Security

Security controls built into the application foundation.

UserArchitect is designed for controlled research workspaces and participant data capture on standard PHP and MySQL hosting.

Role-based access

Workspace membership separates owners, administrators, researchers and viewers.

Password security

Passwords are stored using PHP’s password hashing API and authenticated sessions use secure cookie settings.

Request protection

Administrative write actions use CSRF tokens, output is escaped and database access uses prepared statements.

Upload controls

Uploaded research images are MIME-validated, size-limited and stored where executable server-side files are blocked.

Privacy-aware sessions

Participant IP addresses are represented as salted hashes rather than stored as raw addresses.

Live-site origin checks

The live testing API only permits browser origins matching the configured target site for the study.

Audit trail

Administrative actions such as sign-in, study creation and status changes are recorded in an audit log.

Transport security

The supplied deployment configuration expects HTTPS and redirects application traffic to TLS when enabled.

Security also depends on the cPanel account, PHP/MySQL patching, TLS configuration, backups and operational access controls. A production deployment should be reviewed against your organisation’s security and privacy requirements before collecting real participant data.