Tanaw methodology
Evidence before assertion.
A useful technical finding should tell you what Tanaw concluded, what it actually observed, where that evidence came from, and how certain the interpretation is.
The conclusion sits above this chain. It is not allowed to replace it.
01
What is a finding?
A finding is an interpretation Tanaw can support with something it observed. It may summarize a provider clue, a configuration state, a detected technology or another technical condition, but the interpretation remains distinct from the underlying evidence.
That distinction matters because the same record can support different levels of confidence. Tanaw should make the reasoning inspectable instead of asking you to trust a label on its own.
02
Finding anatomy
shops.myshopify.comIllustrative anatomy, not a live result. The values show how the relationship is presented; run a lookup for current observations.
03
Observation → Evidence → Source / channel
The evidence chain answers three different questions. What did Tanaw observe? Which record or browser-visible signal supports the interpretation? Which channel supplied that observation?
CNAME → shops.myshopify.comPlain-language takeaway: Tanaw does not merely name a platform. It shows the record that led to the conclusion and where that record came from.
04
Where observations come from
- Public DNS
- Address, alias, nameserver, mail and text records exposed through DNS.
- Registration / registry
- Registrar, lifecycle dates, status codes, nameservers and related public registration data when available.
- Network / ASN
- Resolved addresses, announcing network and prefix context from public network data.
- Certificate Transparency
- Publicly logged certificate issuance. This is not the same as the certificate a server is currently presenting.
- Browser-local extension
- Markup, headers, timing and other signals the current tab exposes to the extension.
05
Confidence and uncertainty
Confidence describes the strength of the connection between the evidence and the interpretation. It does not turn an inference into a fact.
06
“Could not check” is not “no problem.”
Tanaw keeps source failures separate from successful observations. A timeout, unavailable provider, missing registry record or unresolved domain is evidence about the check itself, not permission to display an all-clear state.
07
What Tanaw refuses to infer
- A CDN or reverse proxy is not automatically the origin host.
- A certificate in a transparency log is not automatically the certificate currently served.
- Unavailable checks are not converted into positive security claims.
- Public records do not reveal private server-side configuration that was never exposed.
- The website lookup does not claim to actively scan, probe ports or enumerate hidden paths.
08
Known boundaries and limitations
The website lookup and the extension are intentionally different. The website reads public domain infrastructure records from your browser. The extension can inspect the current page locally, subject to browser permissions and protected-page restrictions.
Neither surface should be mistaken for continuous monitoring, a penetration test, forensic proof, legal advice or a complete picture of private infrastructure.
09
A worked evidence example
CNAME shops.myshopify.comThe useful part is not the brand name. It is the chain: conclusion, supporting record, source/channel and confidence remain separately inspectable.
10
Privacy and data handling
Methodology explains how Tanaw reasons about observations. The complete privacy disclosure separately documents what each Tanaw surface sends, stores and processes.
Return to the instrument
Inspect the evidence on a real domain.
Methodology is useful only if the product lets you check the reasoning for yourself.