01
01 / ArchitectureA static-first public information service.
The production build contains static pages and assets delivered through Cloudflare. There is no website database, authentication system, checkout, patient portal or general contact-form backend in the current release.
02
02 / Browser and edge controlsRestrictive headers and limited browser permissions.
Production responses use content-type protection, framing restrictions, referrer controls, a content security policy and a permissions policy that disables unnecessary device capabilities. Cloudflare provides TLS delivery, edge caching and traffic security controls.
03
03 / Data minimizationSecurity also means collecting less.
The site avoids accounts, patient information, online payments, advertising trackers and form databases. Language preferences are stored locally. Reducing stored personal information reduces the consequences of application-layer compromise.
04
04 / Reporting a concernProvide enough detail without exposing data.
Security concerns may be initiated through the Contact route until a verified dedicated security mailbox is published. Include the affected URL, observed behaviour, date, browser and safe reproduction steps. Do not access, download, retain or transmit personal, confidential or patient data.
05
05 / Responsible testingAvoid disruption, persistence and social engineering.
Do not perform denial-of-service testing, automated high-volume scanning, credential attacks, persistence, malware deployment, social engineering or testing against third-party services. Stop testing if sensitive information is encountered and report the issue without including that information.
06
06 / Response boundariesReports are assessed against evidence and scope.
Lucius may request clarification, reproduce the issue, prioritize remediation and coordinate disclosure timing. This statement does not create a bug-bounty programme, payment obligation or authorization to test systems beyond the public Lucius website.