Skip to content

Security at HumanTrue

Trust is a system, not a promise.

HumanTrue combines enterprise controls, isolated customer environments, full provenance, model governance, and human review for regulated clinical development.

Overview

Security is foundational to everything we build.

Our platform handles sensitive clinical trial data, and we take our responsibility to protect that data seriously. We maintain robust security controls, comply with industry standards, and continuously improve our security posture.
  • Secure by design

    Encryption in transit and at rest, SSO, role-based study access, and isolated customer instances.

  • Observable by design

    Source citations, transformation history, model and version records, approvals, and exportable audit logs.

  • Reproducible by design

    Versioned inputs, assumptions, configurations, seeds, and builds for simulation and structured outputs.

  • SOC 2

    Enterprise security controls

  • HIPAA

    Architecture supports protected workflows

  • ISO 17100

    Human-certified translation workflow

  • USDM 4.0

    Standards-based interoperability

Operational security

Specific controls, not a generic assurance statement.

Security is designed into access, infrastructure, software delivery, monitoring, and recovery.
  • Encryption

    TLS 1.3 or higher in transit. AES-256 encryption for stored data.

  • Identity and access

    MFA for employee access, role-based access control, least privilege, access review, and automated deprovisioning.

  • Infrastructure

    Enterprise cloud controls, network segmentation, firewall protection, comprehensive logging, and monitoring.

  • Continuity

    Automated backups with point-in-time recovery and documented incident-response procedures.

  • Secure development

    Peer review, CI/CD security checks, dependency scanning, vulnerability detection, and engineering security training.

  • Vulnerability management

    Regular scanning, independent penetration testing, severity-based remediation targets, and coordinated disclosure.

Compliance posture

Evidence for quality, security, and procurement review.

HumanTrue documents what is complete, what is customer-specific, and what remains in progress. Detailed evidence is provided through the appropriate diligence and contracting process.
  • Assurance

    SOC 2

    HumanTrue is audited with the SOC 2 standard, with our security controls designed to meet these requirements. Policy documents and audit reports are available upon request for customers who require them for their own compliance needs.

  • Health data

    HIPAA

    HumanTrue's platform does not collect or require Protected Health Information (PHI) or Personally Identifiable Information (PII) to operate. However, we have proactively designed our platform to comply with the Health Insurance Portability and Accountability Act (HIPAA), implementing appropriate administrative, physical, and technical safeguards. Business Associate Agreements (BAAs) are available for customers who require them.

  • Regulated use

    21 CFR Part 11, GxP, and Annex 11

    HumanTrue supports risk-based validation with intended-use documentation, requirements-to-verification traceability, audit history, access controls, versioning, and change evidence. Each customer remains responsible for validating its configured use within its quality system.

  • Data protection

    GDPR and UK DPA

    Data protection obligations are addressed through technical controls, customer agreements, and data processing terms appropriate to the engagement.

  • Infrastructure

    Residency and subprocessors

    Hosting architecture, deployment region, data residency requirements, and current subprocessor information are documented during solution design and vendor review.

  • Validation

    Computer system validation

    Validation scope follows intended use and risk. Available evidence includes requirements, release records, verification traceability, exception handling, and change-control documentation.

  • Security testing

    Vulnerability and penetration testing

    Current testing scope, report availability, findings status, and remediation evidence are confirmed during security review and shared under appropriate confidentiality controls.

AI governance

Models assist. Evidence decides.

HumanTrue orchestrates specialized models within a controlled pipeline. Customer data is not used to train, fine-tune, or modify external models or offerings.
  • Model and version traceability for generated results
  • Deterministic schema and rule validation
  • Human-in-the-loop approval and Level 2 consensus review
  • Exceptions remain visible rather than being silently resolved
  • Customer-controlled retention and access

Clear responsibility boundaries

Designed for its actual role in the study.

  1. HumanTrue verifies and prepares

    It creates review-ready study specifications, structured outputs, content, and evidence for review.
  2. Operational platforms execute

    EDC, IRT, CTMS, and eCOA vendors retain and operate their production technologies.
  3. Authorized people approve

    Sponsors, CROs, and designated experts retain final decision and release authority.

Security researchers

Report a security vulnerability

We welcome reports from security researchers and the broader community. HumanTrue supports coordinated disclosure, and we will acknowledge receipt of your report within 2 business days.
security@humantrue.com
  • What to expect

    • Acknowledgment: We will acknowledge receipt of your report within 2 business days
    • Updates: We will provide transparent updates on our investigation and remediation timeline
    • Coordinated Disclosure: We request that you allow us reasonable time to address the issue before public disclosure
    Critical
    7 days
    High
    30 days
    Medium
    90 days
  • Safe Harbor

    We support safe harbor for security researchers who:

    • Make a good faith effort to avoid privacy violations, data destruction, and service interruption
    • Report vulnerabilities promptly
    • Allow reasonable time for remediation before public disclosure
  • What to include in your report

    • Description of the vulnerability and potential impact
    • Detailed steps to reproduce the issue
    • Proof-of-concept code or screenshots (if applicable)
    • Your contact information for follow-up questions

Precise terminology

What “verified” and “validated” mean here.

Verified
Checked against defined evidence, rules, or acceptance criteria, with the result and review status retained. It is not a guarantee of study performance.
Validated output
An output that passes the specified structural, fidelity, and traceability checks for that deliverable. It does not replace a sponsor's computer system validation obligations for its intended use.
Human-certified
A defined expert review or translation workflow completed by an authorized human reviewer, with the review record retained.

Contact

For general security inquiries or questions about our security practices, please contact us at security@humantrue.com.

Last updated:

Start with one protocol

Find what your current process cannot see.

Request a Working Session