Public site
The website uses same-origin form submission, CSRF protection, timing and honeypot checks, server-side validation, rate limiting and security headers.
Credentials
SMTP and other secrets are configured outside public files and must never be committed to JavaScript or the web root.
Portals
Confidential areas require server-side authorization, secure session management, role-based permissions, logging and protected storage.
Sensitive data
The public site is not intended to collect patient information or protected health information.
Responsible disclosure
Researchers should report suspected vulnerabilities privately through the production security contact and avoid accessing, modifying or retaining real data.
Operations
Patching, backups, monitoring, least privilege and incident response remain ongoing deployment responsibilities.
Last reviewed
2026-07-21