position-aware-elements",
    "scroll-progress-indicator",
    "scroll-snap-realtime-feedback",
    "scroll-snap-state-sync",
    "scroll-target-on-load",
    "scrollability-affordance-hints",
    "scrollytelling",
    "search-hidden-content",
    "shaped-cutouts",
    "shrinking-header-on-scroll",
    "size-aware-styling",
    "soft-edge-content-fade",
    "stabilize-reactive-state",
    "stack-drill-down",
    "style-parent-with-has",
    "support-global-calendar-systems",
    "swipe-to-remove",
    "visually-stable-font-fallbacks",
    "visually-stable-mixed-fonts",
    "visually-texture-content",
    "agentic-forms",
    "agentic-javascript-tools",
    "webmcp"
  ],
  "artifacts": [
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Audit evidence: cookies.json",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Audit evidence: dark.png",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F004"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Audit evidence: desktop.png",
      "findingIds": [
        "F001",
        "F003",
        "F015",
        "F004",
        "F012",
        "F014"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "Audit evidence: discoverability-crawler.png",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Audit evidence: discoverability-rendered.png",
      "findingIds": []
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "Audit evidence: discoverability.json",
      "findingIds": []
    },
    {
      "type": "dom",
      "path": "evidence/dom.json",
      "caption": "Audit evidence: dom.json",
      "findingIds": [
        "F002",
        "F003",
        "F015",
        "F007",
        "F008",
        "F014"
      ]
    },
    {
      "type": "other",
      "path": "evidence/guidance-list.json",
      "caption": "Pinned Modern Web Guidance catalog material consulted before judgement.",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/guidance-retrieved.md",
      "caption": "Pinned Modern Web Guidance catalog material consulted before judgement.",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/guidance-searches.json",
      "caption": "Pinned Modern Web Guidance catalog material consulted before judgement.",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Audit evidence: headers.json",
      "findingIds": [
        "F010",
        "F011"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap.json",
      "caption": "Audit evidence: heap.json",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/high-contrast.png",
      "caption": "Audit evidence: high-contrast.png",
      "condition": "forced-colors: active; prefers-contrast: more",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/http-chrome-body.html",
      "caption": "Audit evidence: http-chrome-body.html",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/http-crawler-body.html",
      "caption": "Audit evidence: http-crawler-body.html",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/http-default-body.html",
      "caption": "Audit evidence: http-default-body.html",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/http-variants.txt",
      "caption": "Audit evidence: http-variants.txt",
      "findingIds": [
        "F009",
        "F010",
        "F011"
      ]
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Audit evidence: images.json",
      "findingIds": []
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "Audit evidence: layout-mobile.json",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F005",
        "F006"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Audit evidence: lighthouse.json",
      "findingIds": [
        "F012"
      ]
    },
    {
      "type": "trace-summary",
      "path": "evidence/load-trace-summary.json",
      "caption": "Audit evidence: load-trace-summary.json",
      "findingIds": []
    },
    {
      "type": "trace",
      "path": "evidence/load-trace.json",
      "caption": "Audit evidence: load-trace.json",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Audit evidence: mobile.png",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F005",
        "F006"
      ]
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "Audit evidence: network-summary.json",
      "findingIds": [
        "F001",
        "F002",
        "F009",
        "F012"
      ]
    },
    {
      "type": "har",
      "path": "evidence/network.har",
      "caption": "Audit evidence: network.har",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "Audit evidence: probe.json",
      "findingIds": [
        "F013"
      ]
    },
    {
      "type": "other",
      "path": "evidence/quality-probe.json",
      "caption": "Audit evidence: quality-probe.json",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/routes-probe.json",
      "caption": "Audit evidence: routes-probe.json",
      "findingIds": [
        "F008",
        "F009"
      ]
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Audit evidence: secrets.json",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Audit evidence: trackers.json",
      "findingIds": []
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 58,
    "blocked": 0,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": true
