Security
Secure by design. Not unhackable.
Elaryvo holds professional records, so access control, private storage and least privilege are product requirements. No serious product can promise that it cannot be attacked.
- Server-side authorisation — hiding a button is not a control.
- Doctors see their own records. Organisations do not own the career.
- Invite tokens are high-entropy. Assessments lock after submit.
- Admin access is allowlisted on the server.
Elaryvo has not yet completed an independent penetration test. We will not describe the product as independently tested until that work is done and serious findings are fixed.
To report a vulnerability, use the contact in /.well-known/security.txt. Do not include patient information.