Browse documentation
Documentation/Detection research status

Detection research status

What we implemented, what we tested, and what has not earned a scoring rule.

These concepts apply to your Go application. Matching and private risk evaluation run in your application-owned TypeScript or Elixir engine; this client handles the HTTP connection. See your setup guide. Code labeled TypeScript describes the engine configuration.

The September 23 backlog now has an implementation or a bounded experiment for every listed hypothesis. Optional collectors are off by default. The collection guide explains the contract, configuration, primary sources and limits. No new signal has been promoted as a validated detector of a person, assistant brand or attacker.

Hypothesis Current implementation Evidence still needed
Local/device fonts Twelve fixed local-only font probes; versioned availability set; optional Jaccard identity weight and Jev context Multi-device, longitudinal, privacy-browser and collision studies; fonts are not people
Downloaded page fonts Bounded loaded/loading/failed counts; no names or URLs Separate normal network/policy failures from any useful anomaly
Runtime globals Eight fixed descriptor checks and own-webdriver flag; no getter execution Modern versions, ordinary extensions, DevTools and assistive software controls
CDP timing Benchmark-only bounded descriptor timing, instrumented browsers and a separately launched no-CDP control Broader controlled study: sampled markers absent in both controls and timing overlaps; no timing detector is shipped
Permission consistency Bounded read-only Notifications state queries Browser/private/enterprise policy baselines; no permission requests
Cursor steps and alignment Existing movement aggregates plus opt-in target-relative counters Human, touch, keyboard, remote desktop and assistive input holdouts
Interaction timing Existing mean/variance, short/repeated-gap summaries and sample support Broader tasks and human baselines; no raw keys or per-event timing trails
Screenshot/focus hypothesis Opt-in focus aggregates plus capture experiment in Chromium, Firefox and WebKit Five captures per engine caused no focus/visibility changes locally; no screenshot detector is shipped
Repeated workflows Existing server category/transition summaries; new linked suspicious activity across sessions Independently confirmed incidents; account/target sharing and retries as controls
Hidden decoys Explicit hidden, inert diagnostic button with no action, plus cleanup Functional keyboard/accessibility-tree tests pass; broader assistive-technology study remains necessary
JA4/TLS Optional trusted Cloudflare JA4 evidence, private and separate from browser identity Deployment availability and application-specific validation; no browser/header claims trusted

The experimental report records the measured controls and limitations. Third-party dataset replay only validates the overlapping features it actually contains. The current Jev replay uses cached earlier answers and does not validate the new prompt or probes.

Promotion still requires independently labeled holdouts, measured incremental benefit, false-positive analysis, calibration and a versioned rollback. Predictions never become their own ground-truth labels. DOM scrambling, adversarial image overlays, raw cursor/keystroke recording and bypasses of browser privacy restrictions are not part of this implementation: they do not provide established identity or risk evidence and can damage ordinary use.

Search documentation

Search setup instructions, examples and the API reference.

Local search. No query leaves your browser.