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "Dark-mode screenshot is pixel-equivalent in presentation to the light screenshot: white canvas and black text, with no color-scheme declaration or authored CSS.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/dark.png",
        "evidence/desktop.png"
      ],
      "findingIds": [
        "F004"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Reduced-motion emulation matched true and document.getAnimations() returned an empty array; no non-essential or auto-advancing motion exists.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Forced-colors/prefers-contrast screenshot keeps the black heading and body text clearly visible on the white system background.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The rendered response is a static server error with no state or route change to transition.",
      "reason": "The rendered response is a static server error with no state or route change to transition."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "DOM and quality probes found no scripts, scroll handlers, CSS, or scroll-linked motion, so the response does not implement the main-thread scroll-listener anti-pattern.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "DOM and quality probes found no pointer handlers, gesture controls, or custom scrolling code that fights platform behavior.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The short error document has no scrolling chrome or navigable content surface.",
      "reason": "The short error document has no scrolling chrome or navigable content surface."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "There are no tooltips, popovers, or menus in the rendered DOM.",
      "reason": "There are no tooltips, popovers, or menus in the rendered DOM."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "The error state contains no link, focus target, navigation cue, or directional transition to guide the user toward a safe next step.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F015"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Desktop screenshot and DOM show only one heading and paragraph, with no overlay, banner, or interstitial.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "There are no overlays, disclosures, selects, or rich controls to implement.",
      "reason": "There are no overlays, disclosures, selects, or rich controls to implement."
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Desktop screenshot shows no application frame, borders, navigation chrome, or decorative clutter around the message.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "At a requested 360x800 mobile viewport, layout reports hasViewportMeta=false and an effective 980 CSS-pixel layout viewport, so the page is desktop-scaled instead of adapting.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json"
      ],
      "findingIds": [
        "F005"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The response has no reusable UI component rendered in multiple container sizes.",
      "reason": "The response has no reusable UI component rendered in multiple container sizes."
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The DOM contains zero links, buttons, or form controls, so there is no input target to test.",
      "reason": "The DOM contains zero links, buttons, or form controls, so there is no input target to test."
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "The target root responds 404 and renders only “Not Found”; it does not identify ICICI Corporate Internet Banking or offer a next action.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F001"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "The intended banking entry journey cannot begin: the root document is HTTP 404 and contains zero links, controls, and forms.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/dom.json",
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F002"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "The error message has no home link, retry, support route, incident reference for browser users, or other recovery control.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F003"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Trace measured LCP 1585.98 ms, CLS 0, and total blocking time 0 ms on the rendered error response.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Mobile layout observer recorded CLS 0 with no layout-shift entries.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Trace and layout observers recorded zero long tasks and 0 ms total blocking time; the page ships no scripts.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "HAR summary shows only two first-party requests, 6,582 transferred bytes, no redirects, no render-blocking candidates, and no missing-cache signal.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "DOM probe found no scripts or authored CSS; HAR contains only the document and favicon, so no unused or duplicate bundle is shipped.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The document contains no images, form fields, controls, canvas, or other name/role targets.",
      "reason": "The document contains no images, form fields, controls, canvas, or other name/role targets."
