Trust is explained, not implied

A boundary you can read is stronger than an adjective.

This page separates observable website controls, documented product behavior, design direction and work that still requires independent verification.

Updated
01
Verified from the public surface

This website

livara.org is served over HTTPS and sends HSTS, content-type, framing, referrer, permissions and content-security headers. Contact submissions are validated on the server, use an origin-bound CSRF token, a honeypot and rate controls.

    These controls reduce specific risks; they do not prove that the website or any product is secure against every threat.

    02
    Product boundary

    Livara Chat

    Livara Chat encrypts on the client. Direct-message text, edits, captions and attachments use LVR1, a hybrid ratchet that mixes ML-KEM-768 with P-256 and advances the key before every send; compatible private-group text, edits and attachment keys use LGS1 sender keys. Channel content is not covered and stays readable by the server. Calls carry WebRTC DTLS-SRTP media with pairwise-sealed signalling, which is not itself post-quantum. Sign-in uses SRP, so the password never travels; the key backup needs a recovery phrase as well. Routing, membership, timestamp, ciphertext size and delivery metadata remain part of the platform.

    • Direct messages and compatible private groups: end-to-end encrypted
    • Channels: server-readable, and labelled that way
    • Calls: DTLS-SRTP media, sealed signalling, not post-quantum
    • Group membership is server-supplied, so a compromised server could insert a member
    • Routing, membership and timing metadata: server-visible
    • LVR1 and LGS1 are custom protocols with no external audit claimed by this site
    03
    Product boundary

    Dr. Livara

    Implemented foundation scopes document forced PostgreSQL row-level isolation, server-resolved tenant context and minimized tamper-evident audit evidence. Protected capabilities are default-off on the public project host.

    • No healthcare approval or clinical validation claimed
    • Not a diagnostic replacement
    • Production activation requires independent legal, clinical, privacy, security and operational review
    04
    No implied proof

    What is not claimed

    Livara does not claim an independent product security audit, certification, production SLA, healthcare approval, deployment count or absolute security guarantee. Product evaluation must review the exact released build and operating environment.

      05
      Responsible disclosure

      Report a vulnerability

      Send a concise report to [email protected]. Include the affected URL or component, reproducible steps, impact and a safe contact channel. Do not access other people’s data, degrade service or test with real medical information.

        We aim to acknowledge complete reports within five working days. This is a target, not an SLA, and no bug bounty is offered.

        Canonical product detailchat.livara.org/security ↗Dr. Livara boundary
        Start with the real constraint

        Something important needs to work better.

        Tell us about the product, workflow, or system you are trying to build.

        Start a conversation