Security is the product.
Clinical trial data sits at the intersection of patient privacy and regulatory submission. We built to the higher bar: Part 11, E6(R3), and GDPR. From day one.
Where we are, honestly.
No fake badges. No inherited SOC reports. Here is the real state of our certifications and validation packages.
| Standard | Status |
|---|---|
| 21 CFR Part 11 | Live — validation package available to QA teams on request |
| ICH E6(R3) | Live — ALCOA+ compliant audit logs |
| HIPAA | BAA available |
| GDPR | DPA available |
Built to be validated.
TrialNexus is designed as a GAMP 5 Category 4 configured product. Our validation package is available to qualified QA teams during security review. No customer signature required to see the documentation.
Your QA lead can review our full validation package before any contract is signed. We expect this to be part of the process, not an afterthought.
Request validation documentation →Six layers.
Data residency
US-East and EU-West regions. Your data never leaves the region you pick. Enterprise tenants get dedicated databases.
Tenant isolation
Row-level security on every Postgres table. Dedicated database instances for Enterprise. LLM calls scoped to tenant identity.
Encryption
TLS 1.3 in flight. AES-256 at rest. Customer-held KMS keys for Enterprise. Secrets in AWS Secrets Manager; never in source.
Audit logs
Immutable, append-only. Every agent call, every human approval, every data change. Exportable to your SIEM.
Access control
SAML / OIDC via Auth0. MFA enforced. Role-based access with study-scoped permissions. Break-glass procedures documented.
Pen testing
Annual third-party penetration testing. Findings triaged and remediated before each test cycle closes.
Found something? We want to hear.
Security issues go to security@trialnexus.ai. We respond within one business day and publish advisories once fixes ship. Safe-harbor for good-faith research.