Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The documentation makes a strong safety claim that there is no bypass for webhook secret/signature validation, yet elsewhere documents `PROCU_ALLOWED_TIER` as a dev override that bypasses webhook signature checks. Contradictory security claims are dangerous because operators may deploy with false assumptions, and an accidentally enabled bypass could disable a core authenticity control for payment/license webhooks.
