A boundary you can read is stronger than an adjective.
This page separates observable website controls, documented product behavior, design direction and work that still requires independent verification.
UpdatedThis website
livara.org is served over HTTPS and sends HSTS, content-type, framing, referrer, permissions and content-security headers. Contact submissions are validated on the server, use an origin-bound CSRF token, a honeypot and rate controls.
These controls reduce specific risks; they do not prove that the website or any product is secure against every threat.
Livara Chat
Livara Chat uses client-side end-to-end encryption for direct messages, group messages, channels and calls. New direct content uses the documented hybrid ML-KEM-768 and P-256 design; group, channel and call modes may use their own compatible key and transport layers. Routing, membership, timestamp and delivery metadata remains part of the platform.
- Direct, group and channel content: end-to-end encrypted
- Calls: end-to-end encrypted
- Routing and membership metadata: server-visible
- No external audit claimed by this site
Dr. Livara
Implemented foundation scopes document forced PostgreSQL row-level isolation, server-resolved tenant context and minimized tamper-evident audit evidence. Protected capabilities are default-off on the public project host.
- No healthcare approval or clinical validation claimed
- Not a diagnostic replacement
- Production activation requires independent legal, clinical, privacy, security and operational review
What is not claimed
Livara does not claim an independent product security audit, certification, production SLA, healthcare approval, deployment count or absolute security guarantee. Product evaluation must review the exact released build and operating environment.
Report a vulnerability
Send a concise report to [email protected]. Include the affected URL or component, reproducible steps, impact and a safe contact channel. Do not access other people’s data, degrade service or test with real medical information.
We aim to acknowledge complete reports within five working days. This is a target, not an SLA, and no bug bounty is offered.
Something important needs to work better.
Tell us about the product, workflow, or system you are trying to build.
