Does KillChains.com require an account?
No. The current public release has no account system, advertising, analytics provider, uploaded user content, or server-side persistent learning profile.
Read the supporting sectionSite policy
Release 1.38.0 is deliberately data-minimizing. It has no user accounts, analytics service, advertising, uploaded content, server-side persistent learning profile, or server-side saved Atlas views, Human Control replays/results, or Source Classification Evidence Lab results.
Answer-first summary
No. The current public release has no account system, advertising, analytics provider, uploaded user content, or server-side persistent learning profile.
Read the supporting sectionNo. Those sensor streams are not collected or transmitted by the public release.
Read the supporting sectionThe PHP application uses a temporary session cookie to keep the selected scenario or challenge’s authoritative state, evidence and decision progress, enabled controls, recent synthetic events, rate-limit counters, and a CSRF token. The cookie is HttpOnly and SameSite=Lax; it is marked Secure when the site is served over HTTPS. Session retention is controlled by the hosting provider’s normal PHP configuration.
The immersive renderer loads the pinned Three.js module from jsDelivr when available. That network request is governed by the CDN’s own policies. When the module cannot be loaded, the site automatically uses its local Canvas 2D fallback. No simulation state is sent to the CDN.
The hosting provider may create ordinary HTTP access, error, security, or infrastructure logs. Their contents and retention are controlled by the deployment environment, not by the application code. A production operator should document those practices and minimize IP and user-agent retention where feasible.
After a completed daily challenge, the browser may store the challenge code, completion date, model label, and overall educational assessment in localStorage. This optional record never leaves the device in this release. The homepage includes a Clear local record control; browser settings can also remove all site data. Closing the browser normally ends the session cookie. Reset returns the active synthetic challenge to its first phase but does not erase the separate local completion record or control host-level logs.
Result cards are generated in the browser. A share action occurs only after the visitor activates it and may use the browser’s native sharing or clipboard interface. Shared challenge links contain only an allowlisted challenge identifier and deterministic seed; they do not contain the sender’s answer, score, name, IP address, or XR telemetry.
The Human Control Lab uses only page-local JavaScript state for selected synthetic observations, fictional thresholds, policy choices, queue progress, authority-token assignments, timers, and results. The application does not transmit those interactions, write them to the PHP session, add them to localStorage, or create a server-side profile. Reloading the page clears the lab state.
Copy-result controls run only after explicit visitor action. They place a text-only synthetic summary in the browser clipboard when permission is available. The summary contains no required identity, target, coordinate, raw sensor data, pose, gaze, voice, or location. Browser and operating-system clipboard handling remains outside the application.
Each Human Control module can create a deterministic HC1 replay code from released module IDs and allowlisted synthetic choices. The code contains no name, email, freeform text, raw timing, IP-derived location, pose, gaze, voice, private note, real target, coordinate, weapon parameter, casualty value, or real-system performance field. The application creates no account, PHP-session result, server-side replay record, analytics event, localStorage, sessionStorage, IndexedDB, or cookie from the replay.
A replay URL is still an ordinary URL. Its hc query value may appear in browser history, copied messages, referrer handling, security appliances, or ordinary host access logs when requested. The application marks replay-query variants noindex,follow,noarchive and canonicalizes them to the clean Human Control page, but that does not make a copied URL private. A local 1200×630 PNG and accessible text result are created only after explicit visitor action and are not uploaded by this release.
The Anticipatory Intelligence Lab keeps classification choices, opened evidence, hypothesis selections, R-CCAM proposal checks, federated-node quarantine state, counterfactual progress, and the page-local learning report only in JavaScript memory for the current page. It does not write those interactions to the PHP session, a database, localStorage, sessionStorage, IndexedDB, cookies, analytics, or an external service. Reloading or leaving the page clears the exercise state.
The lab does not accept live intelligence, names, identifiers, coordinates, uploads, freeform operational data, or outside-system connections. The copy control writes a fixed synthetic text summary to the clipboard only after explicit visitor action. No result is stored by this release, although copied text and ordinary page requests remain subject to the visitor’s browser, operating system, messaging application, and hosting-provider logs.
