Security from the foundation

Modern access and data controls for high-trust workflows.

Lexa combines identity security, clinic-scoped authorization, protected sessions, request controls, file safeguards, and operational visibility.

Access and data controlsDEFENCE IN DEPTH
PasskeysWebAuthn sign-in
Two-factor authAuthenticator app TOTP
Role permissionsClinic-scoped access
Secure sessionsTracking and locking
Request controlsCSRF and rate limits
Signed file linksTime-limited downloads
Layered controls

Security across the platform lifecycle

Controls are applied at identity, clinic, request, storage, and operational layers instead of relying on a single perimeter.

01

Identity protection

Argon2 password hashing, email verification, password recovery, passkeys, authenticator app 2FA, and secure login flows.

02

Role-aware authorization

System roles remain separate from clinic membership roles, with clinic-level checks and fine-grained assistant permissions.

03

Session controls

Valkey-backed sessions support tracking, expiry, active-session visibility, auto logout, and session locking.

04

Protected requests

Security headers, CSRF protection, rate limiting, schema validation, and authenticated service boundaries reduce request risk.

05

Patient file safeguards

Role-aware upload and access rules, storage quotas, isolated S3 paths, and expiring signed download URLs protect files.

06

Operational visibility

Audit-focused admin tools, service health, logs, metrics, feature flags, and privacy-aware filtering support responsible operation.

How access is resolved

The right user, clinic, role, and action

01AuthenticateVerify the user and establish a protected session.
02Resolve clinicIdentify the clinic context for the requested workflow.
03Check membershipConfirm clinic membership roles and permissions.
04Authorize actionAllow only the data and operation appropriate to that role.
Security scope during development

Lexa is still in active development. These controls describe the current architecture and implemented safeguards, not a claim of completed certification, compliance, or production availability. Security testing and operational hardening continue as the platform moves toward staging and production.

Track the path to production

Review what is active in development, what is still being completed, and what comes next.

View build status