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Computed styles are black text on the browser white canvas and the forced-colors screenshot remains legible.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "The simple document has one H1 followed by one paragraph, no skipped heading levels, and no focusable controls whose order or focus style could fail.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Screenshots show unclipped 32 px heading and 16 px paragraph text; mobile layout reports no horizontal overflow in its effective layout viewport.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "No viewport meta is present; Chrome uses a 980 CSS-pixel mobile layout viewport at a 360-pixel device viewport, preventing normal mobile reflow.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json"
      ],
      "findingIds": [
        "F006"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "The response contains no scripts or event-driven runtime; repeated DOM/evaluate loads completed without an uncaught page exception.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "DOM confirms an HTML doctype and declared HTTP character encoding; there are no images, scripts, or authored CSS assets to misuse.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "No scripts, paste handlers, permission prompts, libraries, or source-map-dependent assets are present in the response.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "Title is generic “404 Not Found” and meta[name=description] is absent.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/dom.json"
      ],
      "findingIds": [
        "F007"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "The document has no anchors, no viewport meta, and /robots.txt returns 404, leaving no crawlable route or mobile-friendly signal.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/dom.json",
        "evidence/routes-probe.json"
      ],
      "findingIds": [
        "F008"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "HAR and curl record HTTP 404 for normal/browser clients; canonical, robots meta, sitemap, and hreflang are absent, and /sitemap.xml also returns 404.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/http-variants.txt",
        "evidence/routes-probe.json"
      ],
      "findingIds": [
        "F009"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "This is an HTTP error representation, not an article, product, event, place, or rich entity.",
      "reason": "This is an HTTP error representation, not an article, product, event, place, or rich entity."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "Direct response is HTTPS with HSTS and X-Frame-Options, but no Content-Security-Policy or X-Content-Type-Options is present.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/http-variants.txt",
        "evidence/headers.json"
      ],
      "findingIds": [
        "F010"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "HAR and tracker probes found zero third-party requests, zero known trackers, zero cookies, and the secrets scan found no exposed credential.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The rendered response exposes no authentication UI and requests no browser permissions; the intended flow is unavailable at this URL.",
      "reason": "The rendered response exposes no authentication UI and requests no browser permissions; the intended flow is unavailable at this URL."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "Direct response has HSTS and X-Frame-Options: SAMEORIGIN, but lacks CSP/frame-ancestors, Referrer-Policy, Permissions-Policy, and X-Content-Type-Options.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/http-variants.txt",
        "evidence/headers.json"
      ],
      "findingIds": [
        "F011"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "The browser response is complete static HTML with no scripts; its heading and message render without JavaScript.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "There are no overlays, async dependencies, background tasks, or runtime state in the static error document.",
      "reason": "There are no overlays, async dependencies, background tasks, or runtime state in the static error document."
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "A bank login is intrinsically online and the rendered response is not an app surface; offline/installability is not a reasonable requirement for this error page.",
      "reason": "A bank login is intrinsically online and the rendered response is not an app surface; offline/installability is not a reasonable requirement for this error page."
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "The HTTP 404 state is a generic server page with no useful recovery option; Lighthouse also aborts with ERRORED_DOCUMENT_REQUEST.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/lighthouse.json",
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F012"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "DOM probe reports html.lang and html.dir as empty, so assistive technology and language-sensitive rendering cannot identify the content language or direction.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F013"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "No dates, numbers, currencies, durations, or calendar data are rendered.",
      "reason": "No dates, numbers, currencies, durations, or calendar data are rendered."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "No time or event data is rendered.",
      "reason": "No time or event data is rendered."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "The screenshot and DOM contain no consent, pricing, advertising, cancellation, upsell, or deceptive choice UI.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "There is no form or editable field on which to exercise validation.",
      "reason": "There is no form or editable field on which to exercise validation."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "There are no input fields in the response.",
      "reason": "There are no input fields in the response."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "issues",
      "confidence": "high",
      "method": "Rendered-state inspection corroborated by the named CDP/network artifact.",
      "evidence": "A corporate banking entry URL exposes no authentication or account flow at all because the root returns 404; users cannot verify, enter, cancel, or recover the sensitive journey.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json"
      ],
      "findingIds": [
        "F014"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The response contains no images, video, audio, fonts, or decorative assets.",
      "reason": "The response contains no images, video, audio, fonts, or decorative assets."
