Public access verification
Status: verified
Build: beauty-evidence-hub-2026-07-28.3
Published: 2026-07-28T11:57:30.000Z
Verified: 2026-07-28T11:57:30.000Z
Problems found
- The prior robots.txt used Disallow: /, which told retrieval systems not to fetch any evidence route.
- The prior response headers added X-Robots-Tag: noindex, nofollow, noarchive, which unnecessarily discouraged link traversal.
- The prior completion page used relative artifact links instead of the required absolute public URLs.
- The prior artifact routes were client-side meta-refresh wrappers rather than directly readable evidence documents.
- The prior package did not expose /completion/plain/ or /completion/qa-summary.json.
- The prior public handoff had not published a URL-by-URL cookie-free and clean-browser verification report.
- The prior host injected a bot-management cookie and challenge script even when no challenge was displayed.
- The first relay pass stripped inert JSON-LD together with executable scripts, weakening the public SEO evidence.
- Cloudflare Managed robots.txt replaced the reviewed allow-all file with AI-crawler disallow directives.
- Cloudflare's deprecated zone-wide Block AI bots setting returned a 403 block page to ChatGPT's user-directed retrieval agent before the request reached the evidence relay.
Corrections made
- Allowed retrieval of the fictional-only public evidence package while preserving noindex and noarchive.
- Removed nofollow from the public evidence metadata and response headers.
- Placed all fourteen absolute artifact URLs directly in the initial /completion/ HTML.
- Replaced meta-refresh wrappers with complete static copies of the underlying sanitized evidence documents.
- Rewrote document, image, stylesheet, script, and related-file references to absolute HTTPS URLs.
- Added a framework-free /completion/plain/ fallback and a public application/json QA endpoint.
- Kept the evidence package isolated from customer, administrative, billing, domain, outreach, and deployment systems.
- Added a dedicated allowlisted evidence relay that emits no cookies, challenges, executable scripts, or upstream implementation headers.
- Preserved only inert application/ld+json structured data while removing executable and injected challenge scripts.
- Added exact route and content-manifest digests, fixed MIME types, deterministic upstream request headers, and stale-manifest deployment checks.
- Disabled Cloudflare's Managed robots.txt override so the reviewed User-agent: * / Allow: / policy is served byte-for-byte.
- Disabled Cloudflare's deprecated zone-wide AI-crawler block after confirming it prevented user-directed ChatGPT retrieval; the evidence relay's exact read-only path allowlist remains the publication boundary.
- Repeated retrieval checks with browser, ChatGPT-User, GPTBot, ClaudeBot, and PerplexityBot user agents and confirmed the real static evidence is returned without cookies or challenges.
Retrieval-agent compatibility
| User agent tested | Purpose | Status | Cookie? | Challenge? |
|---|---|---|---|---|
| Mozilla/5.0 | ordinary browser control | 200 | no | no |
| ChatGPT-User/1.0 | user-directed ChatGPT retrieval | 200 | no | no |
| GPTBot/1.0 | OpenAI crawler compatibility | 200 | no | no |
| ClaudeBot/1.0 | representative third-party AI crawler compatibility | 200 | no | no |
| PerplexityBot/1.0 | representative AI search compatibility | 200 | no | no |
URL-by-URL results
| Public URL tested | Initial | Final | Redirect chain | Content type | Auth? | JS? | Incognito | Cookie-free | Artifact links | Broken links | Missing images | Privacy |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| https://evidence.cauldronideations.com/completion/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 14 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/completion/plain/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 14 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/completion/qa-summary.json | 200 | 200 | none | application/json; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 0 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/qa-gallery/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/architecture/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/fidelity-ledger/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/migration/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/generator-lab/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/machine-qa-summary/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/gold/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/worst/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/rejected/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/current-v2/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/content-normalized/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/structure-only/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/tests/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
| https://evidence.cauldronideations.com/performance/ | 200 | 200 | none | text/html; charset=utf-8 | no | no | pass — opened directly in a fresh extension-free Chrome incognito profile | pass | 1 | 0 | 0 | pass |
Verification method
Every primary URL was fetched without cookies through the public Cloudflare edge, followed through redirects, checked for status and MIME, crawled for broken same-origin links and assets, scanned for private references and secret patterns, and checked for authentication or bot challenges. Each URL was then opened directly in a fresh Chrome incognito profile with extensions disabled; all 17 loaded, the JSON parsed, and the plain fallback passed with JavaScript disabled. A separate retrieval-agent sweep confirmed that the user-directed ChatGPT fetcher and representative GPTBot, ClaudeBot, and PerplexityBot user agents receive the same static evidence rather than a Cloudflare block page.