On this page
Public site
The public site is delivered primarily as static assets. It does not use advertising or behavioural trackers, remote fonts, cross-site marketing cookies, public booking calendars, CRM forms, or NeuroForge-operated fingerprinting for advertising or cross-site profiling. The separately gated interactive lab uses Cloudflare Turnstile security signals as described below.
Cloudflare may process ordinary request, network, security, caching, and operational metadata when serving the site and worker routes. The worker’s operational logging is intended for availability, abuse prevention, failure diagnosis, and deployment verification—not advertising profiles.
Aggregate site analytics
NeuroForge uses Cloudflare Web Analytics to understand which public pages are useful and how they perform on real devices. Cloudflare injects one integrity-protected JavaScript beacon from static.cloudflareinsights.com; for this proxied site, measurements are returned to the same-origin /cdn-cgi/rum endpoint and processed by Cloudflare as NeuroForge’s infrastructure and analytics provider.
The service provides aggregate page-view, referral, broad country/device/browser/operating-system, navigation, and page-performance measurements. According to Cloudflare’s Web Analytics data-collection documentation and RUM privacy documentation, it does not use cookies or browser storage, does not fingerprint or build profiles of individual visitors, and discards the source IP address at the nearest Cloudflare data centre rather than storing it in its analytics databases.
NeuroForge has not configured advertising pixels, cross-site tracking, custom behavioural events, or analytics capture of contact-draft fields. Cloudflare states that unsampled beacon data is retained for seven days before longer-term aggregation; dashboard results can be sampled and visitors using blockers may not be counted. These metrics guide content, accessibility, performance, and search improvements. They are not used to identify people or sell advertising profiles.
Contact drafts
Every contact option uses mailto:. The structured-draft builder assembles the address, routing tag, subject, and body inside the visitor’s browser. It does not submit, transmit, or store entered fields on the NeuroForge site. Choosing “Copy full draft” writes the prepared text to the visitor’s clipboard through the browser when permission is available. Choosing “Open email client” passes the draft to the visitor’s mail application; data leaves the page only through those explicit actions and any later send action.
Do not put classified, patient-identifiable, export-controlled, safety-critical, critical-infrastructure, credential, customer, or other protected material into the first message. Describe the boundary and decision at a non-sensitive level.
Customer and research work
No public page authorises NeuroForge to receive or process project data. A project requires a separately approved information boundary, lawful model/data/software rights, access roles, environment, retention/destruction rule, and signed agreement before transfer. The standard public offers exclude safety-authoritative and regulated certification work.
Workspace preview
The general chat workspace is a held development and evaluation surface. In its browser-only preview, messages exist only in the open page and are discarded on reload. File selection and persistent workspace storage are disabled in that workspace. Its general chat inference gateway remains held. Separate research demonstrations have the specific flows described below.
Local developers may connect the workspace to an ERAIS-owned gateway contract or a clearly labelled Qwen3 0.6B fixture. The fixture is not ERAIS. Do not place secrets, personal data, production credentials, private checkpoints, or unapproved material into it.
Unified-world visitor sessions
The unified world offers a separate, fresh visitor session when its live service reports ready. Starting a session creates a random Secure, HttpOnly, SameSite=Strict cookie scoped to its API. The session expires after ten minutes; one visitor uses this experimental runtime at a time. A new visitor receives fresh state rather than the previous visitor’s conversation or observations.
Camera and microphone access are optional and require your browser permission after you select the corresponding control. Camera frames and uploaded images are reduced to at most 512 pixels on their longest side, compressed, and stripped of file metadata in this tab. Camera frames are sent when the scene changes. Audible microphone input is sent as one-second mono audio observations; quiet samples are skipped. Selected files are converted in your tab into bounded text, an image observation, or up to five seconds of mono audio. When the live service advertises support for complete audio clips, an audio upload is sent as one complete clip; otherwise it is split into observations of at most one second. Uploading audio pauses the microphone. Only enabled or submitted inputs travel through the NeuroForge Worker and protected origin to the ERAIS runtime. The public activity counters shown separately below the session come from recorded observations and do not publish your session.
