Identity protection
Argon2 password hashing, email verification, password recovery, passkeys, authenticator app 2FA, and secure login flows.
Lexa combines identity security, clinic-scoped authorization, protected sessions, request controls, file safeguards, and operational visibility.
Controls are applied at identity, clinic, request, storage, and operational layers instead of relying on a single perimeter.
Argon2 password hashing, email verification, password recovery, passkeys, authenticator app 2FA, and secure login flows.
System roles remain separate from clinic membership roles, with clinic-level checks and fine-grained assistant permissions.
Valkey-backed sessions support tracking, expiry, active-session visibility, auto logout, and session locking.
Security headers, CSRF protection, rate limiting, schema validation, and authenticated service boundaries reduce request risk.
Role-aware upload and access rules, storage quotas, isolated S3 paths, and expiring signed download URLs protect files.
Audit-focused admin tools, service health, logs, metrics, feature flags, and privacy-aware filtering support responsible operation.
Lexa is still in active development. These controls describe the current architecture and implemented safeguards, not a claim of completed certification, compliance, or production availability. Security testing and operational hardening continue as the platform moves toward staging and production.
Review what is active in development, what is still being completed, and what comes next.
View build status