The Code Rare Survey Platform was architected with enterprise-grade security and true zero-knowledge privacy. Personal identity data is encrypted so that only the participant can access it — researchers and survey owners see only anonymized aliases.
All pages, logins, survey submissions, and API calls use industry-standard 256-bit SSL/TLS with SHA-256 certificates. Data is always encrypted in transit.
Every participant's personal identity information (name, email, and any PHI) is encrypted client-side in the browser using their own password as the encryption key (AES-256-GCM via PBKDF2). The server never receives or stores plaintext personal data.
Both administrators and participants must use MFA on every login. This protects accounts even if a password is compromised, adding a critical second layer of identity verification.
When survey data is viewed at the individual answer level by researchers or survey administrators at Code Rare, the participant's real identity is never shown. Instead, each participant is displayed only as an anonymized alias — for example, Participant-XYZ-123.
Survey answers remain fully usable for analysis, comparisons, feedback, and visualizations, but they are permanently decoupled from any personally identifiable information. This pseudonymization ensures that researchers can perform their work without ever seeing or accessing real identities.
SurveyApp meets all seven GDPR principles through:
California residents receive full rights under CCPA:
Healthcare organizations that use this portal to collect Protected Health Information (PHI) are required under HIPAA to maintain a signed BAA with Code Rare. We provide one upon request.