For institutions

Department-wide qualitative research, without forking your IT review.

Clear deployment facts, security documentation, audit trails and a dedicated research-desk contact for teams evaluating QualCanvas. We identify unavailable controls before procurement begins.

What IRBs and procurement ask first

The three documents your committee will want.

Data residency

The application database currently runs in US East and uploads use Cloudflare R2. EU-resident deployment is not currently available.

Read posture →

IRB compliance

Audit trails, consent records, anonymization tools and retention-date recording support a documented workflow; they do not replace institutional review.

Review security details →

License administration

Current access uses email/password, Google identity, team invitations and project roles. SAML/OIDC and SCIM are not currently available.

Discuss requirements →

Procurement should begin with the controls that exist today, the regions where data actually lives, and the gaps your protocol still needs to address.

QualCanvas product principle
Institution features

Procurement reads this list.

Identity and access

Email/password, Google identity, team invitations and project roles are available today. SAML/OIDC and SCIM are not currently available.

Audit logs

Canvas actions record timestamp, user identity, hashed IP and response status for security and research traceability.

Contract review

Request the current DPA and sub-processor information from [email protected]. A HIPAA BAA is not currently offered; do not upload PHI that requires one.

Custom retention

Projects can record a research-data retention date. Canvases moved to Trash have a separate 30-day recovery window before automatic permanent deletion.

EU residency

An EU-resident application database is not currently available. Current application and database hosting is US East.

AI use policy

AI runs only after a user action and provider terms apply. A project-enforced AI-disable switch is not currently available. See /trust/ai.

Procurement questions
Is QualCanvas FERPA-compliant?
QualCanvas provides controls that may support an institution’s FERPA workflow, but QualCanvas does not certify a deployment as FERPA-compliant. Your institution must review the current hosting, access and retention controls before use.
Where is our data stored?
US East for the application and database, with Cloudflare R2 for uploaded files. EU-resident application hosting is not currently available. Full posture on /trust.
Can we sign a DPA?
You can request the current DPA materials before a call. Availability, transfer terms and any requested amendments are confirmed during legal review; no signature timeline is guaranteed.
Do you support SSO and SCIM?
Not currently. QualCanvas presently supports email/password, Google identity and project invitations. Institutions requiring SAML/OIDC or SCIM should treat that as a deployment blocker.
Can we configure data retention?
A project can record a research-data retention date for workflow visibility. Separately, deleted canvases remain recoverable in Trash for 30 days and are then permanently removed.
What about AI training on participant transcripts?
Transcripts are never used to train any model. Full architectural promise at /trust/ai. If your protocol requires a technical zero-AI enforcement control, QualCanvas does not currently provide one.
How is the plan priced?
Institutional requirements are reviewed individually. Contact the research desk for a written scope and quote; no typical price range or turnaround is promised on this page.
Twenty minutes.

Book a call with our research desk.

Bring your residency, identity, retention and AI-control requirements. We’ll compare them with the controls available today.