Participant health data, regulated records and a sponsor's reputation all sit in your EDC. These are the questions to ask before you sign, what a good answer looks like, and how Capture answers the ones that are about the product.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Individual user accounts only (no shared logins)?
Role-based access enforced at the database layer?
Password expiry policy
Re-authentication for electronic signatures?
Evidence: product documentation
Key points
Why it matters
ICH GCP makes the sponsor responsible for the data and for the vendors it uses to handle them. If a vendor loses data, exposes participant information or cannot produce an audit trail at inspection, it is the sponsor's study that suffers. Security due diligence is how you show that you selected the vendor carefully and continue to oversee it.
Academic sponsors face the same expectation, plus institutional information security reviews that can delay study start by months if they begin late. Starting the questionnaire at the shortlisting stage, rather than after vendor selection, avoids that bottleneck, whether you are comparing enterprise platforms such as Medidata Rave and Veeva Vault EDC or lighter, self-serve tools. The EDC procurement checklist shows where security review fits in the wider buying process.
The questionnaire
The right-hand column gives Capture's answer where the question is about product capabilities. For certifications and procedural documents, request the current versions directly.
| Question | Good answer shows | Capture |
|---|---|---|
| Where is data hosted, and can we choose? | Named regions, customer choice, no silent transfers | EU (Frankfurt) or US (N. Virginia), chosen at study setup |
| Is data encrypted at rest and in transit? | Modern encryption on both | AES-256 at rest, TLS in transit |
| How is access controlled? | Individual accounts, roles, least privilege | Role matrix per study and site; row-level security at the database layer |
| Is personal data separated from clinical data? | Pseudonymisation for sponsor-side users | Coordinators see names; researchers see coded IDs |
| What does the audit trail record? | Who, what, when, old and new value, why | Every field change with user, time, old and new value and reason |
| Can the audit trail be modified? | No; tamper-evident | Append-only, SHA-256 hash chain with verification |
| How do electronic signatures work? | Re-authentication and meaning | Password re-entry verified on the server; meaning stored |
| What is the password policy? | Enforced, not advisory | Expiry every 90 days, enforced on the server |
| Can we export all our data at any time? | Yes, in open formats, without fees | CSV and Excel exports with data dictionary, any time |
| Certifications, pen tests, policies | Current reports and dates | Request current documentation from us |
| Backup, recovery and incident response | Documented RPO/RTO, tested, notification commitments | Request current documentation from us |
| Subprocessors and data processing terms | Named list, DPA, change notification | Request our DPA and subprocessor list |
Hosting and residency
EU-sponsored studies usually want data in the EU; US studies often want it in the US. Capture lets you choose the hosting region at study setup, with encryption at rest and in transit either way.
EU (Frankfurt)
Default for EU-sponsored studies
US (N. Virginia)
Default for US-sponsored studies
Access and privacy
Permissions follow a role matrix for every study and site: study owner, PI, sub-investigator, coordinator, monitor, data manager and participant. Site staff see only their assigned sites, and personal identifiers stay with the site while sponsor-side users see coded IDs.
Study owner
Builds and configures the study
Principal investigator
Oversees the site, signs off the casebook
Sub-investigator
Enters and signs clinical data
Study coordinator
Screens subjects, enters visit data
Monitor (CRA)
Verifies data, raises queries
Data manager
Reviews, freezes and locks data
Participant
Completes their own questionnaires
Open a free sandbox and inspect the roles, audit trail and signature controls directly.
Contracts
Technical controls get most of the attention, but several of the most important protections live in the contract. Make sure the agreement covers them before signature, when you still have leverage.
State that the sponsor owns the data, that full exports (including audit trails and metadata) are available at any time and at termination, and whether any fees apply. A vendor that charges heavily for exit makes future switches painful; see how to switch EDC vendors mid-study.
Specify how quickly the vendor must notify you of a personal data breach, so you can meet your own obligations (GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a reportable breach).
Require a list of subprocessors, notice before changes, and a right to audit or to receive audit reports. For US studies with covered entities, confirm how HIPAA obligations will be handled.
Because GCP keeps the sponsor accountable for trial data held by vendors. The questionnaire documents that the vendor was assessed and supports ongoing oversight.
Company and certifications, hosting and residency, encryption, access control, audit trail and signatures, backup and recovery, incident response, and subprocessors and contracts.
In the EU (Frankfurt) or the US (N. Virginia), chosen at study setup.
AES-256 encryption at rest and TLS in transit.
Yes. The free sandbox includes roles, audit trail and electronic signatures, so your team can test them directly.
Contact us for current security documentation, data processing terms and the subprocessor list.
Keep exploring
EDC procurement checklist
The full buying process.
GDPR compliant trial software
EU data protection.
HIPAA compliant trial software
US health data protection.
21 CFR Part 11 compliant EDC
Electronic records controls.
Computer system validation
Qualifying the system for use.
What to look for in an EDC platform
Beyond security.
Free sandbox with every feature. Security documentation on request.