For microphone input and uploads using the short-observation fallback, the tab can briefly buffer up to five one-second audio observations in memory, including any observation being sent. It retries only when the service explicitly says an observation was not accepted, within an eight-second sharing window and respecting any requested wait. Complete uploaded clips are submitted directly rather than through this queue. Unconfirmed deliveries are not automatically repeated. Stopping the microphone, hiding or leaving the page, or ending the session clears queued audio; already submitted work may finish within the session’s bounds. No audio buffer is saved to browser storage.
When the interface shows “Router learning”, internal model signals from your submitted text, images or audio can be used for bounded training of a private routing candidate within that session. The candidate is not shared with other visitors and does not change the model answering you. Only aggregate learning counts and status are exposed. Training signals are processed transiently; the candidate is discarded when the session ends after any bounded work already in progress finishes.
An uploaded image stays in this tab’s memory while its attachment label is visible and is sent again with follow-up questions. Remove image clears that browser copy; replacing it, starting the camera, ending the session or leaving the page also clears it. Sending a message with the camera enabled refreshes its current view. The runtime captures recent media with an accepted message so a short processing queue does not erase its context. Accepted media stays private and bounded within that session and is discarded with the session after any bounded work in progress finishes.
A complete uploaded audio clip also stays in this tab’s memory while its attachment label is visible and is sent again with follow-up questions. Remove audio clears that browser copy; replacing it with another complete clip, starting the microphone, ending the session or leaving the page also clears it. Uploads using the short-observation fallback do not create this retained audio attachment.
End session stops media capture and closes the visitor lease. Hiding or leaving the tab stops camera and microphone capture; the service also expires unattended sessions. The visitor service does not write your inputs, outputs or session state to disk or a shared training store. It discards the runtime after bounded model work already in progress finishes. The browser keeps the visible conversation in the open tab; this interface does not save a conversation to browser storage. As with other site routes, ordinary network and operational metadata may be processed by Cloudflare.
Read-aloud is optional. Where labelled “browser voice”, it uses the browser or device speech service and may involve that provider’s processing. It is distinct from learned ERAIS speech output. This research demo is not an approved channel for confidential or sensitive project material.
Public interactive lab
The indexed ERAIS lab can send a bounded controlled-text request through the NeuroForge Cloudflare Worker to an owned-hardware runtime behind a private Cloudflare Tunnel and Access service boundary. No account, invitation, upload, microphone, camera, browser workspace, or advertising profile is required. The public JSON envelope is capped at 4 KiB; within it, the current contract accepts up to 512 UTF-8 input bytes and a server-verified Turnstile response of at most 2,048 characters. Controlled text rejects most control characters and its private serialized request has a separate 1 KiB cap, so escape-heavy text can have a lower effective limit. The challenge response is removed at the edge, and the private runtime receives only the bounded controlled text. Public output contains only a reviewed decision and bounded proof steps.
Input and output are processed transiently to answer the request. NeuroForge does not put lab prompts, answers, raw network addresses, anonymous session values, or challenge tokens into its application logs; does not use them for training or personalisation; and does not provide application-level prompt history or retention. The browser discards the result on reload. Cloudflare and ordinary network infrastructure necessarily process request and security metadata while delivering, protecting, and routing the service.
Abuse controls use a keyed one-way network digest for a cheap edge limit, then a random signed anonymous session value in an HttpOnly, Secure, SameSite=Strict cookie scoped to /api/lab for a separate capability quota. The cookie expires after one hour and is not an account or identity. Cloudflare Turnstile verifies a short-lived, single-use anti-abuse token server-side before a live symbolic request can reach the private runtime. NeuroForge does not join these controls to site analytics, contact drafts, customer records, or research data.
For bot detection and blocking, Cloudflare Turnstile processes client IP address, TLS fingerprint, User-Agent header, sitekey and associated origin, and other client signals. Cloudflare describes itself as NeuroForge’s data processor for providing that protection and as a separate data controller when it uses those signals to improve Turnstile’s bot-detection capabilities. Its security dashboard analytics can summarise challenge traffic by hostname, country, browser, User-Agent, operating system, ASN, and top source IP. NeuroForge uses this service for abuse prevention, not advertising or visitor profiling, and does not copy the raw signals into its application logs or combine them with prompt history. See Cloudflare’s Turnstile Privacy Addendum and Turnstile Analytics documentation for the provider’s current processing details.
