Notēsis

Data & Security

How Notēsis protects your research workspace, project files, and researcher-controlled records.

Your research workspace is private by default

Notēsis is designed so project content is available only to people who are authorized to access that project. Research notes, memos, meetings, transcripts, literature records, and project files are protected by project-level access controls rather than being publicly accessible.

Project files are stored in private Supabase Storage. Database Row Level Security (RLS) is used throughout the application to enforce which projects and records a signed-in user may access.

Sharing does not mean giving up ownership

Project owners control collaboration. A collaborator can access a project only after being added as a project member or successfully accepting a valid invitation.

Collaborators do not automatically receive owner-level permissions. Project ownership and project membership remain separate.

Pending invitations do not grant project access until the invitation is successfully claimed by the intended account.

What happens when I upload a file?

  1. Notēsis checks whether the file type is permitted.
  2. Notēsis checks the project's available storage.
  3. The upload is screened for malware before it is treated as a trusted project file.
  4. The file is stored in private project storage.
  5. Notēsis records project and uploader information so access and storage usage can be managed correctly.

Video uploads and dangerous executable or active-content file types are currently blocked.

Malware protection

Permitted uploads are screened with ClamAV before they are treated as trusted files. In production, Notēsis is configured to fail safely if malware scanning is unavailable rather than silently accepting an unscanned file.

Malware definitions are initialized and refreshed automatically as part of the production deployment and scanning process.

No malware scanner can guarantee detection of every malicious file.

AI and your research

Notēsis uses AI only for specific, user-initiated features. AI is intended to support researcher workflow and reflexivity—not replace the researcher as the analyst.

Examples of permitted AI assistance include transcription, reflective prompt suggestions, non-leading follow-up questions, and narrowly defined administrative Meeting synthesis.

Meeting administrative synthesis may organize topics discussed, explicit decisions, action items, unresolved questions, and logistical next steps. It is not permitted to generate research findings, code data, infer themes as findings, recommend analyses, propose research questions, or decide what evidence means.

Notēsis should send only the information needed for the feature the researcher explicitly requests. Literature Review annotations are excluded from AI context.

Researcher control and provenance

Notēsis is designed to preserve the history of researcher-controlled records rather than silently replacing them.

  • The original machine-generated transcript remains distinct from researcher corrections.
  • Transcript correction history is retained.
  • Re-running Meeting administrative synthesis preserves prior versions.
  • Audio recordings are not automatically deleted after transcription.
  • Storage reconciliation reports inconsistencies rather than automatically deleting ambiguous files.

This helps preserve a clear record of what was generated, what was changed, and what remains researcher-authored.

Account access

Notēsis requires a normal authenticated account for research and project work.

Public pages such as sign in, signup, password recovery, About, and Data & Security remain available without a research workspace session.

Privileged system access

Notēsis separates ordinary application access from highly privileged maintenance access.

The normal Notēsis web service does not use the Supabase service-role credential. Privileged credentials are restricted to specific administrator-run maintenance processes such as storage reconciliation.

These privileged maintenance capabilities are not exposed as ordinary user actions.

Automated maintenance

  • Storage consistency is checked on a scheduled basis.
  • Storage reconciliation is report-only.
  • Ambiguous files are not automatically deleted.

What Notēsis does not claim

Security is an ongoing process, not a guarantee.

Notēsis does not currently claim:

  • HIPAA compliance
  • FERPA compliance
  • institutional IRB approval
  • end-to-end encryption
  • zero-knowledge storage

Questions about data security?

If you are evaluating Notēsis for research involving sensitive or institutionally governed data, review your institution's requirements before uploading that material.