AHDRC uses first-party browser storage for authentication, security and user-requested preferences. AHDRC does not currently use analytics, advertising or behavioural-profiling cookies. Protected authentication forms also use Cloudflare Turnstile as a necessary anti-bot security service.
Turnstile processes security signals including the client IP address, TLS fingerprint, User-Agent header, sitekey and associated origin. Cloudflare states that these signals are used for bot detection and blocking rather than to identify, profile or target individuals. See Cloudflare's Turnstile Privacy Addendum.
The comparison cookie is encrypted and authenticated with ASP.NET Core Data Protection and is HttpOnly, Secure, SameSite=Lax, essential and host/path scoped. Authentication, 2FA and antiforgery cookies are likewise configured with security-focused cookie attributes appropriate to their function.
AHDRC does not currently deploy analytics, advertising or behavioural-profiling storage. If optional tracking or analytics is introduced later, it must be assessed and, where required, blocked until the applicable consent mechanism is in place.