Trust is explained, not implied

A boundary you can read is stronger than an adjective.

This page separates observable website controls, documented product behavior, design direction and work that still requires independent verification.

Updated
01
Verified from the public surface

This website

livara.org is served over HTTPS and sends HSTS, content-type, framing, referrer, permissions and content-security headers. Contact submissions are validated on the server, use an origin-bound CSRF token, a honeypot and rate controls.

    These controls reduce specific risks; they do not prove that the website or any product is secure against every threat.

    02
    Product boundary

    Livara Chat

    Livara Chat uses client-side end-to-end encryption for direct messages, group messages, channels and calls. New direct content uses the documented hybrid ML-KEM-768 and P-256 design; group, channel and call modes may use their own compatible key and transport layers. Routing, membership, timestamp and delivery metadata remains part of the platform.

    • Direct, group and channel content: end-to-end encrypted
    • Calls: end-to-end encrypted
    • Routing and membership metadata: server-visible
    • No external audit claimed by this site
    03
    Product boundary

    Dr. Livara

    Implemented foundation scopes document forced PostgreSQL row-level isolation, server-resolved tenant context and minimized tamper-evident audit evidence. Protected capabilities are default-off on the public project host.

    • No healthcare approval or clinical validation claimed
    • Not a diagnostic replacement
    • Production activation requires independent legal, clinical, privacy, security and operational review
    04
    No implied proof

    What is not claimed

    Livara does not claim an independent product security audit, certification, production SLA, healthcare approval, deployment count or absolute security guarantee. Product evaluation must review the exact released build and operating environment.

      05
      Responsible disclosure

      Report a vulnerability

      Send a concise report to [email protected]. Include the affected URL or component, reproducible steps, impact and a safe contact channel. Do not access other people’s data, degrade service or test with real medical information.

        We aim to acknowledge complete reports within five working days. This is a target, not an SLA, and no bug bounty is offered.

        Canonical product detailchat.livara.org/security ↗Dr. Livara boundary
        Start with the real constraint

        Something important needs to work better.

        Tell us about the product, workflow, or system you are trying to build.

        Start a conversation