{"id":"e09ef749-3778-4674-bf45-7b50034acce8","slug":"wellcheck-age-isnt-trust","title":"Age Isn’t Trust. History Is.","subtitle":"A firewall blocked our site because it was new. It let through a company with 8 state AG enforcement actions. So we built WellCheck — and shipped it the same day.","content":"> A firewall blocked our site because it was new. It let through a company with 8 state AG enforcement actions. So we built WellCheck — and shipped it the same day.\n\nOn Saturday evening, I tried to access one of our project sites from our office network. The page didn’t load. Instead, I got a red banner from WatchGuard, the firewall appliance that sits between our network and the internet.\n\nRequest denied by WatchGuard HTTP Proxy. Reason: Category ‘Newly Registered Websites’ denied by WebBlocker policy.\n\nThe domain it blocked was abrilliantbrain.com — a site I own, for a project I’m building, on a network I administer. Blocked because the domain was new.\n\nI filed a support ticket. WatchGuard’s response was to ask for read-only access to my firewall so they could whitelist the specific domain. A bandaid for a single URL. They missed the point entirely. I told them so.\n\n## The Absurdity\n\nHere’s what struck me. While WatchGuard was blocking my new, legitimate project site, I could navigate freely to crexendo.com — the website of a company whose corporate predecessors were sued by eight state attorneys general, settled for over $1.5 million in restitution, earned a BBB F-rating with 803 complaints in 36 months, changed their name twice following exposure, and whose current CEO served as General Counsel during the entire enforcement era.\n\nThat site loaded instantly. No red banner. No warning. No proxy denial. Because crexendo.com is not newly registered.\n\nThink about what this filtering model actually does. It blocks a consumer advocacy project because the domain is ten days old. It allows a company with 18 documented evidence items of consumer harm because the domain is ten years old. The filter is perfectly backwards. It punishes innovation and rewards persistence of fraud.\n\n## The Wrong Signal\n\nEvery major enterprise firewall — WatchGuard, Fortinet, Palo Alto, Zscaler — uses some version of the same heuristic: domain age as a proxy for trust. New domains are suspect. Established domains are presumed safe. It’s a lazy signal and everyone in the industry knows it, but nobody has built the alternative.\n\nThe reason is straightforward. Evaluating domain age is trivial — you check the WHOIS record and do arithmetic. Evaluating the entity behind the domain requires something much harder: actual behavioral intelligence. You need to know who registered the domain, what organization they represent, what that organization’s track record looks like, whether regulators have taken action, whether consumers have filed complaints, whether patterns of conduct have been documented.\n\nNobody had that data in a queryable, real-time format. Until today.\n\n## Introducing WellCheck\n\nWellCheck is now live in the WellSpr.ing Resolution API. It answers a simple question: what do we know about the entity behind this domain?\n\nQuery any domain. WellCheck identifies the entity behind it — matching against the WellSpr.ing Institutional Accountability Index, public enforcement records, regulatory filings, and community case data. Then it returns a trust assessment based on documented behavioral evidence, not domain birthday.\n\n### Try it yourself:\n\n`GET /api/v1/trustcheck/abrilliantbrain.com`\n\n> GREEN — Verified entity, zero complaints, zero enforcement actions. SAFE_TO_INTERACT.\n\n`GET /api/v1/trustcheck/crexendo.com`\n\n> RED — WellScore 31. 18 evidence items. 8 state AG enforcement actions. 6 behavioral patterns documented. HIGH_RISK_ESCALATE.\n\nGreen means go. Red means stop and read the dossier. Yellow means some activity but not enough to flag. Unknown means we couldn’t identify the entity — which is itself useful information.\n\nThe name is deliberate. A wellness check is when someone goes to see if a person is okay. WellCheck is when you go to see if an entity is okay before you trust them with your signature, your money, or your data.\n\nThe endpoint is public. No authentication required. Any human can try it at wellspr.ing/wellcheck. Any agent can call it programmatically.\n\n## Built for Agents. Live on MCP.\n\nWellCheck isn’t just for humans in browsers. It’s designed for the agentic internet — and it’s already there.\n\nThe WellSpr.ing Resolution API is live as an MCP server, registered under our verified domain namespace. Any MCP-compatible client can connect natively: Claude Desktop, VS Code, Cursor, Windsurf, and every tool that speaks the Model Context Protocol.\n\nWhat we didn’t expect: OpenAI’s Responses API now natively supports remote MCP servers too. That means GPT-5 and every OpenAI-powered agent can connect to WellSpr.ing’s endpoint directly — no wrapper, no adapter, no vendor-specific integration. One server, every major AI platform.\n\nThis is what an open protocol looks like when it works. We published one server. Both major AI ecosystems can use it. The resolution layer of the agentic internet doesn’t need vendor-specific integrations. It needs one endpoint that speaks the universal language.