Buying guide · Due diligenceUpdated September 28, 2026

The security questionnaire every clinical trial software vendor should pass

Participant health data, regulated records and a sponsor's reputation all sit in your EDC. These are the questions to ask before you sign, what a good answer looks like, and how Capture answers the ones that are about the product.

  • Hosting and encryption
  • Access, audit and signatures
  • Contracts and incidents

Free sandbox · No credit card · 21 CFR Part 11 aligned

Vendor assessment · Section 3 of 8
Access control and authenticationIn review

Individual user accounts only (no shared logins)?

YesNo

Role-based access enforced at the database layer?

YesNoPartially

Password expiry policy

Every 90 days, enforced on the server

Re-authentication for electronic signatures?

YesNo

Evidence: product documentation

Ask for evidence, not just yes or no

Key points

  • Vendor qualification is a sponsor responsibility under GCP: you remain accountable for trial data even when a vendor hosts it.
  • A good questionnaire covers eight areas: company and certifications, hosting and data residency, encryption, access control, audit trail and signatures, backup and recovery, incident response, and subprocessors and contracts.
  • Ask for evidence (documentation, reports, demonstrations) rather than accepting yes or no answers.
  • Separate product controls (which a vendor can demonstrate) from procedural controls (which you will need to see documented).
  • A sandbox where you can inspect the controls yourself answers many questions faster than a spreadsheet.

Why it matters

You can outsource hosting, not accountability

ICH GCP makes the sponsor responsible for the data and for the vendors it uses to handle them. If a vendor loses data, exposes participant information or cannot produce an audit trail at inspection, it is the sponsor's study that suffers. Security due diligence is how you show that you selected the vendor carefully and continue to oversee it.

Academic sponsors face the same expectation, plus institutional information security reviews that can delay study start by months if they begin late. Starting the questionnaire at the shortlisting stage, rather than after vendor selection, avoids that bottleneck, whether you are comparing enterprise platforms such as Medidata Rave and Veeva Vault EDC or lighter, self-serve tools. The EDC procurement checklist shows where security review fits in the wider buying process.

The questionnaire

Questions to ask, and what a good answer shows

The right-hand column gives Capture's answer where the question is about product capabilities. For certifications and procedural documents, request the current versions directly.

QuestionGood answer showsCapture
Where is data hosted, and can we choose?Named regions, customer choice, no silent transfersEU (Frankfurt) or US (N. Virginia), chosen at study setup
Is data encrypted at rest and in transit?Modern encryption on bothAES-256 at rest, TLS in transit
How is access controlled?Individual accounts, roles, least privilegeRole matrix per study and site; row-level security at the database layer
Is personal data separated from clinical data?Pseudonymisation for sponsor-side usersCoordinators see names; researchers see coded IDs
What does the audit trail record?Who, what, when, old and new value, whyEvery field change with user, time, old and new value and reason
Can the audit trail be modified?No; tamper-evidentAppend-only, SHA-256 hash chain with verification
How do electronic signatures work?Re-authentication and meaningPassword re-entry verified on the server; meaning stored
What is the password policy?Enforced, not advisoryExpiry every 90 days, enforced on the server
Can we export all our data at any time?Yes, in open formats, without feesCSV and Excel exports with data dictionary, any time
Certifications, pen tests, policiesCurrent reports and datesRequest current documentation from us
Backup, recovery and incident responseDocumented RPO/RTO, tested, notification commitmentsRequest current documentation from us
Subprocessors and data processing termsNamed list, DPA, change notificationRequest our DPA and subprocessor list

Hosting and residency

Choose where the data lives, per study

EU-sponsored studies usually want data in the EU; US studies often want it in the US. Capture lets you choose the hosting region at study setup, with encryption at rest and in transit either way.

  • EU (Frankfurt) or US (N. Virginia).
  • AES-256 at rest, TLS in transit.
  • Chosen at study setup.
GDPR compliant clinical trial software
Data residency
EU

EU (Frankfurt)

Default for EU-sponsored studies

US

US (N. Virginia)

Default for US-sponsored studies

AES-256 at rest TLS/SSL in transit Chosen at study setup

Access and privacy

Least privilege by default

Permissions follow a role matrix for every study and site: study owner, PI, sub-investigator, coordinator, monitor, data manager and participant. Site staff see only their assigned sites, and personal identifiers stay with the site while sponsor-side users see coded IDs.

  • Row-level security enforced in the database.
  • PII segregation between site and sponsor roles.
  • Expired accounts can read but cannot write or sign.
HIPAA compliant clinical trial software
  • SO

    Study owner

    Builds and configures the study

  • PI

    Principal investigator

    Oversees the site, signs off the casebook

  • SI

    Sub-investigator

    Enters and signs clinical data

  • SC

    Study coordinator

    Screens subjects, enters visit data

  • CRA

    Monitor (CRA)

    Verifies data, raises queries

  • DM

    Data manager

    Reviews, freezes and locks data

  • PT

    Participant

    Completes their own questionnaires

Answer half the questionnaire yourself

Open a free sandbox and inspect the roles, audit trail and signature controls directly.

Review Capture in a sandbox

Contracts

The contract questions security teams forget

Technical controls get most of the attention, but several of the most important protections live in the contract. Make sure the agreement covers them before signature, when you still have leverage.

Data ownership and exit

State that the sponsor owns the data, that full exports (including audit trails and metadata) are available at any time and at termination, and whether any fees apply. A vendor that charges heavily for exit makes future switches painful; see how to switch EDC vendors mid-study.

Breach notification

Specify how quickly the vendor must notify you of a personal data breach, so you can meet your own obligations (GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a reportable breach).

Subprocessors and audits

Require a list of subprocessors, notice before changes, and a right to audit or to receive audit reports. For US studies with covered entities, confirm how HIPAA obligations will be handled.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Why do sponsors send security questionnaires to EDC vendors?

Because GCP keeps the sponsor accountable for trial data held by vendors. The questionnaire documents that the vendor was assessed and supports ongoing oversight.

What should a clinical trial software security questionnaire cover?

Company and certifications, hosting and residency, encryption, access control, audit trail and signatures, backup and recovery, incident response, and subprocessors and contracts.

Where is Capture data hosted?

In the EU (Frankfurt) or the US (N. Virginia), chosen at study setup.

How is data encrypted?

AES-256 encryption at rest and TLS in transit.

Can we see the controls before buying?

Yes. The free sandbox includes roles, audit trail and electronic signatures, so your team can test them directly.

How do we get certifications and policies?

Contact us for current security documentation, data processing terms and the subprocessor list.

Verify the controls, not just the answers

Free sandbox with every feature. Security documentation on request.

Review Capture in a sandbox