The Source Classification Evidence Lab keeps answers, opened lineage panels, progress, and result metrics only in page-local JavaScript memory. It does not use a PHP session, fetch(), XMLHttpRequest, WebSocket, EventSource, sendBeacon(), localStorage, or sessionStorage. Reloading or leaving the page clears the exercise state.
The copy control writes a fixed, privacy-safe text summary only after explicit activation. The download control creates a PNG locally with the browser’s Canvas API. Neither artifact contains a name, location, raw timing, target data, or claim about real-system performance. A challenge-code query changes only the deterministic card order; as an ordinary URL, it may appear in browser history or server access logs when requested.
The Evidence Atlas does not create a server-side saved-view record. Its current filters, selected public records, comparison references, timeline position, and optional search text can appear in the browser address through history.replaceState(). Copying a view happens only after the visitor activates Share current view.
Because an Atlas view is an ordinary URL, its query string may be retained in browser history, copied into messages, included in referrer handling, or written to ordinary hosting logs when another person requests it. Do not enter names, private notes, credentials, classified terms, or other sensitive information in the Atlas search field. The application does not use that text to contact another system, create a record, or build a profile.
The provider directory can filter providers and company-to-system relationships by search text, category, kill-chain function, evidence class, lifecycle, relationship role, and sort order. Up to four released relationship IDs can be selected for comparison. Without JavaScript, those values are processed by the server as ordinary GET parameters. With JavaScript, filtering and comparison are performed locally and the visible state may be reflected in the browser URL.
KillChains.com does not create an account, saved comparison, rating, or behavioral profile from those selections. Search terms and released relationship IDs placed in a URL may still appear in browser history, copied links, referrer handling, and host access logs, so do not enter private or sensitive information.
Official company and product links leave KillChains.com after an explicit click. The destination site's privacy, cookies, analytics, and terms apply after that navigation.
KillChains.com includes ordinary links to the independent sister site at KillWebs.com. This site does not embed its pages, proxy its content, execute its JavaScript, or transmit your KillChains challenge, Atlas, Evidence Lab, or Human Control state to it. When you activate an external link, the destination site may receive the usual web request information and may apply its own logs, cookies, analytics, privacy policy, availability, and regional behavior.
KillChains.com also includes ordinary links to Evulgare.com, the ecosystem destination for real-system evidence and accountability software. KillChains.com does not embed Evulgare, transfer simulation or laboratory state to it, create a cross-site account, or transmit a visitor’s KillChains interactions when a page loads. Activating an external link creates an ordinary request to Evulgare.com, whose own logging, privacy, security, availability, and service terms then apply.
The public KillChains pages do not collect production-system telemetry, model versions, software inventories, authority records, operator-view evidence, or incident evidence for Evulgare. Any future real-system integration belongs to Evulgare’s separate product and contractual boundary, not this educational site.
The Accountability Handoff Lab uses only a fixed fictional scenario and local page state. It sends no classification choices to KillChains.com, KillWebs.com, or Evulgare; creates no account or persistent learner profile; and copies a summary only after an explicit visitor action.
The Machine Answerability Replay also uses only fixed server-rendered fictional records and current-page JavaScript state. Its state selector and causal-question display create no account, cookie, saved result, analytics event, persistent browser record, production evidence transfer, or cross-site session. A copied report is generated only after explicit activation.
The Machine Answerability Remediation Lab applies safeguard selections only in the current page and optional query string. It creates no server-side result, account, cookie, persistent browser profile, analytics event, production evidence record, or cross-site session. Copying the synthetic report requires explicit activation.
The Predictive Enforcement Explorer is a read-only public research page. Server-rendered filters may place ordinary search text, released status, function, jurisdiction, sort, or comparison IDs in the URL. The JavaScript enhancement performs the same filtering and comparison locally. The page does not accept a person profile, upload, watchlist record, passenger record, police report, location, identity document, biometric, or live operational data.
No account, server-side saved comparison, analytics event, browser-local profile, persistent feedback-loop result, external API request, or runtime source crawl is created. Query terms and comparison IDs in a URL may still appear in browser history, copied messages, referrer handling, and ordinary hosting logs, so do not enter private or sensitive information.
