Skip to main content
Trust Center

Architecture and Assurance Roadmap

PrismCDM is architected around the regulatory frameworks our customers operate under. Independent assurance and external attestation sit on top of that architecture and follow our product maturity roadmap. This page lists what is implemented today, what independent validation is in progress, and what attestations are planned next.

1. Architecture precedes attestation

The platform is architected around controls that align with the objectives of the regulatory frameworks our customers operate under. Formal attestations provide independent validation of those controls as the platform and company mature.

We make commitments in two stages. The architectural commitments are made on day one of every customer engagement, regardless of which attestations have been issued. The attestation commitments follow as customer demand, regulatory evolution, and platform maturity make them useful.

2. The roadmap at a glance

Items move from Planned to In Progress to Current as the corresponding work is completed and, where applicable, independently validated.

Current
  • Source Fidelity
  • Provenance Engine
  • Append-only audit chain
  • Tenant isolation enforced at the data layer
  • Integrity protection on every Brief
  • 21 CFR Part 11 alignment
  • HIPAA alignment
  • GDPR alignment
In Progress
  • Independent 21 CFR Part 11 validation
  • SOC 2 Type I readiness
  • Third-party penetration testing program
Planned
  • SOC 2 Type II
  • ISO 27001
  • HITRUST consideration
  • EU AI Act readiness review

3. Architecture implemented vs independent assurance

The distinction between architectural implementation and independent external assurance is important and easily confused. The table below makes it explicit.

CapabilityArchitecture ImplementedIndependent Assurance
Source FidelityYesArchitecture review during Compliance Review
Provenance EngineYesArchitecture review during Compliance Review
Append-only auditYesIndependent Part 11 validation (In Progress)
Tenant isolationYesSOC 2 (In Progress)
21 CFR Part 11 alignmentYesIndependent Part 11 validation (In Progress)
SOC 2In progressSOC 2 Type I (In Progress); Type II (Planned)
ISO 27001PlannedPlanned

These controls are implemented in the platform regardless of whether a formal attestation has been completed.

4. Why this order?

PrismCDM prioritizes architectural controls before independent attestations because durable platform controls benefit every customer immediately, while attestations validate those controls at defined points in the company's maturity. Architecture is the substrate; attestation is the audit of the substrate.

5. Evidence produced today

One concern enterprise procurement teams have about an in-progress SOC 2 is: what evidence can you show me today? The answer is below. The evidence is real; the format is shared during the Compliance Review under NDA.

EvidenceAvailability
Architecture documentationAvailable during Compliance Review
Security design overviewAvailable during Compliance Review
Source Fidelity specificationAvailable during Compliance Review
Provenance specificationAvailable during Compliance Review
Penetration test summary (when available)Available during Compliance Review
SOC 2 readiness packageAvailable during Compliance Review
Risk registerOn request during Compliance Review

6. Assurance mapping

Each capability the platform implements maps to one or more independent assurance mechanisms. The mapping makes the relationship between architecture and attestation visible.

RequirementImplementationIndependent Assurance
AuditabilityImplementedIndependent Part 11 validation (In Progress)
Access controlImplementedSOC 2 (In Progress)
EncryptionImplementedSOC 2 (In Progress)
Tenant isolationImplementedSOC 2 (In Progress)
ProvenanceImplementedArchitecture review during Compliance Review
Source FidelityImplementedArchitecture review during Compliance Review
AI governanceImplementedDocumented in the Responsible AI Architecture

7. In progress in detail

  • Independent 21 CFR Part 11 validation. Independent validation of the Part 11 architectural alignment. The platform is architected against the Part 11 objectives today; independent validation issues formal evidence against them.
  • SOC 2 Type I readiness. Security, availability, processing integrity, confidentiality, and privacy controls under active review. Formal audit engagement targeted within the design partner phase.
  • Third-party penetration testing program. Annual third-party penetration tests of the platform with documented findings and remediation tracking.

8. Planned in detail

  • SOC 2 Type II. Continuous-operation attestation following SOC 2 Type I.
  • ISO 27001. Information security management system certification.
  • HITRUST consideration. Evaluating HITRUST CSF certification as customers in healthcare segments express demand.
  • EU AI Act readiness review. Structured review of platform features and customer use cases against the AI Act's obligations as it enters force.

9. What we do not promise

PrismCDM does not promise to be certified against every framework at every moment. We make architectural commitments that benefit every customer immediately, and we add formal attestations as they become useful to our customers. We do not market against attestations we have not earned.

10. How we communicate updates

Material movements on this roadmap (an item moving from Planned to In Progress to Current) are reflected here and communicated through the platform or by email to commercial customers where required by the executed agreement.

11. Customer-driven additions

If a regulatory framework or attestation is material to your evaluation of PrismCDM and is not represented above, we want to know. Contact us through /contact with reason “Compliance Review”. Customer demand is the most important signal for prioritizing additions to the Planned column.

12. The PrismCDM objective

Our objective is not to accumulate certifications. Our objective is to build a platform whose architecture supports regulated clinical development, then obtain independent assurance that validates those architectural commitments over time.

13. Related Trust Center documents

Version
1.0
Effective Date
July 2026
Last Updated
July 2026