First-party and zero-authority
The browser receives a random UUID cookie for private event correlation. It is not a login, cannot authorize an action, and is not calculated from device characteristics or an IP address.
AIREA maintains a private integrity trail so research actions can be attributed, investigated, and reconciled without publishing a person's browsing history.
The browser receives a random UUID cookie for private event correlation. It is not a login, cannot authorize an action, and is not calculated from device characteristics or an IP address.
After sign-in, material actions can be correlated to the researcher, credentials, submissions, registered-work IDs, and evidence runs.
No public endpoint exposes the audit trail. It is excluded from research records, author pages, discovery results, and external provider payloads.
Visiting ID, authenticated user ID when present, event type, internal resource reference, minimal structured status metadata, and timestamp. The authenticated account session is a separate opaque credential whose server-side hash and expiration are checked before any restricted action. Raw IP addresses and browser fingerprints are not stored by the AIREA application.