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Trace reports zero long tasks and HAR reports only two requests totaling 6,582 bytes, with no background fetch or script.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Tracker/HAR probes found zero third-party bytes and DOM found no fonts, audio, video, animation, or autoplay media.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "No usable banking capability is exposed at the target URL; adding an agent action to a bare error response would be inappropriate.",
      "reason": "No usable banking capability is exposed at the target URL; adding an agent action to a bare error response would be inappropriate."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The error response has no inference use case where on-device AI would improve the experience.",
      "reason": "The error response has no inference use case where on-device AI would improve the experience."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "not-applicable",
      "confidence": "high",
      "method": "DOM and page-archetype applicability inspection.",
      "evidence": "The static response has no representative interaction to repeat; fabricating one would not test a real user journey.",
      "reason": "The static response has no representative interaction to repeat; fabricating one would not test a real user journey."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "Heap summary is 752,292 self-size bytes; the live DOM has six elements and performance.memory reports about 1.06 MB used JS heap, proportionate to the tiny response.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "high",
      "method": "Direct DOM, screenshot, layout, trace, HAR, security, or heap evidence as stated.",
      "evidence": "The document ships no scripts and has six live elements; the heap constructor summary contains no Detached* population, with no app code able to add listeners or timers.",
      "pathIds": [
        "root"
      ],
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json",
        "evidence/probe.json"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F004"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F015"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F005"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F001",
        "F002",
        "F003"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F006"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F007",
        "F008",
        "F009"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F010",
        "F011"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F012"
      ]
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F013"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F014"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "Every defined check is genuinely inapplicable to the static, non-interactive HTTP error representation; each check outcome records its specific rationale."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "pass"
    }
  ],
  "paths": [
    {
      "id": "root",
      "description": "Supplied entry URL and intended primary corporate-banking entry journey. It represents the only browser-visible template because the response contains no links or controls.",
      "url": "https://cibnext.icici.bank.in/",
      "conditions": [
        "desktop",
        "viewport: 360x800",
        "prefers-color-scheme: dark",
        "prefers-reduced-motion: reduce",
        "forced-colors: active / prefers-contrast: more"
      ],
      "result": "issues"
    },
    {
      "id": "crawler",
      "description": "Raw/crawler representation comparison to test indexing and no-JavaScript visibility.",
      "url": "https://cibnext.icici.bank.in/",
      "conditions": [
        "web-uplift crawler user agent",
        "JavaScript disabled"
      ],
      "result": "issues"
    },
    {
      "id": "discovery",
      "description": "Route discovery via DOM links, /robots.txt, and /sitemap.xml. No additional archetype was discoverable.",
      "url": "https://cibnext.icici.bank.in/",
      "conditions": [
        "normal browser user agent"
      ],
      "result": "issues"
    }
  ],
  "findings": [
    {
      "id": "F001",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "critical",
      "confidence": "high",
      "principleId": "support-core-task-success",
      "principleCheckId": "clear-purpose-and-primary-action",
      "guidanceId": "html",
      "summary": "The public entrypoint does not communicate the banking service or a next action.",
      "evidence": "The target root responds 404 and renders only “Not Found”; it does not identify ICICI Corporate Internet Banking or offer a next action.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Restore the intended entry route. If this URL is obsolete, redirect it to the supported corporate banking sign-in or a branded route-selection page.",
      "effort": "large"
    },
    {
      "id": "F002",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "critical",
      "confidence": "high",
      "principleId": "support-core-task-success",
      "principleCheckId": "primary-flow-completion",
      "guidanceId": "forms",
      "summary": "The primary banking journey cannot start because the root is an HTTP 404 with no controls.",
      "evidence": "The intended banking entry journey cannot begin: the root document is HTTP 404 and contains zero links, controls, and forms.",
      "artifacts": [
        "evidence/dom.json",
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Serve the supported sign-in/registration journey at this entrypoint or issue a permanent redirect to it, then test the full path end to end.",
