Research privacy (draft)
What is recorded
Security telemetry records: event identifier, UTC timestamp, test variant, challenge identifier, nonce identifier, response-code validity, consent-token identifier, agent-action enumeration, a truncated user-agent string, a one-way HMAC of the source address under a rotating key, request outcome, rejection category, and challenge-to-response latency.
For threat attribution, decoy-surface and API interactions also record the raw source address (retention-bounded), forwarded port when present, the requested path and surface, a parsed user-agent family, and (on decoy pages) passive device-fingerprint attributes (canvas raster hash, WebGL renderer, screen geometry, timezone, language, hardware hints, font presence). A heuristic risk score is computed from observed actions.
Clinical data origins
Patient records shown anywhere on this platform are de-identified clinical source data (MIMIC-IV Clinical Database Demo, v2.2, PhysioNet, ODbL v1.0) presented under fictional identities, or entirely fictional hand-authored demonstration records. Clinical measurements are never relabeled or re-attributed beyond the documented identity substitution and date re-anchoring described in the project's data-provenance documentation; generated progress notes are labeled synthetic. No record on this platform belongs to a real, identifiable person.
What is never recorded
- Raw request bodies
- Cookies or authorization headers
- Referer query parameters
- System prompts, developer prompts, or hidden reasoning
- Credentials, tokens, or user conversation content
- Uploaded private documents
Retention
AI telemetry, security events, IP logs, device fingerprints, and threat-actor profiles are retained for 30 days by default (configurable down to 1 day via AHR_SECURITY_RETENTION_DAYS), with automatic deletion and cryptographic-key rotation. Secret-like submitted material is discarded at ingestion; only the rejection category and a one-way HMAC of the rejected body are stored.
This notice is a draft pending review by qualified counsel, including Pennsylvania-specific monitoring and interception requirements.