Production legal review: This structured draft reflects the approved site architecture and core trust principles. Counsel should confirm jurisdiction-specific language before public launch.

Public site

The website uses same-origin form submission, CSRF protection, timing and honeypot checks, server-side validation, rate limiting and security headers.

Credentials

SMTP and other secrets are configured outside public files and must never be committed to JavaScript or the web root.

Portals

Confidential areas require server-side authorization, secure session management, role-based permissions, logging and protected storage.

Sensitive data

The public site is not intended to collect patient information or protected health information.

Responsible disclosure

Researchers should report suspected vulnerabilities privately through the production security contact and avoid accessing, modifying or retaining real data.

Operations

Patching, backups, monitoring, least privilege and incident response remain ongoing deployment responsibilities.

Last reviewed

2026-07-21