The feedback-loop values are fictional aggregate teaching values. They are not a risk score, police forecast, crime estimate, or assessment of a real person, place, program, or jurisdiction.
The source-review page is server-rendered and publicly cacheable. Its optional JavaScript filters only records already present in the page and can copy a stable review URL after an explicit click. It does not crawl external sources, call a result API, create a cookie, use persistent browser storage, or retain a reader profile. Query-state filters may appear in browser history, referrers, or ordinary server logs.
The correction button opens the visitor’s configured email application with a fixed template addressed to mike@ns12.com. KillChains.com has no form processor or message database. The visitor’s mail provider and receiving mail infrastructure govern transmission and retention.
The Authority Casebook is server-rendered, publicly cacheable, and read-only. Optional JavaScript filters records already delivered in the page, limits comparison to three released cases, updates ordinary query presentation state, and creates no server-side result.
The feature creates no account, cookie, analytics event, persistent browser record, public edit, factual submission, or institutional profile. Search and comparison values may appear in browser history, referrers, or ordinary hosting logs, so readers should not enter private or sensitive material.
The Change Impact Explorer is server-rendered, publicly cacheable, read-only, and session-free. Its optional JavaScript filters review items already present in the page, adjusts which allowlisted event choices are shown, and copies a stable public preview URL only after an explicit click.
The page creates no account, cookie, server-side result, analytics event, correction submission, source crawl, registry edit, artifact regeneration, or persistent browser record. Selected source or claim IDs and event names may appear in browser history, referrers, copied links, and ordinary hosting logs. The selector accepts only released public IDs and does not accept arbitrary URLs or private evidence.
Accounts, multiuser sessions, voice, gaze, telemetry, persistent Human Control or Evidence Lab results, scenario uploads, crowdsourced Atlas submissions, AI-generated content, or cyber-range integrations would materially change this policy and should not be enabled without a new privacy review, consent model, retention schedule, access controls, and release update.
Privacy questions may be sent to mike@ns12.com.
The Machine Leadership Lab performs institution selection, authority assignment, responsibility comparison, and stress-test arithmetic only in page-local JavaScript memory. It does not use a PHP session, account, cookie, fetch(), XMLHttpRequest, WebSocket, EventSource, sendBeacon(), localStorage, sessionStorage, or IndexedDB.
The four institutions, authority maps, incidents, metrics, and outcomes are fictional and clear when the page is reloaded. The lab does not ingest company, government, municipal, employee, resident, financial, market, or operational data and cannot control an external organization.
The Claim Lineage Explorer is a server-rendered, publicly cacheable, read-only page. Its optional JavaScript filters records already delivered in the page, updates the selected public claim, changes ordinary query presentation state with history.replaceState, and copies a stable public URL only after an explicit click.
It creates no account, cookie, server-side result, analytics event, behavioral profile, public edit, correction submission, or persistent browser record. Search and selected-claim query values may appear in browser history, referrers, or ordinary hosting logs, so readers should not place private or sensitive material in them.
The Historical Change Ledger is server-rendered, read-only, session-free, and publicly cacheable. Optional JavaScript filters records already delivered in the page, limits comparison to three released events, and copies a stable internal event URL only after an explicit visitor action.
The page creates no account, public correction submission, persistent browser state, behavioral profile, runtime source request, or server-side result. Search and comparison values may appear in the address bar and ordinary host logs, so visitors should not place private information in them.
The Cross-Lab Concept Matrix is server-rendered and publicly cacheable. Its optional JavaScript filters the thirteen released concepts, renders a maximum-three comparison from records already delivered with the page, updates ordinary presentation query state, and copies a stable public URL only after an explicit visitor action.
The matrix creates no account, progress history, inferred profession, competence score, behavioral profile, analytics event, cookie, localStorage, sessionStorage, IndexedDB record, or server-side comparison. Search text and allowlisted concept IDs placed in a URL may still appear in browser history, copied links, referrer handling, or ordinary host logs, so do not enter private or sensitive information.
Links to KillWebs.com and the live Evulgare platform leave KillChains.com only after a deliberate click. KillChains.com does not transmit the visitor’s concept selections, simulation state, or lab results to either site.
