Security & Compliance

Security

Security & Compliance

Enterprise-grade security built for regulated clinical research.

FDA 21 CFR Part 11

The Platform supports electronic signatures, user authentication with password complexity requirements, comprehensive audit trails, and data validation to meet FDA 21 CFR Part 11 requirements for electronic records and signatures.

Encryption
  • Data in transit: TLS 1.2+ for all communications
  • Data at rest: AES-256 encryption for stored data
  • Database: encrypted at the storage layer
  • Passwords: bcrypt hashed with configurable cost factor
Access Control
  • Role-based access control (RBAC) with granular permissions
  • Multi-factor authentication support
  • Data Access Groups (DAGs) for site-level data isolation
  • Automatic session timeout after inactivity
  • IP-based rate limiting on authentication endpoints
Audit Trail

Every data change, login attempt, and administrative action is logged with timestamp, user identity, IP address, before/after values, and reason. Audit logs are immutable and exportable for regulatory submission.

Infrastructure Security
  • Hosted on SOC 2 compliant cloud infrastructure
  • Regular automated backups with point-in-time recovery
  • DDoS protection and web application firewall
  • 24/7 monitoring and incident response
  • Annual penetration testing by independent third parties
Compliance Certifications
  • HIPAA compliance with signed Business Associate Agreements
  • GDPR compliant data processing and Data Processing Agreements
  • ICH GCP E6(R2) aligned workflows
  • 21 CFR Part 11 validation documentation available upon request