Data handling and security

Study design data, handled with defined security controls

Concordare handles study design data only. Protocols contain no PHI. Controls include organization isolation, permissions, authentication, and encryption.

Data we process

Protocols contain no PHI

Protocols describe study design data only, not PHI. Concordare handles that study design data.

Study design data

  • Protocol PDF documents (study design only)
  • Visit schedule and endpoint structures
  • Eligibility criteria text
  • CRF requirement definitions
  • User override and review records

No PHI in protocols

  • Patient records of any kind
  • Subject identifiers or enrollment data
  • Lab results or clinical measurements
  • Adverse event records
  • Any collected study data from active trials

Data handling

  • Protocol documents retained for the contract term
  • Build records and audit trails retained per your configuration
  • Deletion on request at any time
  • Documented retention schedules available in DPA

Access controls

Workspace isolation and user permissions

Each organization has its own logical workspace boundary. One organization cannot access another organization's data.

Workspace isolation

Data is held within a per-organization logical isolation boundary. Cross-organization access is blocked at both the application and storage layers.

Role-based permissions

Workspace admins set per-user permissions for uploading, reviewing, approving exports, and managing settings.

Authentication

Authentication uses email and password with mandatory session expiry. Enterprise customers can use SSO through SAML 2.0.

Encryption

Data in transit uses TLS 1.2 or later, and data at rest uses AES-256. Protocol documents are also encrypted at the object storage layer.

Security posture

Designed for clinical research organization requirements

Concordare is hosted on infrastructure with established compliance certifications relevant to clinical research.

AWS hosting

Hosted on AWS US-East infrastructure. AWS holds SOC 2 Type II, ISO 27001, and HIPAA eligibility. These are AWS certifications. We do not process patient data, and the hosting environment is eligible for those frameworks if required.

Data Processing Agreement

A DPA is available to all customers. It covers processed data, handling, retention schedules, and sub-processor disclosures. Custom BAA execution is available to Enterprise customers.

Audit trail

Each build action, user override, and export event is logged with a timestamp and user attribution. CSV exports are available for validation documentation.

Security details?

Contact us with questions about security, data handling, or the early-access program.