Frequently Asked Questions
The questions every sponsor, CRO, QA, security, and procurement team asks before adopting a regulated clinical platform. Where a direct answer exists, we give it. Where deeper review is required, we explain what happens next.
Compliance and regulation.
Is PrismCDM 21 CFR Part 11 compliant?
PrismCDM is built on the architectural primitives required by 21 CFR Part 11: append-only audit, identity-bound signatures, tamper-evident artifacts, complete provenance, and runtime validation.
Independent validation and formal attestations follow our product maturity roadmap. The current architectural posture is documented in the Trust Center.
Is PrismCDM HIPAA-aligned?
PrismCDM is architected for HIPAA-aligned handling of protected health information: tenant isolation, encryption at rest and in transit, least-privilege access, comprehensive audit, and Business Associate Agreement support. Coverage details and architecture diagrams are shared during the Compliance Review under NDA.
What about ICH GCP and CDISC?
PrismCDM treats ICH GCP and the CDISC family (SDTM, ADaM, Define-XML) as REFERENCE_STANDARDs in the evidence classification taxonomy. Any displayed value tied to one of these standards is citable to the standard at runtime.
Has PrismCDM completed SOC 2?
SOC 2 Type 1 readiness is in progress, with Type 2 planned to follow. See the Trust Center for the current roadmap.
Security and data handling.
How is tenant data isolated?
Every value in PrismCDM carries an evidence classification, and CUSTOMER_SOURCE values never cross tenant boundaries. Tenant isolation is enforced at the data layer, not just at the UI layer. Architecture diagrams are shared during the Compliance Review under NDA.
Where is data hosted?
Production runs on managed infrastructure with full encryption at rest and in transit, isolated per region as required by customer policy. Specific region availability is covered in the Compliance Review.
Can PrismCDM be deployed in our private cloud?
Single-tenant and private-cloud deployment options are part of the conversation in the Compliance Review and in the Strategy Session. They are evaluated case by case based on the customer's regulatory posture and operational needs.
Who owns our data?
The customer owns their data. PrismCDM processes it under the Business Associate Agreement and the master services agreement; the underlying data, the protocols, the operational decisions, and the resulting artifacts remain customer property. Specific data-ownership and exit terms are covered in the commercial agreement and in the Compliance Review.
Integrations and interoperability.
Does PrismCDM integrate with our existing EDC?
PrismCDM is designed to interoperate with existing EDC environments or operate as the primary clinical data platform, depending on customer architecture. Specific EDC integrations are prioritized through the Strategy Session and design partner conversations.
Can PrismCDM run without replacing our existing systems?
Yes. PrismCDM is built as a substrate that can operate alongside the operational tools you already use, contributing Trial Intelligence, evidence, and provenance into your existing workflow without requiring a rip-and-replace. Where deeper integration unlocks more value, that integration is staged and documented during implementation.
How does PrismCDM connect to ClinicalTrials.gov?
PrismCDM ingests the public protocol record as PUBLIC_SOURCE evidence. Every value derived from ClinicalTrials.gov carries the source citation at runtime.
What about CTMS, eTMF, RTSM?
PrismCDM is built for interoperability with the operational tools around the study. Integration scope and depth are part of the implementation conversation, not a fixed checklist.
Evaluation, availability, and commercial terms.
What does evaluation look like?
Most evaluations start with generating a Brief from a public NCT identifier. That takes a few minutes and demonstrates the category without any commercial commitment.
For evaluation on a proprietary protocol, a Strategy Session is the next step. We walk every finding, every recommendation, and every provenance trail with your team.
Procurement and the Compliance Review typically run in parallel with the Strategy Session sequence. We share the current compliance package under NDA when requested.
Is PrismCDM generally available?
PrismCDM is currently available to a limited number of organizations as we expand the platform with design partners.
Can we validate the platform ourselves?
Yes. PrismCDM is designed to be independently validated by the customer's QA, regulatory, and security teams. Architecture documentation, evidence classification rules, integrity anchors, runtime validation behavior, and the Source Fidelity Architecture are all available during the Compliance Review under NDA.
Customer validation packages are versioned against the same Engine Version, Assessment Version, Corpus Snapshot, and Platform Build that produced the artifacts being validated. Re-running the same inputs reproduces the same outputs.
What does pricing look like?
Pricing depends on deployment model, study portfolio, implementation scope, and support requirements. We discuss commercial options during the Strategy Session after understanding your environment.
How long does onboarding take?
Most organizations generate their first Trial Intelligence Brief within days of onboarding. Operational rollout is staged according to implementation scope and integration requirements.
Product and methodology.
What is the Trial Intelligence Brief?
The Brief is the first artifact PrismCDM produces from a protocol. See the Trial Intelligence Brief Guide for the full structure.
What is PTII™?
PTII™ is the composite Prism Trial Intelligence Index over five explainable sub-indices (PCI, OBI, ESI, ARI, EVI). See the Trial Intelligence Methodology for the full definition.
How is PrismCDM different from a generic AI tool?
AI tools produce answers. PrismCDM produces a regulated artifact with sourced values, integrity anchors, and operational follow-through. See the AI Assistant vs Clinical Operating System resource for the category-level comparison.
How does PrismCDM handle AI model updates?
Every generated artifact records the Engine Version, Assessment Version, Corpus Snapshot, and Platform Build used during generation. Regulated outputs remain reproducible even as the platform evolves.
Model upgrades produce new Engine Versions; they do not retroactively change the conclusions in historical Briefs. The four-anchor integrity chain makes the relationship between any artifact and the platform that produced it inspectable forever.