TrialConnx helps institutions, sites and site networks manage all study administrative workflows such as study intake, pipeline, study start up, amendments and closeout. Because the data we handle belongs to our customers and their partners, we treat security as a first-class product concern. This page describes the controls we operate today, the frameworks our controls align with, and how to reach us with questions or to report a vulnerability.
This page should be read alongside our Privacy Policy and Terms of Service. Where the Privacy Policy describes what information we collect and why, this page describes how we protect it.
1. Scope of Data
TrialConnx is a study operations platform, not a clinical data system. As described in our Privacy Policy, the data we hold may include:
- Study, site, and investigator metadata
- Sponsor and CRO user accounts, roles, and activity
- Clinical trial documents such as protocols, contracts, and budgets
- Feasibility surveys and site readiness forms
- Study team contact lists
- Start up Activity updates, comments, collaboration notes, scheduling, and milestone data
TrialConnx does NOT store any patient or participant records, clinical data, case report forms, EDC content, or regulated electronic trial master file (eTMF) records subject to 21 CFR Part 11. Personal health information (PHI) is out of scope for our platform by design.
2. Compliance Posture
Infrastructure. TrialConnx is hosted on Amazon Web Services. AWS holds SOC 1, SOC 2, SOC 3, ISO 27001, and ISO 27017/27018 attestations for the infrastructure layer. Production data is managed on MongoDB Atlas, which is SOC 2 Type II and ISO 27001 certified and provides equivalent encryption, access-control, and audit capabilities. Under the standard shared-responsibility model, our cloud providers secure the underlying platforms and TrialConnx secures the application, data, identity, and configuration layers.
SOC 2. TrialConnx itself is not currently SOC 2 certified. Our application-layer controls are designed against the SOC 2 Trust Service Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy. Customers who require a detailed mapping of our controls to the SOC 2 Trust Service Criteria can request one under a mutual NDA or an executed customer contract.
HIPAA-aligned controls. While PHI is out of scope for TrialConnx, our encryption, access control, and audit practices are designed to meet the standards commonly expected of HIPAA-regulated systems, so customers can deploy TrialConnx with confidence inside healthcare environments.
GDPR. TrialConnx follows GDPR principles of data minimization, lawful basis, and data subject rights for personal data of sponsor and site users. A Data Processing Addendum is available on request for customers in scope.
3. Application Security
Authentication and access control
- JWT-based authentication via Passport.js
- Role-based access control with granular permissions for sponsor administrators, study teams, site staff, and external collaborators
- Organization-level tenant isolation with logical data separation; study-level access scopes within each organization
- Designed to support multi-factor authentication and single sign-on (SAML / OIDC) for enterprise customers; we work with each enterprise to enable and configure these options as part of enterprise onboarding
- Principle of least privilege for internal staff; production access restricted to authorized personnel and logged
Encryption
- All traffic encrypted in transit using TLS 1.2 or higher
- Sensitive application data encrypted at rest using AES-256
- User passwords hashed with bcrypt
- File uploads stored in AWS S3 and served via short-lived pre-signed URLs; direct object access is not permitted
Application hardening
- OWASP security headers enforced at the edge, including Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Strict-Transport-Security
- Input validation through express-validation middleware and schema validation at the database layer to prevent injection attacks
- Secure session handling: HTTP-only cookies, Secure flag, SameSite=strict in production, configurable session expiration per organization
- Rate limiting and traffic filtering at the reverse-proxy layer
Audit trail
- Comprehensive application-level audit logging captures user actions, data modifications, authentication events, and administrative changes
- Audit records are retained in line with our data retention policy and cannot be modified by application users
- Audit export available to customers on request
4. Infrastructure and Operational Security
- Secrets management: credentials managed through a parameter store; secrets are never stored in source code or container images.
- Environment separation: development, staging, and production environments use distinct credentials, data, and network boundaries.
- Deployment: containerized services with isolated service boundaries, immutable builds, and peer code review on every change.
- Dependency management: automated dependency scanning on every build; security patches applied on a defined severity SLA.
- Security assessments: internal security assessments conducted quarterly, with tracked vulnerability remediation, plus additional assessments around major releases. A summary of assessment findings and remediation status can be provided to customers on request under NDA.
- Backups: production data is managed on MongoDB Atlas with automated snapshot backups: hourly snapshots retained for 7 days, daily snapshots retained for 7 days, weekly snapshots retained for 4 weeks, and monthly snapshots retained for 3 months. Point-in-time restore is available within the most recent 7 days. All snapshots are encrypted at rest.
- Availability: multi-AZ deployment on AWS with MongoDB Atlas handling database replication and failover. The uptime remedy available to enterprise customers is described in our Terms of Service.
5. People and Process
- All employees sign confidentiality agreements covering customer data.
- Annual security awareness training for all staff, including HIPAA awareness training for team members working with healthcare organizations.
- Additional secure-coding guidance for engineering staff.
- Formal onboarding and offboarding procedures, including provisioning and timely revocation of access to customer data and production systems.
6. Incident Response
TrialConnx maintains a documented incident response plan that covers detection, containment, eradication, recovery, and post-incident review. Security events are triaged within 4 hours of detection. Confirmed incidents affecting customer data are communicated to affected customers without undue delay, consistent with the notification commitments in our customer agreements and applicable law. Post-incident summaries are provided to affected customers on request.
7. Responsible Disclosure
We welcome reports of suspected vulnerabilities from the security community. Please email security@trialconnx.com with a description of the issue, steps to reproduce, and any supporting evidence. We commit to acknowledging reports within 5 business days and will not pursue legal action against researchers acting in good faith who follow coordinated disclosure practices.
8. For Prospects, Customers, and Vendor-Management Teams
Under a mutual NDA or an executed customer contract we can provide:
- A security controls summary mapped to the SOC 2 Trust Service Criteria (prepared on request)
- AWS and MongoDB Atlas compliance attestations (SOC 2, ISO 27001)
- Security assessment summary and remediation status (on request)
- Completed vendor security questionnaires, prepared on request
- A Data Processing Addendum for GDPR-scope customers
To request any of the above, or to ask a question not covered on this page, email trust@trialconnx.com. For privacy-specific inquiries, please see our Privacy Policy or write to privacy@trialconnx.com.
9. Changes to This Page
We review and update this page as our controls evolve. Material changes will be noted with a revised effective date.
Effective date: December 2025