Bilingual Next.js website for practical one-to-one AI education: adults, AI builders, teams, kids 8–13 and teens 14–18.
The current public static release exposes two deliberate contact paths on /start / /en/start:
- First-party application form (current public mode) — the browser submits JSON only to same-origin
/api/lead.deploy/live/vercel.jsonproxies that path to the separately deployedai-skill-lab-ingressservice. The public static project owns no webhook/signing secret. - Direct-contact fallback — Telegram, email, WhatsApp and LINE remain available if the form cannot be used. Youth applications and organizational communication use an adult contact only.
- Isolated ingress authority — operator identity, privacy contact, jurisdiction, allowlisted origins, 30-day retention, rate-limit readiness, webhook URL and signing secret are provisioned and verified on the ingress project, not the public static project.
NEXT_PUBLIC_LEAD_FORM_ENABLED=true remains an ENV-bound Next-runtime capability and is not public static-release authority. The public form is activated only by the committed static release plus required static-release QA and a separately approved production release.
The canonical production host is https://aiskillab.work. The legacy public Vercel hostname https://ai-skill-lab.vercel.app is routing compatibility only and must permanently redirect to the canonical host while preserving the requested path.
- RU:
/,/about,/build,/business,/challenge,/curriculum,/family,/faq,/kids,/matcher,/method,/parents,/personal,/phuket,/pricing,/privacy,/projects,/proof,/safety,/start,/studio,/teens,/terms - EN:
/en,/en/about,/en/build,/en/business,/en/challenge,/en/curriculum,/en/family,/en/faq,/en/kids,/en/matcher,/en/method,/en/parents,/en/personal,/en/phuket,/en/pricing,/en/privacy,/en/projects,/en/proof,/en/safety,/en/start,/en/studio,/en/teens,/en/terms
NEXT_PUBLIC_SITE_URL=https://aiskillab.work
NEXT_PUBLIC_TELEGRAM_URL=https://t.me/BiTFormer
NEXT_PUBLIC_WHATSAPP_URL=
NEXT_PUBLIC_LEAD_FORM_ENABLED=falseThe .env.example block above is for the optional Next.js runtime and defaults its form flag to false. The committed public static release does not require public-project ENV values for the form. Private receiver/signing configuration belongs only to services/lead-ingress/.env.example and the isolated ingress project.
The lead payload schema is ai-skill-lab.lead.v2. The ingress signs the exact downstream JSON body with its private signing secret; that secret is never shipped in the public static release.
Required repository release QA is the static-release workflow. On a fresh checkout, install the locked npm dependency graph before running the local read-only equivalent:
npm ci --ignore-scripts --audit=false --fund=false
python scripts/preflight_release.py --release <receipt-label>R87 intentionally quarantines the ENV-bound launch checker from required and operator release surfaces. It remains repository evidence only and is not an operator release command. Lead-form mode still requires real operator/legal/webhook configuration before deployment; those deployment-specific values are not part of static release QA.
Root-level R*_READINESS.md files are historical evidence snapshots from earlier release epochs. They are not current operator instructions, release authority, production-state authority, or approval to run legacy commands. Do not execute commands or rely on deployment/status claims from those files as current truth. Current repository release authority is the required static-release workflow and the local read-only preflight above.
- Youth applications/communication use an adult contact.
- The site does not request a child’s own phone/email/messenger contact.
- For educational use with a child under 13, ChatGPT interaction is adult-conducted.
- Users under 18 require parent/guardian permission for ChatGPT, and provider age rules are rechecked before use.
No fabricated testimonials, student counts, income claims or unverified instructor biography are included.
- Historical R7 state used a no-form lead brief; the current D6 release adds the first-party form while preserving the brief and direct-contact fallback.
/aboutand/en/aboutmake the teaching method and claims discipline explicit.- Static release adds skip navigation, focus-visible treatment, reduced-motion handling and a real 404 page.
- No testimonials, student counts or outcome guarantees were added.
/projectsand/en/projects: example outcome formats, explicitly not client case studies./parentsand/en/parents: buyer-facing progress rubric, age/safety framing and family decision support.- Public youth age wording remains aligned with current OpenAI guidance and is linked to the official Help Center from the static parent page.
/pricingand/en/pricing: transparent package comparison without checkout./methodand/en/method: transferable learning method and verification loop./phuketand/en/phuket: honest Phuket-by-arrangement + online worldwide positioning without claiming a permanent venue.- Header pricing links now use dedicated routes; footer links expose pricing, method and location pages.
Historical R10 removed the first-party form from public routes. The current D6 static release supersedes that contact-only state after the isolated ingress, legal/privacy configuration, rate limit and enabled-branch E2E were separately verified.
- Added
/faqand/en/faqwith visible buyer questions/answers. - Added minimal
WebSite+EducationalOrganizationJSON-LD to the root home page without inventing legal/address details. - Kept structured data limited to claims visible on the site; no fake reviews, ratings or FAQ rich-result promises.