What partners can evaluate today
The public portal is intended to help interested researchers, educators, institutions, and civic-science collaborators understand the research workflow before any private application or partnership process exists.
Public demo versus selective-access application
| Surface | Public demo today | Selective-access application would require |
|---|---|---|
| Identity | No accounts, reviewer authentication, institutional login, or access review. | Verified researcher or institution identity, access terms, role boundaries, and account controls. |
| Data | Local browser imports and exports; no public portal collection of observations or restricted datasets. | Documented data-use terms, dataset rights review, storage policy, retention policy, and restricted-data handling. |
| Submissions | Labels, sessions, reviewer packets, and evidence bundles are local downloadable artifacts. | Authenticated intake, transport security, queue routing, audit logs, reviewer assignment, and operational ownership. |
| Review | Observation review, QA metrics, and adjudication queues are local research-workflow surfaces. | Defined reviewer roles, conflict handling, escalation policy, consensus/adjudication rules, and monitoring. |
| Security | Static public portal with security disclosure route, CI, CodeQL, and no production service claims. | Threat model, vulnerability handling, access logging, secrets management, incident response, and deployment controls. |
| Claims | Research-only evidence infrastructure; diagnostic placeholders are not validated scientific outputs. | Any scientific claim would need protocol design, validation evidence, uncertainty analysis, and reproducible review. |
Readiness gates before private sharing
Before COSMOS-CQA is shared as a selective-access application, these gates should be resolved outside the static public demo.
Access terms
Define who may use the application, what verification means, what roles exist, and how access can be suspended or revoked.
Data terms
Clarify allowed datasets, attribution, redistribution limits, retention, export rules, and restricted-data exclusions.
Security controls
Document authentication, authorization, audit logging, vulnerability reporting, dependency review, and incident response.
Review operations
Define reviewer intake, queue routing, QA review, adjudication semantics, escalation, and disagreement handling.
Research protocol
Separate observation, label, evidence, caveat, and claim. Any protocol involving human contributors may require ethics or institutional review.
Evidence export
Preserve validation reports, SBOM references, provenance hashes, session replay, and partner-specific archive requirements.
What is not offered through the public page
- No public account creation, researcher onboarding, institutional access, API keys, hosted reviewer queue, or live observation submission is available here.
- No production, clinical, regulatory, operational, or validated cosmology diagnostic claim is made.
- No timeline, partnership acceptance, funding commitment, data-use agreement, confidentiality, or support obligation is implied by viewing or contacting through this page.
- No restricted dataset, private credential, personal health information, regulated data, or sensitive security detail should be submitted through public GitHub issues or public email.
How to start a responsible conversation
Use the contact route for a short non-confidential note. The most useful first message explains the research or education context, the kind of institution or group involved, the data sensitivity level, the workflow you want to evaluate, and whether accessibility, safety, or security constraints are already known.
Suggested subject: COSMOS-CQA partner-readiness inquiry. Keep the first message non-confidential and do not attach restricted datasets or sensitive security details.