cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2
GraphQL introspection enabled at /graphql/api
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3239b60e82175c24cbf72801353469628b77fa1d0
GraphQL introspection enabled at /graphql Types: 4424 (by kind: ENUM: 241, INPUT_OBJECT: 1732, INTERFACE: 27, OBJECT: 2286, SCALAR: 19, UNION: 119) Operations: - Query: Query | fields: claims3QueryClaimantDetails, claims3QueryClaims, claims3QueryClaimsState, claims3QueryRegisterRegularClaimState, workflowsState - Mutation: Mutation | fields: billingStart, claims3MutationRegisterAndAcceptRegularClaim, claims3MutationRegisterRegularClaim, diaryEventInvoke, workflowRun - Subscription: Subscription | fields: claimantDetailsCompleted, claimsCompleted, registerAndAcceptRegularClaimCompleted, registerClaimantDetailsCompleted, registerRegularClaimCompleted Directives: authorize, computed, defer, delegate, deprecated, include, oneOf, skip, source, stream (total: 11)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3239b60e82175c24cfed67e3b437e9cdcb6b7163f
GraphQL introspection enabled at /graphql Types: 4424 (by kind: ENUM: 241, INPUT_OBJECT: 1732, INTERFACE: 27, OBJECT: 2286, SCALAR: 19, UNION: 119) Operations: - Query: Query | fields: accountTransactionTemplate, accountTransactionTemplates, billingInsights, referenceTypes, referenceTypesLastModifiedAt - Mutation: Mutation | fields: createAccountTransactionTemplate, startAdhocBilling, startAdhocRefund, startBilling, updateAccountTransactionTemplate - Subscription: Subscription | fields: claimantDetailsCompleted, claimsCompleted, registerAndAcceptRegularClaimCompleted, registerRegularClaimCompleted, test Directives: authorize, computed, defer, delegate, deprecated, include, oneOf, skip, source, stream (total: 11)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3239b60e82175c24cea7be1c0f52fa35a0a6ebd81
GraphQL introspection enabled at /graphql Types: 4424 (by kind: ENUM: 241, INPUT_OBJECT: 1732, INTERFACE: 27, OBJECT: 2286, SCALAR: 19, UNION: 119) Operations: - Query: Query | fields: issuerProductIdGenerateNext, product, productCalculatePricing, productEvaluateUnderwriting, productPricing - Mutation: Mutation | fields: cloneProductVersion, createProductVersion, metadataMutationMigrate, productMutationRemoveTermsAndConditions, productMutationSetTermsAndConditions - Subscription: Subscription | fields: claimantDetailsCompleted, claimsCompleted, registerAndAcceptRegularClaimCompleted, registerRegularClaimCompleted, test Directives: authorize, computed, defer, delegate, deprecated, include, oneOf, skip, source, stream (total: 11)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3239b60e82175c24c413c3d358b0c69a40afd42d7
GraphQL introspection enabled at /graphql Types: 4424 (by kind: ENUM: 241, INPUT_OBJECT: 1732, INTERFACE: 27, OBJECT: 2286, SCALAR: 19, UNION: 119) Operations: - Query: Query | fields: insuredPersonDetailReports, policiesPricing, policyPricing, policyReferenceGenerationQueryConfig, premiumPercentage - Mutation: Mutation | fields: addPolicyMemberAdditionMovement, addPolicyMemberChangePlanMovement, addPolicyMemberTerminationMovement, addPolicyMemberUpdateInfoMovement, editPolicyMemberAdditionMovement - Subscription: Subscription | fields: claimantDetailsCompleted, claimsCompleted, registerAndAcceptRegularClaimCompleted, registerRegularClaimCompleted, test Directives: authorize, computed, defer, delegate, deprecated, include, oneOf, skip, source, stream (total: 11)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa38a05cfac47c333b074ee5e09d24bb9c8d55f3563
