UserArchitect is designed for controlled research workspaces and participant data capture on standard PHP and MySQL hosting.
Workspace membership separates owners, administrators, researchers and viewers.
Passwords are stored using PHP’s password hashing API and authenticated sessions use secure cookie settings.
Administrative write actions use CSRF tokens, output is escaped and database access uses prepared statements.
Uploaded research images are MIME-validated, size-limited and stored where executable server-side files are blocked.
Participant IP addresses are represented as salted hashes rather than stored as raw addresses.
The live testing API only permits browser origins matching the configured target site for the study.
Administrative actions such as sign-in, study creation and status changes are recorded in an audit log.
The supplied deployment configuration expects HTTPS and redirects application traffic to TLS when enabled.