Security
Sensitive information requires careful architecture.
PsyLattice is being built around restricted access, role separation and privacy-conscious handling of psychological information.
Role-based workspaces
Personal, researcher and clinician accounts operate within separate workspaces. Access to a workspace is determined by authenticated account information rather than simply by which interface a user selects.
Professional verification
Researcher and clinician accounts are designed to require verification before professional tools become available. Professional access should not be granted solely because someone selects a professional role during registration.
Database access controls
PsyLattice is being designed so that users can access only information permitted for their account and role.
Database-level access rules are intended to provide an additional layer of protection beyond the visible website interface.
Authentication
Account authentication, email confirmation and secure session management are used to establish authenticated access before protected PsyLattice workspaces can be entered.
Future safeguards
Before handling sensitive production data at scale, PsyLattice will require further security review, logging, backup procedures, administrative controls, incident-response processes and appropriate privacy and regulatory review.
Report a security concern
A dedicated security reporting channel will be published before public production use of the platform.