GraphQL introspection enabled at /graphql Types: 4422 (by kind: ENUM: 241, INPUT_OBJECT: 1731, INTERFACE: 27, OBJECT: 2285, SCALAR: 19, UNION: 119) Operations: - Query: Query | fields: insuredPersonDetailReports, policiesPricing, policyPricing, policyReferenceGenerationQueryConfig, premiumPercentage - Mutation: Mutation | fields: addPolicyMemberAdditionMovement, addPolicyMemberChangePlanMovement, addPolicyMemberTerminationMovement, addPolicyMemberUpdateInfoMovement, editPolicyMemberAdditionMovement - Subscription: Subscription | fields: claimantDetailsCompleted, claimsCompleted, registerAndAcceptRegularClaimCompleted, registerRegularClaimCompleted, test Directives: authorize, computed, defer, delegate, deprecated, include, oneOf, skip, source, stream (total: 11)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3141a8af933e7429bbee064f511f6620734b8b91e
GraphQL introspection enabled at /graphql Types: 4337 (by kind: ENUM: 238, INPUT_OBJECT: 1696, INTERFACE: 26, OBJECT: 2239, SCALAR: 19, UNION: 119) Operations: - Query: Query | fields: claimRejectionCodesQuery, claimRejectionReasonsQuery, claimRequestReasonsQuery, gOPLetterReportsQuery, settlementReportsQuery - Mutation: Mutation | fields: claimRejectionReasonMutationBatch, claimRequestReasonMutationBatch, claimRequestReasonMutationCreate, claimRequestReasonMutationDelete, claimRequestReasonMutationUpdate - Subscription: Subscription | fields: claimantDetailsCompleted, claimsCompleted, registerAndAcceptRegularClaimCompleted, registerRegularClaimCompleted, test Directives: authorize, computed, defer, delegate, deprecated, include, oneOf, skip, source, stream (total: 11)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3141a8af933e7429b2a1eed85538dde704c3cb63b
GraphQL introspection enabled at /graphql Types: 4337 (by kind: ENUM: 238, INPUT_OBJECT: 1696, INTERFACE: 26, OBJECT: 2239, SCALAR: 19, UNION: 119) Operations: - Query: Query | fields: referenceTypes, referenceTypesLastModifiedAt, task, tasks, templateStatisticsQuery - Mutation: Mutation | fields: addTaskNoteToTask, createLetter, createTask, markTaskAsComplete, removeDocumentsFromTask - Subscription: Subscription | fields: claimantDetailsCompleted, claimsCompleted, registerAndAcceptRegularClaimCompleted, registerRegularClaimCompleted, test Directives: authorize, computed, defer, delegate, deprecated, include, oneOf, skip, source, stream (total: 11)
Open service 104.26.3.150:443 · api.preprod.ca.covergo.cloud
2026-01-09 07:58
HTTP/1.1 404 Not Found
Date: Fri, 09 Jan 2026 07:58:25 GMT
Content-Length: 0
Connection: close
Server: cloudflare
Cache-Control: no-cache, no-store, must-revalidate
expires: -1
pragma: no-cache
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
referrer-policy: no-referrer
x-xss-protection: 1; mode=block
content-security-policy: default-src 'none';script-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/static/js/middleware.js https://cdnjs.cloudflare.com/ajax/libs/es6-promise/4.1.1/es6-promise.auto.min.js https://cdnjs.cloudflare.com/ajax/libs/fetch/2.0.3/fetch.min.js https://cdnjs.cloudflare.com/ajax/libs/react/16.2.0/umd/react.production.min.js https://cdnjs.cloudflare.com/ajax/libs/react-dom/16.2.0/umd/react-dom.production.min.js https://unpkg.com/subscriptions-transport-ws@0.9.5/browser/client.js https://cdn.jsdelivr.net/react/15.4.2/react.min.js https://cdn.jsdelivr.net/react/15.4.2/react-dom.min.js 