      "effort": "large"
    },
    {
      "id": "F003",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "high",
      "confidence": "high",
      "principleId": "support-core-task-success",
      "principleCheckId": "clear-system-state-and-recovery",
      "guidanceId": "persistent-toast-notifications",
      "summary": "The 404 state gives users no way to recover.",
      "evidence": "The error message has no home link, retry, support route, incident reference for browser users, or other recovery control.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json"
      ],
      "suggestedFix": "Replace the generic server error with a branded error state that offers safe links to home/sign-in, retry, and support, preserving context without exposing sensitive detail.",
      "effort": "large"
    },
    {
      "id": "F004",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "medium",
      "confidence": "high",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "summary": "The error surface ignores the user’s dark color preference.",
      "evidence": "Dark-mode screenshot is pixel-equivalent in presentation to the light screenshot: white canvas and black text, with no color-scheme declaration or authored CSS.",
      "artifacts": [
        "evidence/dark.png",
        "evidence/desktop.png"
      ],
      "suggestedFix": "Declare color-scheme: light dark and use system colors or light-dark() for the error-page surface and text.",
      "effort": "small"
    },
    {
      "id": "F005",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "high",
      "confidence": "high",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "responsive-no-horizontal-scroll",
      "guidanceId": "fluid-scaling",
      "summary": "The mobile response uses a desktop-sized 980 CSS-pixel layout viewport.",
      "evidence": "At a requested 360x800 mobile viewport, layout reports hasViewportMeta=false and an effective 980 CSS-pixel layout viewport, so the page is desktop-scaled instead of adapting.",
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json"
      ],
      "suggestedFix": "Add <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> and verify the restored page reflows at narrow widths without preventing zoom.",
      "effort": "large"
    },
    {
      "id": "F006",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "accessibility",
      "summary": "Missing viewport configuration undermines expected mobile reflow and zoom behavior.",
      "evidence": "No viewport meta is present; Chrome uses a 980 CSS-pixel mobile layout viewport at a 360-pixel device viewport, preventing normal mobile reflow.",
      "artifacts": [
        "evidence/mobile.png",
        "evidence/layout-mobile.json"
      ],
      "suggestedFix": "Add the standard width=device-width viewport declaration without maximum-scale or user-scalable restrictions, then test at 320–400 CSS pixels and browser zoom.",
      "effort": "small"
    },
    {
      "id": "F007",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-discoverable",
      "principleCheckId": "title-and-description",
      "guidanceId": "html",
      "summary": "The error page has generic title metadata and no description.",
      "evidence": "Title is generic “404 Not Found” and meta[name=description] is absent.",
      "artifacts": [
        "evidence/dom.json"
      ],
      "suggestedFix": "Give the branded recovery page a specific title and concise meta description; ensure real service pages each have unique metadata.",
      "effort": "large"
    },
    {
      "id": "F008",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-discoverable",
      "principleCheckId": "crawlable-and-mobile-friendly",
      "guidanceId": "html",
      "summary": "There is no crawlable onward route, viewport meta, or robots resource.",
      "evidence": "The document has no anchors, no viewport meta, and /robots.txt returns 404, leaving no crawlable route or mobile-friendly signal.",
      "artifacts": [
        "evidence/dom.json",
        "evidence/routes-probe.json"
      ],
      "suggestedFix": "Expose real href links to supported public routes, add viewport metadata, and serve an intentional robots.txt policy.",
      "effort": "large"
    },
    {
      "id": "F009",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-discoverable",
      "principleCheckId": "canonical-and-indexing-signals",
      "guidanceId": "html",
      "summary": "Normal clients receive 404 while the crawler user agent receives a different HTTP 200 error document.",
      "evidence": "HAR and curl record HTTP 404 for normal/browser clients; canonical, robots meta, sitemap, and hreflang are absent, and /sitemap.xml also returns 404.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/http-variants.txt",
        "evidence/routes-probe.json"
      ],
      "suggestedFix": "Restore or redirect the canonical entry URL, serve consistent status/content across user agents, publish canonical/indexing signals on public pages, and add a sitemap where appropriate.",
      "effort": "large"
    },
    {
      "id": "F010",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "summary": "The response lacks CSP and nosniff despite otherwise using HTTPS, HSTS, and SAMEORIGIN framing protection.",
      "evidence": "Direct response is HTTPS with HSTS and X-Frame-Options, but no Content-Security-Policy or X-Content-Type-Options is present.",
      "artifacts": [
        "evidence/http-variants.txt",
        "evidence/headers.json"
      ],
