Security overview
ResFlow is designed for research sites that need organisation isolation, role-based access and accountable operational records. The controls below describe behaviour implemented in the product. We do not display certifications or assurance claims that have not been independently obtained.
What is already in place
These controls are built into the platform today:
- Secure sign-in with email verification
- Organisation-level data isolation
- Role-based permissions for site teams
- Database row-level security
- HTTPS encryption in transit
- Append-only audit logging
- Read-only monitor access where authorised
- Automatic redaction of participant identifiers for monitors
Formal assurance packs, hosting and subprocessor details, and any certification or testing evidence are shared during information-governance review on request.
Authentication
ResFlow uses industry-standard authentication with encrypted sessions, email verification for new accounts, and password requirements designed for research environments. Access requires a verified account and an approved research site membership.
Organisation and study isolation
Each research site operates in its own organisation workspace. Database row-level security ensures participants, studies, bookings, visits and operational logs from one organisation cannot be accessed by users from another organisation.
Role-based access
Site administrators, coordinators, investigators and monitors receive permissions appropriate to their responsibilities. Sensitive actions such as team management, protocol configuration and booking management are restricted to authorised roles.
Monitor access and participant redaction
Authorised monitors can receive limited study oversight. Participant-identifiable fields such as names and contact details are redacted automatically for monitor users so operational status can be reviewed without exposing personal details.
Encryption
Connections to ResFlow use HTTPS (TLS). Data transmitted between your browser and our servers, and between ResFlow and integrated services, is encrypted in transit.
Audit logging
Meaningful operational changes — including participant updates, bookings, protocol changes, team actions and study log activity — are recorded in an append-only audit trail with user, timestamp and organisation context.
Infrastructure and subprocessors
ResFlow is hosted on modern cloud infrastructure with managed PostgreSQL. Current subprocessors include Supabase (database and authentication), Vercel (application hosting) and Resend (transactional email). Stripe may be used where invoicing or payment tooling is configured. Detailed subprocessor information is available on request.
Backups and recovery
Platform infrastructure relies on managed cloud provider capabilities. Specific backup frequency, recovery objectives and disaster-recovery arrangements are shared during customer due diligence rather than published as unverified public guarantees.
Incident management
Security or availability incidents are handled through ResFlow’s operational processes. Affected customers are notified where appropriate. Formal incident-response timelines for contractual inclusion can be discussed during onboarding.
Data retention and deletion
Research sites control operational data within their organisation. Retention, export and deletion expectations are described in the Privacy Policy and Data Processing Agreement. Customers may request available exports and account closure steps through the published contact routes.
Security enquiries
Information-governance and procurement teams may request our current security, subprocessor and data-processing documentation.