diff --git a/DECISIONS.md b/DECISIONS.md
index cf6f57e..4a440ed 100644
--- a/DECISIONS.md
+++ b/DECISIONS.md
@@ -91,3 +91,4 @@
- 2026-03-01 m+git@andri.dk — Added portal UI screenshots to landing page. 4 PNGs (setup wizard, dashboard, activity feed, subscriptions) captured via Playwright with mocked API responses. Displayed in 2x2 grid "See it in action" section between Features and Architecture. Screenshots are served as static assets from `web/`.
- 2026-03-02 m+git@andri.dk — Portal HTTPS cert now cached with expiration, matching leaf cert behavior. Previously, `startPortalHTTPS` generated the portal cert once at startup and baked it into `tls.Config.Certificates` — after 24h of uptime it expired, causing TLS errors for the portal, PAC file, and all proxy traffic routed through the HTTPS port. Fix: `Cache.GetPortalCert()` caches the portal cert with a 24h `expiresAt` and regenerates on demand. `startPortalHTTPS` uses `tls.Config.GetCertificate` callback instead of a static cert. Transparent mode was unaffected (already called `PortalCert()` per-connection).
- 2026-03-02 m+git@andri.dk — TLS handshake failure circuit breaker for automatic cert-pin detection. When a host accumulates 3 TLS handshake failures within 10 minutes, the proxy auto-switches it to passthrough (no MITM) for 1 hour. After the TTL expires, a single failure re-trips the breaker immediately (`prevTripped` flag) to avoid repeated breakage. `RecordSuccess` clears all state when a MITM handshake succeeds, proving the host is not pinned. Portal host and IPs are excluded — they can never be auto-passthrough'd. Events are logged at warn level and recorded in the activity feed as `auto-passthrough`. Works in both explicit and transparent proxy modes. No CLI flags; all thresholds hardcoded. In-memory only; resets on restart.
+- 2026-03-02 m+git@andri.dk — SEO and Open Graph improvements for landing page. Added `og:image` (1200x630 PNG matching the CRT/terminal aesthetic), `og:site_name`, Twitter Card meta tags, canonical URL, SVG favicon, and JSON-LD `SoftwareApplication` structured data. OG image source is `web/og-image.html` — a standalone HTML file screenshotted via Playwright to `web/og-image.png`. Keeps the image regenerable from source.
diff --git a/web/favicon.svg b/web/favicon.svg
new file mode 100644
index 0000000..b5264f2
--- /dev/null
+++ b/web/favicon.svg
@@ -0,0 +1,5 @@
+
diff --git a/web/index.html b/web/index.html
index e337bca..15b0e7f 100644
--- a/web/index.html
+++ b/web/index.html
@@ -5,10 +5,47 @@
Network-wide HTTPS proxy that blocks ads at the HTTP layer. Full Adblock Plus filter support, cosmetic filtering, and passkey auth. Goes where DNS blockers can't.
+
+
+
+
+
+
+
+
+ user@ublproxy:~
+
+
+ # Run with Docker
+ $docker run-p 8080:8080 -p 8443:8443\
+ -vublproxy-data:/data\
+ ghcr.io/andrioid/ublproxy:edge
+
+ # Portal ready at :8443
+ $curl-x https://127.0.0.1:8443\
+ https://example.com
+