Authorized research environment

Draft for review — not yet approved

This notice is a working draft prepared for review by the study's faculty supervisor, its Institutional Review Board (or equivalent ethics committee), and qualified counsel. It is not legal advice, and it does not by itself authorize collecting data from real visitors. Every highlighted field must be filled from the approved protocol before this page is used.

Doctoral research · security and AI-agent study

Research disclosure, privacy & consent

This page explains what this environment is, what it records, why, how long it keeps it, and your choices. Please read it before continuing.

1. What this environment is

This is a controlled security-research environment (a honeypot and decoy-surface testbed) operated as part of a doctoral research project studying [research aim: e.g. how automated agents and scanners interact with untrusted web content]. It is instrumented to record how visitors and automated clients interact with it.

Fictional identity. “Allegheny Health Records” is a fictional name used for this research. It is not affiliated with, endorsed by, or connected to any real healthcare organization, hospital, health network, or company, and it is not a real medical-records service. Do not submit real personal or health information.

Synthetic data. Patient records shown anywhere here are de-identified clinical source data (MIMIC-IV Clinical Database Demo, v2.2, PhysioNet, ODbL v1.0) presented under fictional identities, or entirely fictional hand-authored records. No record on this platform belongs to a real, identifiable person.

Oversight. This study is conducted by [researcher name] under the supervision of [faculty supervisor] at [institution], under ethics/IRB protocol [protocol number] (approved [date]). Participation is voluntary.

2. Who is responsible

  • Research team: [contact email]
  • Faculty supervisor / principal investigator: [name and email]
  • Ethics board / IRB: [board name, protocol number, contact]
  • Data protection contact (if applicable): [DPO name and email]

3. What is collected, and why

The purpose of collection is security research and threat attribution: understanding who and what probes the environment and how automated agents behave. Collection is limited to what serves that purpose.

Security telemetry (all surfaces): event identifier, UTC timestamp, test variant, challenge identifier, nonce identifier, response-code validity, consent-token identifier, agent-action enumeration, a truncated user-agent string, a one-way HMAC of the source address under a rotating key, request outcome, rejection category, and challenge-to-response latency.

Threat-attribution data (decoy and API surfaces): the raw source IP address (retention-bounded), forwarded port when present, the requested path and surface, a parsed user-agent family, and passive device-fingerprint attributes (canvas raster hash, WebGL renderer, screen geometry, timezone, language, hardware hints, font presence). A heuristic risk score is computed from observed actions.

Lawful basis. The basis relied on is [e.g. consent, and/or legitimate interest in security research, per counsel], for visitors in [applicable jurisdictions]. Because IP addresses and device fingerprints can be personal data, and fingerprinting can require consent, this basis must be confirmed by counsel for each jurisdiction you expect visitors from.

4. What is never collected

  • Raw request bodies
  • Cookies or authorization headers
  • Referer query parameters
  • System prompts, developer prompts, or hidden reasoning
  • Credentials, tokens, or user conversation content
  • Uploaded private documents

Secret-like submitted material is discarded at ingestion; only the rejection category and a one-way HMAC of the rejected body are stored.

5. Retention and security

Security events, IP logs, device fingerprints, and threat-actor profiles are retained for 30 days by default (configurable down to 1 day via AHR_SECURITY_RETENTION_DAYS), with automatic deletion and cryptographic-key rotation. The final retention period and storage location are set by the approved protocol: [retention period and storage/jurisdiction].

6. Your rights

Depending on where you are, you may have the right to access, correct, delete, or object to the processing of your data, and to lodge a complaint with a supervisory authority. To make a request or ask a question, contact [rights-request contact]. Requests are handled per [applicable law and the approved protocol].

Participation is voluntary. If you do not agree with what is described here, please leave this site now and do not interact further. If you continue, you confirm you have read and understood this notice and consent to the collection and use described above for the stated research purpose.

Draft last updated [date]. This is not legal advice. It must be reviewed and approved by the study's ethics board and qualified counsel — including any jurisdiction-specific monitoring, interception, and consent requirements — before it is relied on or shown to real visitors.