Identity and least privilege
Access is designed around named identities, strong authentication, limited permissions, and separation of duties where risk warrants it.
Trust
Statera treats security, privacy, authorization, and auditability as product behavior. We do not use this page to imply a certification or assurance we have not earned.
Design commitments
Access is designed around named identities, strong authentication, limited permissions, and separation of duties where risk warrants it.
A system’s technical capability does not grant permission. Material actions require the applicable purpose, authority, and recorded approval.
Security-relevant changes and governed actions are designed to produce durable evidence for review, investigation, and correction.
Responsible disclosure
Send a concise initial description to security@statera.systems. Do not include exploit code, patient information, credentials, or other sensitive data in the first message.
Do not access, alter, retain, or disclose data that is not yours. Do not disrupt services, impersonate users, evade access controls, or test production systems beyond what is necessary to describe a suspected issue. This page does not create a bug bounty or authorize activity that would otherwise be unlawful.