Research Tools

Security and data protection

Participant data should be collected deliberately, not casually.

This page summarizes the operating model for hosted studies and saved inventory accounts. Formal terms, ethics approvals and institution-specific data-processing requirements should still be agreed before paid collection begins.

Account data

  • Passwords are stored as bcrypt hashes, never plain text.
  • Verification links are sent before saved results become available.
  • Participants can contact support directly from account pages.

Research responses

  • Participant links and session codes keep study responses structured.
  • Public displays should use aggregate statistics, not individual records.
  • Exports should use explicit column projections for analysis.

Clinical language

  • Inventories are screening and research aids only.
  • Pages should not claim diagnosis, treatment or clinical certainty.
  • High-risk wording should route users toward qualified help.

Deployment controls

  • HTTPS, redirects and canonical hosts should be verified before launch.
  • Admin, API and response files should stay blocked from indexing.
  • SMTP, database and payment secrets should be rotated when exposed.
For institutional projects: confirm ethics approval language, consent copy, data retention, export format, access roles, support mailbox and deletion process before recruitment starts.
Discuss data handlingView launch options