The lab renders its complete synthetic claim case on the server and may use page-local JavaScript to change allowlisted claim, safeguard, assumption, owner, and change selections. It sends no result to KillChains.com, Evulgare, KillWebs, or another service and stores no persistent learner or assurance record.
Allowlisted query-state URLs may appear in browser history or ordinary hosting logs. They contain only fictional IDs and receive a nonindex directive. They contain no name, email, real incident, real system evidence, target, location, model artifact, credential, or liability conclusion.
The route is server-rendered, read-only, session-free, and publicly cacheable. Optional JavaScript compares only the allowlisted fictional snapshots already delivered with the page, filters claim changes, copies a stable URL, and creates a local JSON packet after an explicit action.
It creates no account, production evidence record, analytics profile, cookie, persistent browser state, upload, cross-site session, or server-side review result. Allowlisted snapshot IDs in the address bar may appear in browser history, copied links, referrers, or ordinary hosting logs, so visitors should not place private information in query values.
The route is server-rendered, session-free, read-only, and publicly cacheable. Optional JavaScript enforces only the local comparison limit, copies an allowlisted stable URL or text summary, and creates a local JSON file after explicit visitor action.
It creates no account, production evidence record, analytics profile, persistent browser state, upload, cross-site session, signature, certification, or server-side review result. Allowlisted query IDs may appear in browser history, referrers, copied links, or ordinary hosting logs.
The route is server-rendered, session-free, read-only, and publicly cacheable. Optional JavaScript limits allowlisted remediation selections, copies an allowlisted stable URL or accessible summary, and creates a local JSON result only after explicit visitor action.
It creates no account, upload, production evidence record, analytics profile, persistent browser state, public dispute submission, cross-site session, signature, correction acceptance, legal result, or server-side remediation branch. Query IDs may appear in browser history, referrers, copied links, or ordinary hosting logs.
The route is server-rendered, session-free, read-only, and publicly cacheable. Optional JavaScript filters records already delivered with the page, enforces the local comparison limit, copies an allowlisted stable URL or text summary, and creates a local JSON file only after explicit visitor action.
It creates no account, upload, public dispute, production evidence record, analytics profile, persistent browser state, cross-site session, signature, correction acceptance, legal result, or server-side ledger change. Allowlisted query IDs and search text may appear in browser history, referrers, copied links, or ordinary hosting logs.
The route is server-rendered, session-free, read-only, and publicly cacheable. Optional JavaScript filters the released synthetic audits, enforces a maximum-three comparison, copies an allowlisted stable URL or accessible summary, and creates a local JSON file only after explicit visitor action.
It creates no account, public audit submission, production evidence record, analytics profile, persistent browser state, upload, cross-site session, signature, certification, legal finding, or server-side effectiveness result. Allowlisted query IDs and search text may appear in browser history, referrers, copied links, or ordinary hosting logs.
The lab uses only released fictional records and page-local interaction. It creates no account, production monitoring record, public submission, analytics profile, persistent browser state, upload, write API, cross-site session, certificate, operational decision, or server-side reopening result.
Allowlisted branch, comparison, filter, and search values may appear in browser history, referrers, copied links, or ordinary hosting logs. Locally generated summaries and JSON remain under the visitor’s control unless the visitor deliberately saves or shares them.
The lab uses only released fictional records and page-local interaction. It creates no account, production monitoring record, public submission, analytics profile, persistent browser state, upload, write API, cross-site session, certificate, operational decision, or server-side coverage result.
Allowlisted branch, comparison, filter, and search values may appear in browser history, referrers, copied links, or ordinary hosting logs. Locally generated summaries and JSON remain under the visitor’s control unless deliberately saved or shared.
The drill uses only released fictional records and page-local interaction. It creates no account, database record, production monitoring configuration, real alert, public submission, analytics profile, persistent browser state, upload, write API, external action, cross-site session, certificate, operational decision, or server-side learner profile.
Allowlisted preset, branch, remediation, implementation-state, condition, and failure-injection values may appear in browser history, referrers, copied links, or ordinary hosting logs. Locally copied summaries and downloaded JSON remain under the visitor’s control unless deliberately saved or shared.