Trust

Security without theater.

Statera treats security, privacy, authorization, and auditability as product behavior. We do not use this page to imply a certification or assurance we have not earned.

Design commitments

Controls should constrain real behavior.

Identity and least privilege

Access is designed around named identities, strong authentication, limited permissions, and separation of duties where risk warrants it.

Authorization before execution

A system’s technical capability does not grant permission. Material actions require the applicable purpose, authority, and recorded approval.

Traceable decisions

Security-relevant changes and governed actions are designed to produce durable evidence for review, investigation, and correction.

Responsible disclosure

Report a security concern.

Send a concise initial description to security@statera.systems. Do not include exploit code, patient information, credentials, or other sensitive data in the first message.

Please do

  • Identify the affected domain, page, or product area.
  • Describe the observed behavior and plausible impact.
  • Provide a safe way to reproduce the issue, if available.
  • Allow us to establish an appropriate channel before sharing sensitive material.

Boundaries for testing

Do not access, alter, retain, or disclose data that is not yours. Do not disrupt services, impersonate users, evade access controls, or test production systems beyond what is necessary to describe a suspected issue. This page does not create a bug bounty or authorize activity that would otherwise be unlawful.