Security & Compliance

Security is the foundation of trust.

TruTechnologies is built for the highest standards of clinical research. Every layer — device, network, application, and process — is designed to protect patient data and preserve the integrity of the trial.

How we protect data

Defense in depth — by design.

Encryption everywhere

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Encryption keys are rotated regularly and managed in dedicated KMS infrastructure.

Least-privilege access

Role-based access control, SSO, and MFA for all internal and customer users. Production access is logged, time-bound, and reviewed continuously.

Secure cloud infrastructure

Hosted on hardened, SOC 2 / ISO 27001 certified cloud infrastructure in the United States with network segmentation, WAF, and 24/7 monitoring.

Continuous monitoring

Real-time logging, anomaly detection, and centralized alerting across application, infrastructure, and device layers. Incidents are triaged 24/7.

Validated SDLC

Computer System Validation aligned with GAMP 5. Every release passes peer review, automated testing, security scanning, and documented QA.

Resilience & recovery

Automated backups, point-in-time restore, geographically separate disaster recovery, and tested business continuity procedures.

Compliance

Built to meet the standards regulators expect.

From CFR Part 11 to GDPR, our controls map to the frameworks sponsors, sites, and auditors rely on. Documentation is available under NDA.

HIPAA

Business Associate Agreements and full administrative, physical, and technical safeguards for protected health information.

21 CFR Part 11

Audit trails, system validation, and access controls for FDA-regulated electronic records.

GDPR

Lawful processing, data subject rights, breach notification, and EU representative for personal data of EEA/UK residents.

SOC 2 Type II

Independently audited controls covering security, availability, confidentiality, and processing integrity.

GxP

Designed and operated to meet Good Clinical Practice (GCP) and Good Manufacturing Practice (GMP) expectations.

ISO 27001

Information Security Management System aligned with ISO 27001 control objectives.

Data integrity

ALCOA+ from capture to EDC.

Every action — by every user, on every device — is captured with attributable, time-stamped audit trails. Records are complete, consistent, and contemporaneous, and cannot be altered without a verified electronic signature.

Attributable

Every record is tied to a unique, authenticated user.

Legible & permanent

Records are human-readable and immutable once committed.

Contemporaneous

Captured at the moment of activity at the clinical site.

Original

Source data, not transcribed — eliminating manual entry error.

Accurate

Validated workflows enforce protocol logic in real time.

Complete, consistent, enduring & available

Backed up, retained, and exportable on demand.

Responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from the security community. Please share details privately so we can investigate and remediate before public disclosure. We commit to acknowledging reports within two business days.