Security + deployment
One public directory. Separate clinical boundaries.
Okairah Health is deliberately limited to organization routing and public evaluation material. It is not a clinical tenant, identity provider, or clinical data plane.
Current public surface
The directory has a deliberately narrow job.
Bounded request
One small URL-encoded organization-code field; other body shapes fail closed.
Exact routing
Server-side configuration maps a code only to its exact validated HTTPS origin.
No directory database
The public application has no patient store, user account store, or lead database.
Browser restrictions
Security headers restrict framing, objects, device permissions, and form destinations.
Public demonstration
Synthetic means synthetic only.
The public Clinical workspace is intended only for supplied synthetic scenarios. It is not connected to production hospital identity, EHR, database, storage, or delivery systems.
Do not enter patient names, medical record numbers, recordings, encounter information, or any other protected or sensitive clinical data.
Open the clearly labeled synthetic demoProduction direction
A hospital boundary is intended to stand alone.
A future PHI-capable deployment is intended to own its application runtime, identity integration, database, storage, keys, audit records, backups, recovery process, and release authority.
No PHI-capable deployment should begin until its clinical, privacy, security, legal, operational, and recovery gates have been approved.
Include security in a technical reviewResponsible disclosure
Report a suspected security issue privately.
Email support@okairah.com with the affected public URL, a concise description, and safe reproduction steps. Never include PHI, credentials, or exploit data belonging to others.