Deployment and privacy

The canonical URL is https://mc.keff.uk. Cloudflare Workers Static Assets serves the Vite build, public nuclear data, documentation, and preview image. A read-only Worker supplies Markdown negotiation, canonical/discovery Link headers, caching, and security headers. It has no simulation endpoint and accepts only GET or HEAD.

Workers Static Assets was selected instead of a plain Pages upload so the same public documentation URL can respond to Accept: text/markdown. Simulation transport, geometry, tallies, and rendering remain entirely in the browser. Observability is disabled in the Worker configuration. Ordinary asset requests reach the hosting provider; private calculation state does not.

npm ci
npm run verify
npm run test:browser
npm run deploy:check
npm run deploy
npm run audit:production

Wrangler uses an authenticated Cloudflare account with the keff.uk zone and Workers custom-domain permission. The configuration explicitly binds mc.keff.uk. No deployment credentials are committed. HTTPS and HSTS protect the public site. COOP/COEP headers support isolated GPU resources; all required assets are same-origin. CSP allows the application bundle and exact hashes of its static structured metadata. The social image and metadata are present without executing JavaScript.

Hashed application assets receive immutable caching. Nuclear-data binaries and preview images cache for one day; informational content caches for five minutes. Data manifests carry SHA-256; the loader rejects a mismatch. Treat an evaluated dataset ID as immutable and issue a new ID/path for a changed dataset. SPA fallback serves application routes; absent machine-readable resources return 404, not an HTML page mislabeled as an API.

Saved configurations use browser local storage. File import is user initiated. Results live in GPU buffers and local application state until explicit export. There is no analytics, remote simulation storage, account system, or hosted agent execution. Agent mutation and field export require consent for the current tab; reload clears that consent.

Production verification records are generated by scripts/production-audit.ts. The Cloudflare Agent Readiness checker result is recorded separately after a live scan. Checks for payments, OAuth, and a hosted MCP server are outside this application's public surface and are not implemented to inflate a score.

Recorded public checks

On 9 October 2026, the live HTTPS audit passed 18 checks covering canonical metadata, Markdown responses, discovery, security headers, nuclear-data assets, social-image dimensions, missing-resource behavior, and rejection of POST requests. Chromium also executed all six presets against the public deployment on an Intel Gen-9 adapter; the 22 browser observations include controls, GPU-rendered pixels, accessibility, responsive layout, and local-state privacy.

The Cloudflare Agent Readiness checker passed all seven selected applicable checks: robots.txt, sitemap, Link headers, Markdown negotiation, AI crawler rules, Content Signals, and Agent Skills discovery. It displayed 100 for this partial scan of 7 of 20 checks. This is not a full-framework score. The raw result is recorded separately, alongside the production audit and browser record.