Architecture and Assurance Roadmap
PrismCDM is architected around the regulatory frameworks our customers operate under. Independent assurance and external attestation sit on top of that architecture and follow our product maturity roadmap. This page lists what is implemented today, what independent validation is in progress, and what attestations are planned next.
1. Architecture precedes attestation
The platform is architected around controls that align with the objectives of the regulatory frameworks our customers operate under. Formal attestations provide independent validation of those controls as the platform and company mature.
We make commitments in two stages. The architectural commitments are made on day one of every customer engagement, regardless of which attestations have been issued. The attestation commitments follow as customer demand, regulatory evolution, and platform maturity make them useful.
2. The roadmap at a glance
Items move from Planned to In Progress to Current as the corresponding work is completed and, where applicable, independently validated.
- Source Fidelity
- Provenance Engine
- Append-only audit chain
- Tenant isolation enforced at the data layer
- Integrity protection on every Brief
- 21 CFR Part 11 alignment
- HIPAA alignment
- GDPR alignment
- Independent 21 CFR Part 11 validation
- SOC 2 Type I readiness
- Third-party penetration testing program
- SOC 2 Type II
- ISO 27001
- HITRUST consideration
- EU AI Act readiness review
3. Architecture implemented vs independent assurance
The distinction between architectural implementation and independent external assurance is important and easily confused. The table below makes it explicit.
| Capability | Architecture Implemented | Independent Assurance |
|---|---|---|
| Source Fidelity | Yes | Architecture review during Compliance Review |
| Provenance Engine | Yes | Architecture review during Compliance Review |
| Append-only audit | Yes | Independent Part 11 validation (In Progress) |
| Tenant isolation | Yes | SOC 2 (In Progress) |
| 21 CFR Part 11 alignment | Yes | Independent Part 11 validation (In Progress) |
| SOC 2 | In progress | SOC 2 Type I (In Progress); Type II (Planned) |
| ISO 27001 | Planned | Planned |
These controls are implemented in the platform regardless of whether a formal attestation has been completed.
4. Why this order?
PrismCDM prioritizes architectural controls before independent attestations because durable platform controls benefit every customer immediately, while attestations validate those controls at defined points in the company's maturity. Architecture is the substrate; attestation is the audit of the substrate.
5. Evidence produced today
One concern enterprise procurement teams have about an in-progress SOC 2 is: what evidence can you show me today? The answer is below. The evidence is real; the format is shared during the Compliance Review under NDA.
| Evidence | Availability |
|---|---|
| Architecture documentation | Available during Compliance Review |
| Security design overview | Available during Compliance Review |
| Source Fidelity specification | Available during Compliance Review |
| Provenance specification | Available during Compliance Review |
| Penetration test summary (when available) | Available during Compliance Review |
| SOC 2 readiness package | Available during Compliance Review |
| Risk register | On request during Compliance Review |
6. Assurance mapping
Each capability the platform implements maps to one or more independent assurance mechanisms. The mapping makes the relationship between architecture and attestation visible.
| Requirement | Implementation | Independent Assurance |
|---|---|---|
| Auditability | Implemented | Independent Part 11 validation (In Progress) |
| Access control | Implemented | SOC 2 (In Progress) |
| Encryption | Implemented | SOC 2 (In Progress) |
| Tenant isolation | Implemented | SOC 2 (In Progress) |
| Provenance | Implemented | Architecture review during Compliance Review |
| Source Fidelity | Implemented | Architecture review during Compliance Review |
| AI governance | Implemented | Documented in the Responsible AI Architecture |
7. In progress in detail
- Independent 21 CFR Part 11 validation. Independent validation of the Part 11 architectural alignment. The platform is architected against the Part 11 objectives today; independent validation issues formal evidence against them.
- SOC 2 Type I readiness. Security, availability, processing integrity, confidentiality, and privacy controls under active review. Formal audit engagement targeted within the design partner phase.
- Third-party penetration testing program. Annual third-party penetration tests of the platform with documented findings and remediation tracking.
8. Planned in detail
- SOC 2 Type II. Continuous-operation attestation following SOC 2 Type I.
- ISO 27001. Information security management system certification.
- HITRUST consideration. Evaluating HITRUST CSF certification as customers in healthcare segments express demand.
- EU AI Act readiness review. Structured review of platform features and customer use cases against the AI Act's obligations as it enters force.
9. What we do not promise
PrismCDM does not promise to be certified against every framework at every moment. We make architectural commitments that benefit every customer immediately, and we add formal attestations as they become useful to our customers. We do not market against attestations we have not earned.
10. How we communicate updates
Material movements on this roadmap (an item moving from Planned to In Progress to Current) are reflected here and communicated through the platform or by email to commercial customers where required by the executed agreement.
11. Customer-driven additions
If a regulatory framework or attestation is material to your evaluation of PrismCDM and is not represented above, we want to know. Contact us through /contact with reason “Compliance Review”. Customer demand is the most important signal for prioritizing additions to the Planned column.
12. The PrismCDM objective
Our objective is not to accumulate certifications. Our objective is to build a platform whose architecture supports regulated clinical development, then obtain independent assurance that validates those architectural commitments over time.
13. Related Trust Center documents
- Version
- 1.0
- Effective Date
- July 2026
- Last Updated
- July 2026