The Trusted Operating System
for Clinical Development.
PrismCDM is designed for regulated clinical development. Trust is its primary differentiator. The trust architecture, security practices, and provenance commitments below are the foundation everything else stands on.
Don't trust us. Verify us. Every recommendation traces to its protocol source, engine version, evidence record, and build.
The full enterprise security and compliance package.
The architecture story, the legal documents, the AI policy, the subprocessor categories, and the roadmap. Procurement, legal, security, and compliance teams can read every pillar before the first conversation.
Security
The architectural posture. Engineering Trust, Infrastructure, Authentication, Encryption, Vulnerability Management, Logging, Incident Response, Responsible AI, and the Compliance Roadmap.
ReadPrivacy
GDPR-aligned scope, AI and customer data commitments, data ownership, regulatory boundary, subprocessors, and international transfer safeguards.
ReadTerms of Service
Terms for the website and Evaluation Services. Commercial use is governed by separately executed agreements.
ReadResponsible AI Architecture
AI operates inside a governed execution architecture. Four guardrails (Source Fidelity, Provenance, Structural Validation, Human Governance) constrain every AI output.
ReadSubprocessors and Trust Boundary
PrismCDM does not outsource trust. Third parties supply infrastructure; provenance, evidence classification, and regulated execution stay under our control.
ReadData Processing Agreement
Article 28 GDPR controller-processor terms, SCCs, UK Addendum, and the subprocessor controls customers expect.
ReadBusiness Associate Agreement
HIPAA 45 CFR 164.504 framework. PHI handling, breach notification, subcontractor flow-through, return or destruction.
ReadArchitecture and Assurance Roadmap
Architecture precedes attestation. Current architectural controls, in-progress independent validations, and planned external attestations.
ReadMethodology
The methodology and engineering behind every Brief. PTII™ + 5 sub-indices, Evidence Classification, integrity anchors, and the engine versioning stack.
Read
Built on the regulations that govern clinical data.
Audit chain architecture
Designed to support 21 CFR Part 11 controls. Append-only audit_events table backs every regulated action. Electronic signature ceremony per §11.50; signature manifests per §11.200. Source attribution per row enables defensible regulatory submission.
Aligned data handling
Multi-tenant isolation with row-level security on every PHI-bearing table. Encryption at rest + in transit. Operator action logging via the same Part 11 audit chain that backs every regulated event.
Readiness in progress
Security, availability, processing integrity, confidentiality, and privacy controls under continuous review. Formal audit engagement targeted within the design partner phase.
Aligned workflow controls
Workflow definitions encode GCP-aligned cascade controls. Amendment workflow enforces re-consent + re-training cascades on the regulated schema changes that trigger them.
SDTM + ADaM + Define-XML
SDTM IG v3.4, ADaM IG v1.3, Define-XML v2.1, NCI CT, MedDRA, WHODrug, CDASH. Every pin recorded at protocol upload time + frozen for the lifetime of the protocol version.
Evidence classification on every value
Displayable values must be sourced, generated by PrismCDM, or explicitly marked representative. The Source Fidelity Architecture program enforces this on every displayable value: Phase 3 CI gate scans every PR; Phase 4 runtime gate fails closed on render.
Three public sources of truth, on the roadmap.
When they ship, each becomes a live dashboard reachable from this page. Until then, they are scheduled commitments against the design partner phase.
Live Platform Status
Real-time view of platform health: API uptime, deployment status, ongoing incidents. Updated continuously.
Product Roadmap
What we are working on now, next, and later. Public commitments + delivery dates against the design partner phase.
Validation Posture
The validation package for every regulated workflow. Test counts, last-validation timestamps, downloadable evidence.
Every regulated conclusion in PrismCDM carries a continuous provenance chain.
From the original protocol through AI assessment, operational execution, evidence generation, regulatory submission, and inspection. Intelligence is explainable. Execution is traceable. Submission is defensible.
Get the current trust and compliance package.
For inspectors, auditors, and compliance teams: request the current trust and compliance package covering audit chain architecture, electronic signature controls, multi-tenant isolation, source attribution discipline, and the running Source Fidelity program.