Operations
Security and data protection
Scope
The platform is not tenant-isolated and not approved for production PHI or partner-confidential inputs. Do not load patient data into an evaluation install.
Network exposure
- Loopback only. Native services listen on
127.0.0.1. In Docker, ports are published to127.0.0.1on the host only. - Mutation routes and selected PHI-like reads need a local bearer token, printed by
livemore token. - Browser sessions authorize through a same-origin bootstrap and an
HttpOnly,SameSite=Strictcookie.
Local storage
- Owner-only data directory.
~/.livemoreholds the API token and both patch keys, and is kept at mode0700.livemore doctorchecks it. - The product enforces 32 owner-only checks across the registry, execution and evidence stores, protocol runs, model assets, anatomy cache and patch journal.
- Encryption at rest. Patch journals, bus events and snapshots are encrypted with an owner-only AES-256-GCM key generated at first start.
- Windows is refused natively because owner-only POSIX permissions cannot be expressed there. Use Docker.
Supply chain
- The native installer checks the release archive's SHA-256 before unpacking, installs hash-locked dependencies and verifies model assets byte for byte.
- The Docker image uses the same hash-locked dependencies and runs the test suite while it builds.
- The Docker and manual paths download the archive with
curl | tar, so check it againstlivemorebio-stable.tar.gz.sha256yourself. - For the native installer, pin the build with
LIVEMORE_SHA256to refuse anything but the exact published archive.
Third-party sources
Commercially restricted sources (for example KEGG, GeneCards and Recon3D) fail closed without entitlement. Recon3D is not activated because of its non-commercial restrictions. KEGG and GeneCards stay behind entitlement gates and are never scraped.
Reporting a security issue
Email us the release you are running (stable 6588707) and the output of livemore doctor --json, which contains check outcomes and local tool paths, never your data.
Questions about this page?
Email us