Security at HumanTrue
Trust is a system, not a promise.
Overview
Security is foundational to everything we build.
Secure by design
Encryption in transit and at rest, SSO, role-based study access, and isolated customer instances.
Observable by design
Source citations, transformation history, model and version records, approvals, and exportable audit logs.
Reproducible by design
Versioned inputs, assumptions, configurations, seeds, and builds for simulation and structured outputs.
SOC 2
Enterprise security controls
HIPAA
Architecture supports protected workflows
ISO 17100
Human-certified translation workflow
USDM 4.0
Standards-based interoperability
Operational security
Specific controls, not a generic assurance statement.
Encryption
TLS 1.3 or higher in transit. AES-256 encryption for stored data.
Identity and access
MFA for employee access, role-based access control, least privilege, access review, and automated deprovisioning.
Infrastructure
Enterprise cloud controls, network segmentation, firewall protection, comprehensive logging, and monitoring.
Continuity
Automated backups with point-in-time recovery and documented incident-response procedures.
Secure development
Peer review, CI/CD security checks, dependency scanning, vulnerability detection, and engineering security training.
Vulnerability management
Regular scanning, independent penetration testing, severity-based remediation targets, and coordinated disclosure.
Compliance posture
Evidence for quality, security, and procurement review.
Assurance
SOC 2
HumanTrue is audited with the SOC 2 standard, with our security controls designed to meet these requirements. Policy documents and audit reports are available upon request for customers who require them for their own compliance needs.
Health data
HIPAA
HumanTrue's platform does not collect or require Protected Health Information (PHI) or Personally Identifiable Information (PII) to operate. However, we have proactively designed our platform to comply with the Health Insurance Portability and Accountability Act (HIPAA), implementing appropriate administrative, physical, and technical safeguards. Business Associate Agreements (BAAs) are available for customers who require them.
Regulated use
21 CFR Part 11, GxP, and Annex 11
HumanTrue supports risk-based validation with intended-use documentation, requirements-to-verification traceability, audit history, access controls, versioning, and change evidence. Each customer remains responsible for validating its configured use within its quality system.
Data protection
GDPR and UK DPA
Data protection obligations are addressed through technical controls, customer agreements, and data processing terms appropriate to the engagement.
Infrastructure
Residency and subprocessors
Hosting architecture, deployment region, data residency requirements, and current subprocessor information are documented during solution design and vendor review.
Validation
Computer system validation
Validation scope follows intended use and risk. Available evidence includes requirements, release records, verification traceability, exception handling, and change-control documentation.
Security testing
Vulnerability and penetration testing
Current testing scope, report availability, findings status, and remediation evidence are confirmed during security review and shared under appropriate confidentiality controls.
AI governance
Models assist. Evidence decides.
- Model and version traceability for generated results
- Deterministic schema and rule validation
- Human-in-the-loop approval and Level 2 consensus review
- Exceptions remain visible rather than being silently resolved
- Customer-controlled retention and access
Clear responsibility boundaries
Designed for its actual role in the study.
HumanTrue verifies and prepares
It creates review-ready study specifications, structured outputs, content, and evidence for review.Operational platforms execute
EDC, IRT, CTMS, and eCOA vendors retain and operate their production technologies.Authorized people approve
Sponsors, CROs, and designated experts retain final decision and release authority.
Security researchers
Report a security vulnerability
What to expect
- Acknowledgment: We will acknowledge receipt of your report within 2 business days
- Updates: We will provide transparent updates on our investigation and remediation timeline
- Coordinated Disclosure: We request that you allow us reasonable time to address the issue before public disclosure
- Critical
- 7 days
- High
- 30 days
- Medium
- 90 days
Safe Harbor
We support safe harbor for security researchers who:
- Make a good faith effort to avoid privacy violations, data destruction, and service interruption
- Report vulnerabilities promptly
- Allow reasonable time for remediation before public disclosure
What to include in your report
- Description of the vulnerability and potential impact
- Detailed steps to reproduce the issue
- Proof-of-concept code or screenshots (if applicable)
- Your contact information for follow-up questions
Precise terminology
What “verified” and “validated” mean here.
- Verified
- Checked against defined evidence, rules, or acceptance criteria, with the result and review status retained. It is not a guarantee of study performance.
- Validated output
- An output that passes the specified structural, fidelity, and traceability checks for that deliverable. It does not replace a sponsor's computer system validation obligations for its intended use.
- Human-certified
- A defined expert review or translation workflow completed by an authorized human reviewer, with the review record retained.
Contact
For general security inquiries or questions about our security practices, please contact us at security@humantrue.com.
Last updated:
Start with one protocol