Keep the user data encrypted on Aha!'s end - in your instances and databases. Encrypt/decrypt on-the-fly right in browser, so no one but the authenticated web user can see and modify the user data. (This will assure needlessness of an on-premise Aha! system.)