# Network and CSP

This page lists every host the collector contacts in each mode, and the Content Security Policy entries that allow them. Every host is run by you or by Octet.

## Hosts by mode

| Destination | Protocol | `full` | `lite` | `passive` |
|---|---|---|---|---|
| Your edge, for example `octet.example.com` | HTTPS POST to `/v1/signals` | Yes | Yes | Yes |
| Your edge | WebSocket (`wss://`) to `/v1/ws` | Yes | Yes | No |
| `lon1.octetproof.com`, `chs1.octetproof.com`, `sin1.octetproof.com` | HTTPS | Yes | No | No |
| `lon1.octetproof.com`, `chs1.octetproof.com`, `sin1.octetproof.com` | UDP 3478 (WebRTC) | Yes | Yes | No |

The collector measures network round trips to these three Octet hosts. They receive no cookies and no credentials.

## Content Security Policy

The collector needs `connect-src` entries for your mode, and a `worker-src` entry in every mode. Add them to your existing policy.

**`full`**, the default:

```text
connect-src 'self' https://octet.example.com wss://octet.example.com https://lon1.octetproof.com https://chs1.octetproof.com https://sin1.octetproof.com;
```

**`lite`**:

```text
connect-src 'self' https://octet.example.com wss://octet.example.com;
```

**`passive`**:

```text
connect-src 'self' https://octet.example.com;
```

Replace `octet.example.com` with your edge's hostname. List `wss://` for your edge explicitly, even if the edge shares your page's origin, because some browsers don't treat `'self'` as covering WebSockets.

In every mode the collector also starts a Web Worker from a `blob:` URL. Allow it for the best results:

```text
worker-src blob:;
```

If the Worker is blocked, the collector carries on without it and never throws an error because of it. If your policy has no `worker-src` directive, browsers apply `script-src` to workers, or `default-src` if there is no `script-src`. Adding `worker-src` replaces that rule for workers, so also list any sources your own workers use.

If you serve `octet-collector.js` from your own origin, `script-src 'self'` covers it. The collector needs no `unsafe-eval`, no `unsafe-inline` and no frames.

## WebRTC and firewalls

CSP does not control WebRTC. In `full` and `lite` mode the browser sends UDP packets to port 3478 on the three Octet network hosts. Corporate firewalls and some networks block outbound UDP. If yours might, allow outbound UDP 3478 to `lon1.octetproof.com`, `chs1.octetproof.com` and `sin1.octetproof.com`.

## If a host is blocked

The collector still works. It leaves out any measurement it could not make, sends the rest to your edge, and never throws an error because of it. The verdict is weaker: Octet has less evidence, so fewer masked sessions reach `medium` or `high`.

The one request that must succeed is the POST to your edge. If it is blocked, `ready()` and `verify()` reject, and no verdict is produced.

## Your edge

| Direction | Protocol and port | Peer |
|---|---|---|
| Inbound | TCP 443 | Browsers |
| Outbound | TCP 443 | `geo.octetproof.com` |

## Your backend

| Direction | Protocol and port | Peer |
|---|---|---|
| Outbound | TCP 443 | `geo.octetproof.com`, for verdicts and the key set |
