Mahlis Security Policy
Mahlis treats security as an operating requirement. This page explains public principles without publishing credentials, private infrastructure details or instructions that would weaken the service.
What we protect
The website is designed to protect public-content integrity, contact submissions, protected accounts, authenticated sessions, administrative records, release evidence, backups and credentials.
Current controls
The application uses controls including:
- Environment-based secrets
- Production configuration validation
- Password hashing
- Server-side sessions
- Secure cookie settings in production
- Cross-site request forgery protection
- Login rate limiting
- Allowlisted public routes
- Sanitized Markdown rendering
- Parameterized database operations
- Request-size limits
- Browser security headers
- Controlled database migrations
- Backup and release verification
Security controls are reviewed and tested; their existence does not guarantee that every vulnerability has been discovered.
Responsible reporting
Use the contact page to report a suspected security issue. Provide the affected component, a clear description, safe reproduction steps and potential impact.
Do not include stolen credentials, patient information, destructive demonstrations or data obtained without authorization. Do not publicly disclose an unresolved issue before Mahlis has had a reasonable opportunity to investigate and respond.
Product boundary
The public website is not a clinical system and does not store patient records. Future Mahlis products require separate threat models, verification evidence and release decisions appropriate to their intended use.
Compliance-readiness documentation supports preparation. It does not, by itself, establish certification, attestation or regulatory approval.