'sha256-Gxpjf4M1AL2rbr8HklfQy5Jq23MvhM70WRkOHvkUnhM=' 'sha256-ack9GFEvsegjZzsiBBNPhpuQqa/7O0uPOpqqLryk0yU=' 'sha256-cwGTkITorIXUqHhYWvFFsjAzy9xE1VF2TzuCDkXU2E8=' 'sha256-Tui7QoFlnLXkJCSl1/JvEZdIXTmBttnWNxzJpXomQjg=' 'sha256-tXBBy2ddQE05YnhSpRixXZQBlFGnOa+tBLcTqT3nJ/I=';object-src 'none';style-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/static/css/index.css https://fonts.googleapis.com 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-TAnmuFnPR9h7/BWqle7//h2Li9AQ5DJ/NYVBeghDI8U=' 'sha256-O577/R2yD2COM5KrDiJSrAwRWDqsh2FVrIkpKcLt3b8=' 'sha256-wkAU1AW/h8YFx0XlzvpTllAKnFEO2tw8aKErs5a26LY=';img-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/logo.png https://cdn.jsdelivr.net/npm/graphql-playground-react/build/favicon.png https://www.w3.org/2000/svg data:;font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com;connect-src 'self';base-uri 'none';form-action 'self';frame-ancestors 'self' https://uapix-portal.jtetbwkl.com.hk;worker-src 'self' blob:;block-all-mixed-content
x-covergo-ref: 982a09bed7036cadf52dbca615e38429
x-envoy-upstream-service-time: 7
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=51,cfOrigin;dur=51
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=d9nz0z35G4lN4nJXYuqkONCVxryPR391XlTmxtSVJunHY9m8%2BAcVGei4Ilo2Lm%2BieJE6LBRO4ZgA6oSKqXZWshy14AoehTBr5y9O3XHCWf6%2BTBUUnJYgOg007w%3D%3D"}]}
CF-RAY: 9bb263b299f16a58-EWR
alt-svc: h3=":443"; ma=86400
Open service 104.26.3.150:443 · api.preprod.ca.covergo.cloud
2026-01-02 13:14
HTTP/1.1 404 Not Found
Date: Fri, 02 Jan 2026 13:14:28 GMT
Content-Length: 0
Connection: close
Server: cloudflare
Cache-Control: no-cache, no-store, must-revalidate
expires: -1
pragma: no-cache
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
referrer-policy: no-referrer
x-xss-protection: 1; mode=block
content-security-policy: default-src 'none';script-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/static/js/middleware.js https://cdnjs.cloudflare.com/ajax/libs/es6-promise/4.1.1/es6-promise.auto.min.js https://cdnjs.cloudflare.com/ajax/libs/fetch/2.0.3/fetch.min.js https://cdnjs.cloudflare.com/ajax/libs/react/16.2.0/umd/react.production.min.js https://cdnjs.cloudflare.com/ajax/libs/react-dom/16.2.0/umd/react-dom.production.min.js https://unpkg.com/subscriptions-transport-ws@0.9.5/browser/client.js https://cdn.jsdelivr.net/react/15.4.2/react.min.js https://cdn.jsdelivr.net/react/15.4.2/react-dom.min.js 'sha256-Gxpjf4M1AL2rbr8HklfQy5Jq23MvhM70WRkOHvkUnhM=' 'sha256-ack9GFEvsegjZzsiBBNPhpuQqa/7O0uPOpqqLryk0yU=' 'sha256-cwGTkITorIXUqHhYWvFFsjAzy9xE1VF2TzuCDkXU2E8=' 'sha256-Tui7QoFlnLXkJCSl1/JvEZdIXTmBttnWNxzJpXomQjg=' 'sha256-tXBBy2ddQE05YnhSpRixXZQBlFGnOa+tBLcTqT3nJ/I=';object-src 'none';style-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/static/css/index.css https://fonts.googleapis.com 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-TAnmuFnPR9h7/BWqle7//h2Li9AQ5DJ/NYVBeghDI8U=' 'sha256-O577/R2yD2COM5KrDiJSrAwRWDqsh2FVrIkpKcLt3b8=' 'sha256-wkAU1AW/h8YFx0XlzvpTllAKnFEO2tw8aKErs5a26LY=';img-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/logo.png https://cdn.jsdelivr.net/npm/graphql-playground-react/build/favicon.png https://www.w3.org/2000/svg data:;font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com;connect-src 'self';base-uri 'none';form-action 'self';frame-ancestors 'self' https://uapix-portal.jtetbwkl.com.hk;worker-src 'self' blob:;block-all-mixed-content
x-covergo-ref: 650f14d6849a5fe181072a10151e64f5