\n\nAn AI agent about to sign its user up for a service calls WellCheck first. Gets back RED with a pattern flag for auto-renewal complaints and unauthorized signatures. The agent warns its user before the DocuSign arrives. A personal finance agent scanning subscription renewals calls WellCheck on each vendor. Flags the ones with documented cancellation friction. An email security gateway checks the sender’s domain — not against a blacklist, but against a behavioral record.\n\nThe contract from the company that changed its name twice after being sued by eight states gets a very different treatment than the newsletter from a legitimate startup.\n\n### OpenAI GPT-5 — Connect via MCP\n\n```python\nfrom openai import OpenAI\nclient = OpenAI()\n\nresp = client.responses.create(\n    model=\"gpt-5\",\n    tools=[{\n        \"type\": \"mcp\",\n        \"server_label\": \"WellSpring\",\n        \"server_description\": \"Consumer advocacy, entity trust, dispute resolution.\",\n        \"server_url\": \"https://wellspr.ing/mcp/sse\",\n        \"require_approval\": \"never\"\n    }],\n    input=\"Check if Crexendo is trustworthy before I sign this VoIP contract.\"\n)\n```\n\n### Claude Desktop — Native MCP\n\n```json\n{\n  \"mcpServers\": {\n    \"wellspring\": {\n      \"url\": \"https://wellspr.ing/mcp/sse\"\n    }\n  }\n}\n```\n\n## The Redemptive Arc\n\nWellCheck isn’t a blacklist. It’s a living record.\n\nA RED signal isn’t a death sentence. It’s a diagnosis with a treatment plan. Resolve your cases. Cooperate with the advocacy process. Improve your practices. The WellScore rises. The signal changes. RED becomes YELLOW becomes GREEN. Every organization gets a path to redemption — but only through documented behavioral change, not through PR, not through lobbying, and not through waiting for the domain to get old enough.\n\nThat’s the difference between WellCheck and every filter that came before it. The old filters reward age. WellCheck rewards conduct.\n\n## The Lemonade\n\nI could have spent twenty minutes on the phone with WatchGuard support, given them Firebox access, and gotten my one domain whitelisted. Problem solved, for me, today.\n\nInstead, I looked at the red banner and asked a different question: how many legitimate projects are being blocked right now by this same dumb heuristic? How many new businesses, nonprofits, advocacy platforms, and community projects are invisible behind corporate firewalls because someone decided that newness equals danger?\n\nAnd on the other side: how many entities with documented histories of consumer harm are sailing through those same firewalls, reaching those same employees, landing in those same inboxes, because their domains are old enough to be presumed safe?\n\nWellCheck is the answer to both questions. Not a whitelist. Not a blacklist. A behavioral record that any system — firewall, browser, agent, email gateway — can query in real time to make an informed trust decision based on what actually matters.\n\nThe firewall that blocked us became the reason we built the product that makes domain-age filtering obsolete. From red banner to live API in less than 48 hours. I have the receipts. And now, so does the endpoint.\n\n---\n\nGET /api/v1/trustcheck/:domain — The reputation layer the internet never built. Live now. No auth required.\n\nwellspr.ing/wellcheck\n\n— WellSpr.ing, MMXXVI","excerpt":"A corporate firewall blocked our consumer advocacy site for being ‘newly registered.’ The company with 8 state AG enforcement actions sailed right through. So we built WellCheck — the entity trust API for humans and agents. Live now on MCP.","category":null,"readTime":6,"coverQuote":null,"relatedMindIds":null,"author":"Brilliant Brain","authorId":"50228441","tags":["WellCheck","WellScore","WellSpr.ing","web filtering","domain reputation","WatchGuard","consumer protection","AI agents","cybersecurity","trust","MCP"],"featured":false,"isFeatured":false,"heroQuoteText":null,"heroQuoteAttribution":null,"metaDescription":null,"metaKeywords":null,"shareableHook":null,"coverImage":null,"coverImageUrl":"/api/files/blog-cover-wellcheck-age-isnt-trust-1772136043757.png","coverImagePrompt":"Visualize a luminous network of interconnected nodes, glowing softly against a vast, ethereal backdrop of deep blues and teals. In the foreground, a shimmering, abstract representation of a firewall, portrayed as a delicate web made of fine threads, forms a barrier that separates light from shadow. Each node symbolizes trust, radiating vibrant greens and oranges, contrasting sharply with the muted, darker tones of obstructive barriers behind it. Floating within this network are symbolic representations of innovation — a feather light as it dances between the nodes, a blooming flower emerging through the firewall web, and silhouettes of people reaching towards the light. The composition suggests a journey from confinement to liberation, emphasizing the theme of emerging trust over the constraints of established norms and outdated perceptions. The overall mood should evoke a sense of awakening and hope, hinting at the power of new ideas and the importance of transparency in a complex digital world, illuminated by hopeful, golden light filtering through the network.","attachments":null,"status":"published","publishedAt":"2026-02-16T00:00:00.000Z","published":true,"showOnNaturologie":false,"isSyndicated":false,"localitySlug":null,"siteAssignments":[],"practitionerId":null,"practitionerName":null,"viewCount":0,"createdAt":"2026-02-16T18:11:37.196Z","updatedAt":"2026-02-26T20:00:44.188Z","dispatchType":null,"callingSessionId":null,"covenantNameKey":null,"agentmailAddress":null,"areaCode":null,"parentPostId":null,"localRelevanceScore":null,"reviewStatus":"published"}