      "suggestedFix": "Add a restrictive Content-Security-Policy suitable for the banking app and X-Content-Type-Options: nosniff; retain and verify HSTS and clickjacking protection.",
      "effort": "medium"
    },
    {
      "id": "F011",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "summary": "Several browser-enforced policy headers are absent.",
      "evidence": "Direct response has HSTS and X-Frame-Options: SAMEORIGIN, but lacks CSP/frame-ancestors, Referrer-Policy, Permissions-Policy, and X-Content-Type-Options.",
      "artifacts": [
        "evidence/http-variants.txt",
        "evidence/headers.json"
      ],
      "suggestedFix": "Define least-privilege Referrer-Policy and Permissions-Policy, express clickjacking protection in CSP frame-ancestors, and adopt Trusted Types/origin isolation where the restored app’s threat model warrants them.",
      "effort": "medium"
    },
    {
      "id": "F012",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-resilient",
      "principleCheckId": "network-and-http-failure-states",
      "guidanceId": "persistent-toast-notifications",
      "summary": "The server failure state is a dead end rather than an intentional recovery experience.",
      "evidence": "The HTTP 404 state is a generic server page with no useful recovery option; Lighthouse also aborts with ERRORED_DOCUMENT_REQUEST.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/lighthouse.json",
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Handle unknown routes and upstream failures with a stable branded page, correct status, safe retry/support actions, and no infinite loading or misleading success.",
      "effort": "large"
    },
    {
      "id": "F013",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-internationalised",
      "principleCheckId": "lang-dir-and-logical-properties",
      "guidanceId": "translator",
      "summary": "The document omits language and direction metadata.",
      "evidence": "DOM probe reports html.lang and html.dir as empty, so assistive technology and language-sensitive rendering cannot identify the content language or direction.",
      "artifacts": [
        "evidence/probe.json"
      ],
      "suggestedFix": "Set an accurate html lang value and dir where needed; use logical CSS properties when rebuilding the branded response.",
      "effort": "small"
    },
    {
      "id": "F014",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "critical",
      "confidence": "high",
      "principleId": "be-trustworthy",
      "principleCheckId": "safe-commercial-and-account-flows",
      "guidanceId": "passkey-authentication",
      "summary": "A sensitive banking flow is wholly unavailable at the supplied entry URL.",
      "evidence": "A corporate banking entry URL exposes no authentication or account flow at all because the root returns 404; users cannot verify, enter, cancel, or recover the sensitive journey.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json"
      ],
      "suggestedFix": "Restore the supported account entry journey, make its destination and security context unambiguous, and verify cancellation, support, reauthentication, autocomplete, and passkey behavior on the real flow.",
      "effort": "large"
    },
    {
      "id": "F015",
      "pathId": "root",
      "url": "https://cibnext.icici.bank.in",
      "severity": "high",
      "confidence": "high",
      "principleId": "provide-guided-navigation",
      "principleCheckId": "directs-attention",
      "guidanceId": "html",
      "summary": "The bare error page provides no navigational cue or onward focus target.",
      "evidence": "The error state contains no link, focus target, navigation cue, or directional transition to guide the user toward a safe next step.",
      "artifacts": [
        "evidence/desktop.png",
        "evidence/dom.json"
      ],
      "suggestedFix": "Add clear, real href links to the supported sign-in, home, and support destinations, with visual hierarchy that makes the safest next step obvious.",
      "effort": "large"
    }
  ],
  "taskList": [
    {
      "id": "T001",
      "title": "Restore or correctly redirect the corporate banking entry journey",
      "priority": 1,
      "findingIds": [
        "F001",
        "F002",
        "F009",
        "F014"
      ],
      "guidanceId": "forms",
      "status": "open"
    },
    {
      "id": "T002",
      "title": "Build an intentional branded and recoverable HTTP error experience",
      "priority": 2,
      "findingIds": [
        "F003",
        "F012",
        "F015"
      ],
      "guidanceId": "persistent-toast-notifications",
      "status": "open"
    },
    {
      "id": "T003",
      "title": "Harden response security policies",
      "priority": 3,
      "findingIds": [
        "F010",
        "F011"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T004",
      "title": "Add mobile viewport, reflow, and zoom-safe behavior",
      "priority": 4,
      "findingIds": [
        "F005",
        "F006"
      ],
      "guidanceId": "fluid-scaling",
      "status": "open"
    },
    {
      "id": "T005",
      "title": "Make indexing status and metadata consistent across clients",
      "priority": 5,
      "findingIds": [
        "F007",
        "F008",
        "F009"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T006",
      "title": "Respect color scheme and declare document language",
      "priority": 6,
      "findingIds": [
        "F004",
        "F013"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 3,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-18T14-52-49-756Z"
}