x-envoy-upstream-service-time: 7
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=33,cfOrigin;dur=296
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=o7sFjUQOJlVXU2tJTGcQhZyc70QXiU6Ku9BbF%2BQrlGxuuiWlwXLwwZlDDuGIfiPZFhlTH4din8GQnGkG31rtiqY6gUQDiFs37M1MY%2F49OIuLQsMwKZnEboe3SA%3D%3D"}]}
CF-RAY: 9b7a850449d71e55-FRA
alt-svc: h3=":443"; ma=86400
Open service 104.26.3.150:443 · api.preprod.ca.covergo.cloud
2025-12-22 15:29
HTTP/1.1 404 Not Found
Date: Mon, 22 Dec 2025 15:29:47 GMT
Content-Length: 0
Connection: close
Server: cloudflare
Cache-Control: no-cache, no-store, must-revalidate
expires: -1
pragma: no-cache
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
referrer-policy: no-referrer
x-xss-protection: 1; mode=block
content-security-policy: default-src 'none';script-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/static/js/middleware.js https://cdnjs.cloudflare.com/ajax/libs/es6-promise/4.1.1/es6-promise.auto.min.js https://cdnjs.cloudflare.com/ajax/libs/fetch/2.0.3/fetch.min.js https://cdnjs.cloudflare.com/ajax/libs/react/16.2.0/umd/react.production.min.js https://cdnjs.cloudflare.com/ajax/libs/react-dom/16.2.0/umd/react-dom.production.min.js https://unpkg.com/subscriptions-transport-ws@0.9.5/browser/client.js https://cdn.jsdelivr.net/react/15.4.2/react.min.js https://cdn.jsdelivr.net/react/15.4.2/react-dom.min.js 'sha256-Gxpjf4M1AL2rbr8HklfQy5Jq23MvhM70WRkOHvkUnhM=' 'sha256-ack9GFEvsegjZzsiBBNPhpuQqa/7O0uPOpqqLryk0yU=' 'sha256-cwGTkITorIXUqHhYWvFFsjAzy9xE1VF2TzuCDkXU2E8=' 'sha256-Tui7QoFlnLXkJCSl1/JvEZdIXTmBttnWNxzJpXomQjg=' 'sha256-tXBBy2ddQE05YnhSpRixXZQBlFGnOa+tBLcTqT3nJ/I=';object-src 'none';style-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/static/css/index.css https://fonts.googleapis.com 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' 'sha256-TAnmuFnPR9h7/BWqle7//h2Li9AQ5DJ/NYVBeghDI8U=' 'sha256-O577/R2yD2COM5KrDiJSrAwRWDqsh2FVrIkpKcLt3b8=' 'sha256-wkAU1AW/h8YFx0XlzvpTllAKnFEO2tw8aKErs5a26LY=';img-src 'self' https://cdn.jsdelivr.net/npm/graphql-playground-react/build/logo.png https://cdn.jsdelivr.net/npm/graphql-playground-react/build/favicon.png https://www.w3.org/2000/svg data:;font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com;connect-src 'self';base-uri 'none';form-action 'self';frame-ancestors 'self' https://uapix-portal.jtetbwkl.com.hk;worker-src 'self' blob:;block-all-mixed-content
x-covergo-ref: 6c287512fc9d2174897ac4d639cb5d0c
x-envoy-upstream-service-time: 8
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=8,cfOrigin;dur=22
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=fEdqScnI3d4VgcU23G6J1utmxxe9FTTunfkx7qEAjXm6h8YNViRKnapevpjwU1MgW5gK5ltYZFsOc2PPOP%2BKiRP1s66VU6NpkF5T2Moo4dmCMa7rvGyi5084aw%3D%3D"}]}
CF-RAY: 9b20a81fdc2358c1-EWR
alt-svc: h3=":443"; ma=86400
Open service 104.26.3.150:443 · api.preprod.ca.covergo.cloud
2025-12-20 14:42
HTTP/1.1 503 Service Unavailable
Date: Sat, 20 Dec 2025 14:42:55 GMT
Content-Type: text/plain;charset=UTF-8
Content-Length: 89
Connection: close
Server-Timing: cfEdge;dur=21,cfOrigin;dur=0
Vary: accept-encoding
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=qu4jqK%2B0Px3GwxPdeBg6fmvADiplmQGAYZtVgw2qWuFEa2e3OKsVU6dMQ%2BaNwu9Jh%2BEShpVo5d8qOfMtPpN3jLNLVX4%2BusaMVfnzPKEXDLQXHoIGnSuchQRy0Q%3D%3D"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server: cloudflare
CF-RAY: 9b0fe8b909cedb9d-FRA
alt-svc: h3=":443"; ma=86400
Scheduled Shutdown. Environment covergo-cace1-preprod will be available Monday 12 AM UTC.