Skip to main content
Trust Center

Security is the product.

Clinical trial data sits at the intersection of patient privacy and regulatory submission. We built to the higher bar: Part 11, E6(R3), and GDPR. From day one.

Compliance posture

Where we are, honestly.

No fake badges. No inherited SOC reports. Here is the real state of our certifications and validation packages.

StandardStatus
21 CFR Part 11Live — validation package available to QA teams on request
ICH E6(R3)Live — ALCOA+ compliant audit logs
HIPAABAA available
GDPRDPA available
Computer System Validation

Built to be validated.

TrialNexus is designed as a GAMP 5 Category 4 configured product. Our validation package is available to qualified QA teams during security review. No customer signature required to see the documentation.

What's in the package
System Description Document
Architecture, data flows, and boundary definitions
GAMP 5 Risk Assessment
Category 4 classification with rationale
IQ / OQ / PQ Protocols
Installation, operational, and performance qualification
Traceability Matrix
Requirements → design → test cases → results
Change Control Procedures
How updates are assessed, tested, and released
Periodic Review Guidance
How to demonstrate ongoing validated state
Architecture that supports CSV
Immutable audit trail
Every agent call, approval, and data change is append-only. Nothing is overwritten.
Model version locking
Every output is tied to the exact model version that produced it, permanently
Versioned agent configurations
Config changes are logged and reversible. Validated state is never silently altered.
Electronic signatures
21 CFR Part 11 compliant e-sign on every Decision Queue approval

Your QA lead can review our full validation package before any contract is signed. We expect this to be part of the process, not an afterthought.

Request validation documentation →
How we build it

Six layers.

Data residency

US-East and EU-West regions. Your data never leaves the region you pick. Enterprise tenants get dedicated databases.

Tenant isolation

Row-level security on every Postgres table. Dedicated database instances for Enterprise. LLM calls scoped to tenant identity.

Encryption

TLS 1.3 in flight. AES-256 at rest. Customer-held KMS keys for Enterprise. Secrets in AWS Secrets Manager; never in source.

Audit logs

Immutable, append-only. Every agent call, every human approval, every data change. Exportable to your SIEM.

Access control

SAML / OIDC via Auth0. MFA enforced. Role-based access with study-scoped permissions. Break-glass procedures documented.

Pen testing

Annual third-party penetration testing. Findings triaged and remediated before each test cycle closes.

Reporting

Found something? We want to hear.

Security issues go to security@trialnexus.ai. We respond within one business day and publish advisories once fixes ship. Safe-harbor for good-faith research.

Security questions before you sign? We expect that.

We will walk any security team through our controls, share our validation package, and answer questions on the record. That's what the security review call is for.

Send us your security questions