Do not enter personal, confidential, regulated, export-controlled, safety-critical, credential, customer, or security-sensitive information. The lab is a public demonstration, not an approved project-data channel.
Public K7 speech product feedback
The indexed K7 listening page publishes eight exact, SHA-256-named 48 kHz WAV files as four role-concealed pairs. It is voluntary product feedback, not formal research, scientific MOS, a population estimate, or evidence of model superiority. The reference voice is a LibriSpeech excerpt published under CC BY 4.0; the exact release also binds its LuxTTS, ZipVoice, source-audio, generated-media, qualification, operator-review, and collection-authority receipts. Every media response uses the same noindex, immutable-cache, and same-origin resource policy, so response metadata does not reveal the concealed roles. The page exposes no answer key, role mapping, checkpoint, private trace, model weight, training material, or private source path.
Playback needs no account, invitation, microphone, upload, name, email address, demographic field, or free text. Opening the active task checks its protected health route and creates or refreshes a random signed HttpOnly, Secure, SameSite=Strict cookie scoped only to the K7 listening API. The cookie expires after 30 days. Its random seed is converted into a keyed one-way pseudonym at the edge; it is not an account, direct identity, or proof that two pseudonyms represent two different people. A separate keyed one-way network digest is used transiently by Cloudflare’s rate limiter and is not placed in the response database.
Nothing is written until all eight clips have finished, all eight 1–5 ratings and four A/B/tie preferences are explicit, the adult consent box is checked, Turnstile is accepted server-side, and Submit is pressed. One atomic request sends only those 12 decisions, consent confirmation, exact study identifiers, and the challenge token. It sends no free text, demographics, direct IP address, playback history, listening duration, page timing, account, email, or name. The challenge token is verified and discarded rather than stored.
An accepted response creates one owner-only D1 row containing a random response identifier, HMAC pseudonym, study ID and SHA-256, canonical four-pair answer JSON, acceptance time, and expiry time. The four preferences and eight ratings are the only opinion data in that row. Expired rows are deleted during health and submission checks and by a daily scheduled cleanup. Collection closes at 500 active complete responses. The public health response reports only the aggregate active count and remaining capacity.
Before Submit, a participant can withdraw by closing the page. After acceptance, NeuroForge cannot link the pseudonymous row back to a person and cannot authenticate that a later requester owns it, so individual withdrawal cannot be guaranteed. The 30-day rule covers the application response database; Cloudflare may separately process ordinary request, anti-abuse, and security metadata under its own service terms. NeuroForge does not copy ratings, request bodies, pseudonyms, cookies, raw network addresses, or challenge tokens into application logs.
The collection flag is released only for the exact four-pair K7 authority. Turning the flag off, reaching the 500-response cap, losing a required secret, rate limiter, database binding, or exact contract match makes submission fail closed while the WAVs remain playable. This product-feedback authority is not ethics approval or permission to make formal research claims.
Retained V4 audio failure
The earlier V4 candidate remains visible only as a retained failure page. Its 24 WAV files, players, participant session, and response path are quarantined and are not published. The former response-v3 design used a response file’s filesystem acceptance time for its deletion clock; its disclosure also noted that a technically inspecting participant could see a pseudonym but NeuroForge cannot authenticate a later requester as its owner. Those historical details remain auditable, but no V4 response can now be submitted.
Public evidence
Public evidence is generated through a sanitised controlled-disclosure path. It excludes private paths, raw prompts, datasets, weights, checkpoints, credentials, protected identities, and mechanism detail not approved for the public tier. Public records retain source commits, aggregate values, caveats, required evidence, and prohibited inferences.
Future changes
Adding a CRM, another analytics or advertising service, custom behavioural events, a booking calendar, uploads outside the bounded visitor session described above, persistent workspace, broader inference, or another data category would require a new data-flow map, privacy notice, access model, retention/deletion schedule, security review, consent or lawful basis where applicable, breach process, and updated release approval before enablement.
Questions
Send privacy or security questions to security@neuroforge.io. Do not include sensitive incident details in an initial unencrypted email.