Security
How we protect study data
Clinical trial data is some of the most sensitive data there is. This page sets out the controls that are live in Capture.Study today, and how to tell us if you find a security problem.
Last updated September 29, 2026
Hosting and encryption
- Each study is hosted in the EU (Frankfurt) or the USA (N. Virginia), so you can keep data in the region your protocol and ethics approval require.
- Data is encrypted at rest with AES-256 and in transit with TLS.
- Your study data is yours. Export it at any time as CSV or Excel, with a data dictionary, raw and decoded values, and filters by site and date.
Access control
- Role-based access for study owners, investigators, site staff, monitors and data managers. Each person sees only what their role needs.
- Access rules are enforced by row-level security in the database, not only hidden in the interface.
- Personal details are separated from study data: site staff can see participant names, researchers work with coded participant IDs.
- In blinded studies, treatment-arm information is withheld from blinded roles at the database layer.
Sign-in and signatures
- Two-factor authentication for staff accounts with any authenticator app (Google Authenticator, Authy, 1Password and others).
- Sessions end automatically after a period of inactivity, with a warning first.
- Electronic signatures require password re-authentication and a signature meaning statement. Password managers are blocked from autofilling signature fields, so every signature is a deliberate act.
- Participants sign eConsent on screen and confirm it with a one-time code sent by email. Each signature is cryptographically linked to the exact document they signed.
Audit trail and data integrity
- A field-level audit trail on every record: timestamp, user, role, old value, new value and reason for change.
- Audit entries are written by the database itself, not by the app, and the trail is append-only: the database blocks edits and deletions of audit entries.
- Each audit entry carries a SHA-256 hash chained to the entry before it, so any tampering with the history is detectable.
- Clinical data is never hard-deleted. Removed records are kept, marked as deleted, and stay in the audit trail.
How we build and run it
- We review the application against the OWASP Top 10 and prioritise fixes by real-world risk.
- Third-party dependencies are monitored automatically for updates.
- Technical events are logged separately from the clinical audit trail, so the GCP trail holds regulated actions only.
Compliance
- Controls aligned with 21 CFR Part 11: audit trail, electronic signatures, role-based access and locked, versioned forms. Part 11 compliance is shared between the software and your own validated use of it.
- GDPR-ready, with EU data residency available. HIPAA-ready infrastructure for US studies.
- Enterprise customers can get documentation to support their own system validation and UAT.
Report a vulnerability
If you think you have found a security issue in Capture.Study, email security@capture.study. We acknowledge reports within 3 business days, we won't take legal action against good-faith research that follows our policy, and we'll credit you if you'd like. Please read the policy before you start testing.
Running a security review?
Send us your vendor questionnaire and we'll answer it. You can also build a full study in the free sandbox and check the audit trail, signatures and access rules yourself.
The security questionnaire to send any EDC vendor