Frequently asked questions
Answers about Marsward discovery, provider integrations, data storage, security, pricing and the current local preview.
What is FlowState Marsward?
An application-centered operations command center. It brings infrastructure references, ownership, runbooks and metric provenance into one view while providers remain the systems of record.
What can the scanner discover?
It recognizes 14 provider families, including RevenueCat, Sentry, Stripe, Cloudflare, Supabase and Vercel, from supported code and configuration signals. It runs against a folder you select. It does not observe runtime traffic or enumerate live provider accounts.
Can I scan a website instead of a repository?
Yes. Choose Website URL in resource discovery. The local API reads a public HTTPS homepage and up to three same-origin scripts. Private addresses, credentials, query strings, custom ports and redirects are blocked. The site may log these requests. Findings are unverified provider clues, not a complete inventory.
Does scanning upload my code?
No. The scanner processes eligible files on your device. Only references you choose to add send limited evidence, such as file locations and known signal names, to the local inventory API. Secret files and build output are skipped. Avoid putting credentials in manual notes or URLs.
What if something is not detected?
Add a manual resource. Custom endpoints, runtime-only configuration, unsupported SDKs, files outside scan limits and inactive paths can be missed. Results show skipped files and incomplete coverage.
Can Marsward change my infrastructure?
The optional Vercel connector only reads deployment metadata when configured by the operator. Operational actions such as deploying, changing DNS or issuing refunds stay with the provider.
Are OAuth and MCP integrations available?
Vercel OAuth is implemented for both the local API and signed-in owner workspaces. Workspace authorization is encrypted in Supabase, and on-demand deployment reads have been verified with a real account. MCP installation and a hosted production service are not available. Other live adapters remain planned. Authorization differs by provider. Each future API or MCP adapter will need reviewed operations and appropriately scoped credentials.
Will Marsward keep historical data?
Yes, normalized historical metric snapshots are part of the planned product. Raw provider responses and customer records are not intended to become dashboard storage. Historical persistence, retention enforcement and reports are not implemented in the local preview.
Is Marsward production ready?
No. This is a local review build. Supabase account authentication and workspace inventory are implemented. Hosted API integration, background collection, additional adapters and production hardening remain launch gates. No uptime SLA or security certification is claimed.
Can I buy a plan?
Not yet. The pricing page shows proposals for review. There is no paid subscription or checkout.
How do I get help or report a security issue?
Use the support page for current contact availability and troubleshooting guidance. Never send tokens, passwords, private source code or customer records with a report.