Skip to main content
Security & data protection

Built for sensitive research data

Interviews and focus groups hold some of the most sensitive data your participants will ever share. Resonance is engineered so that protecting it isn't an afterthought: strong encryption, on-device and air-gapped options, enterprise single sign-on, multi-factor authentication, and an immutable audit trail — with you in control of where your data lives.

Encryption everywhere

In transit, at rest, and — when you choose it — end-to-end with a key only you hold.

In transit & at rest

All traffic is encrypted with TLS. Stored secrets — your API keys, identity-provider client secrets, MFA secrets — are sealed with AES-256-GCM and never written to disk or logs in the clear.

Bring your own key (BYOK)

Enterprises and individual researchers can supply their own public key. Covered document binaries are then sealed with envelope encryption (RSA-OAEP wrapping AES-256-GCM) so the server stores ciphertext it cannot read; you decrypt in the browser with a private key we never see.

Force-encryption controls

Organisation admins can require encryption for local data, cloud data, or both — a single switch that applies the policy across everyone in the organisation.

Your data, where you want it

Cloud convenience, on-device control, or fully air-gapped — the choice is yours, at the same price.

On-device storage

Choose “on my device” when creating a project and your source documents stay in a folder you grant — full text and original files never leave your machine. The server keeps only a metadata stub and an integrity hash.

Air-gapped edition

Run Resonance as a single self-contained binary on an isolated network. Pure-Go, zero external runtime calls — ideal for regulated, classified, or offline field environments.

Local AI option

Prefer not to send text to a third-party model? Point AI assistance at a local LLM running inside your own deployment. No prompt, segment, or transcript leaves the host.

Authentication & access control

Enterprise identity, phishing-resistant sign-in, and least-privilege roles.

Single sign-on (SSO)

Bring your own identity provider over OIDC or SAML 2.0 — Okta, Entra ID, Google Workspace, OneLogin, ADFS, Shibboleth and more. Enrolment is reviewed and approved by a platform admin, and password sign-in is disabled on SSO-managed domains.

SCIM provisioning & instant offboarding

Your identity provider can push user create, update, and — critically — deactivate over SCIM 2.0. Remove someone in your IdP and their Resonance sessions are revoked in milliseconds, not at their next login.

Multi-factor authentication (TOTP)

Add a time-based one-time password (Google Authenticator, 1Password, Authy) as a second factor on top of your password. Enrol from your account page, with single-use recovery codes for when you lose your device.

Passkeys & magic links

Sign in without a password at all: phishing-resistant passkeys (WebAuthn) bound to your device, or single-use, short-lived magic links sent to your verified inbox.

Verified domains

Before an organisation can route sign-in for a domain, it proves ownership with a DNS-TXT challenge — checked against trusted resolvers — so no one can claim a domain they don't control.

Least-privilege roles

Project roles (lead analyst, coder, observer), organisation roles, and a redundancy-by-design two-seat org-admin role keep administrative and research duties separate. Every endpoint re-checks permissions server-side.

Account & session security

Defences that watch how — and from where — accounts are used.

Single active session

Each account holds one live session at a time. A sign-in from a new place ends the old one — a stolen token can't quietly ride alongside the real user.

Sign-in visibility

Every session records the source IP and approximate location of its last sign-in. Platform admins see all active sessions — who is signed in, from where, and on what device — in a live dashboard, so unexpected access is easy to spot.

Rate limiting & idle timeout

Sign-in, registration, and MFA endpoints are rate-limited to blunt brute-force and credential-stuffing, and idle sessions time out automatically.

A hardened, auditable platform

Defence in depth in the application, and a record you can stand behind.

Hardened by default

Strict Content-Security-Policy and security headers, server-side request-forgery guards on every outbound identity fetch, HTML sanitisation of researcher notes, restrictive database file permissions, and continuous dependency vulnerability scanning in the build.

Immutable audit trail

Every coding action — applied, removed, edited, merged — is written to an append-only audit log with before/after detail. There is no API path to update or delete an audit entry, so the analytic trail holds up to scrutiny.

Privacy, data rights & transparency

Reflexivity journals stay private to their author. You can export a copy of your data or permanently delete your account at any time — deletion erases your personal information and private journals while de-identifying shared analysis. Product analytics honour Do-Not-Track and a one-click opt-out, and a published privacy policy, data-processing agreement, subprocessor list, and retention schedule spell out exactly what we do with data.

Security questions before you commit?

We're happy to walk your security team through the architecture, encryption model, and deployment options.