Certara
A service provider licensed ANONYMIZE and runs it inside its own client delivery
- 850,000+
- pages
- 250+
- projects
PROTECT & SHARE
Patient privacy and data utility should work together. TrialAssure ANONYMIZE® delivers regulatory-grade, risk-based data anonymization that reduces and quantifies re-identification risk while preserving the value of clinical information across documents, datasets, and images.
* Anonymous ANONYMIZE case study. Results vary by document mix; every decision human-verified.
Track record
Who it is for
TrialAssure ANONYMIZE gives teams a quantified re-identification risk assessment across documents, datasets, and images, helping replace subjective judgment with measurable evidence. The patented clinical trial data anonymization software is designed to help experts make informed, defensible decisions about what can be safely shared.
Product tour
Seven steps, no form: the documents grid, the workbench, the markup review, and the audit trail — the way the product actually presents them. Simulated interface, fictional data.
Simulated product interface · fictional study data (“Zinon”, Regax Inc.)
| Delete | Select | Action | Document | Pages | Description | Document Status | Created By | Created Date | Last Run Date |
|---|---|---|---|---|---|---|---|---|---|
| Sample Title Page and Narrative.pdf | 3 | Draft | M. Researcher | Jul 29 2026 07:30 AM | Aug 26 2026 07:34 AM | ||||
| CSP sample.pdf | 4 | Draft | M. Researcher | Aug 13 2026 09:41 AM | Aug 13 2026 10:00 AM | ||||
| Subject Narratives 014.pdf | 3 | Draft | M. Researcher | Aug 24 2026 07:21 AM | Aug 26 2026 03:56 AM |
| Protocol Number: | PRM001 |
| Title: | Physiological Magnesium Maintenance in Chronic Renal Disease Subjects Requiring Dialysis by Delivery of Zinon via Hemodialysate |
| Test Drug: | Zinon |
| Indication: | Magnesium maintenance in subjects with chronic renal disease |
| Study Design: | Prospective, randomized, placebo-controlled, double-blinded, multicenter, clinical study |
| Study Phase: | Phase 3 |
| Study Dates: | 20 Jan 2025 (first subject first visit) to 14 Jun 2026 (last subject last visit) |
| Early Termination: | Not applicable |
| Principal Investigator: | Evan Underhill, MD Company X 222 Company Way Novidane, ND 58105 eunderhill@companyx.com |
| Sponsor Signatory: | Eve Greig, Chief Medical Officer Phone: 111-246-4578; FAX: 111-246-4578 egreig@companyx.com |
| Sponsor: | Regax, Inc. |
| Document Date: | 12 February 2026 |
This study was conducted in compliance with Good Clinical Practices, including the archiving of essential documents.
Every document in a project runs against one reusable rule set. Open the Workbench on a document.
Growing volumes of clinical information can make manual anonymization difficult to manage consistently. Risk-based anonymization gives teams a more measurable approach, helping quantify re-identification risk while preserving data utility across documents, datasets, and images.
Large volumes of clinical information still need to be reviewed against fixed deadlines. As programs grow, so does the burden on the people responsible for anonymization and QC.
Manual decisions can vary across reviewers and projects. Standardized rules and data de-identification tools help teams apply anonymization approaches more consistently across clinical information.
Removing more information than necessary can limit the scientific value of deidentified data. Risk-based anonymization helps teams protect patient privacy while preserving information that can be safely shared.
Frameworks including EMA Policy 0070 and Health Canada PRCI place importance on protecting participant privacy as well as preserving the usefulness of clinical information. A re-identification risk assessment gives teams quantitative evidence to support those decisions.
Context-aware AI goes beyond keyword-matching data de-identification tools to identify PII, PHI, and CCI across documents, datasets, and images, including scanned content with OCR.
The risk engine performs a re-identification risk assessment, quantifies the probability of re-identification, and helps determine the appropriate transformation based on the defined threshold.
Standardized rules apply anonymization, redaction, masking, pseudonymization, and other techniques consistently across documents, datasets, and images, helping preserve the utility of deidentified data.
Human experts review flagged decisions and confirm the output, with actions captured in a traceable audit trail.
The page still answers the research question.
That is the entire difference between risk-based anonymization and a black rectangle.
Watch
Certara
850,000+ pages anonymized across 250+ projects with Certara
Every detection, risk score, and transformation is logged and traceable, giving teams a clear record of how anonymization decisions were made. TrialAssure ANONYMIZE operates in a closed, Azure-hosted environment, and client data is never used to train public AI models.
Visit the Trust Center →When used with other TrialAssure products, anonymized content can connect with TrialAssure REGISTRY® for clinical trial disclosure and TrialAssure LINK® AI for AI-assisted medical writing, reducing manual handoffs and duplicate entry.
Your team, our technology. Full control and traceability.
Get a demoAdd anonymization expertise and capacity when you need it.
Talk to our teamSend us your documents, datasets, and/or images. We’ll manage the anonymization process.
Explore servicesRedaction removes information from view, masking replaces or obscures specific information, and anonymization transforms information to reduce the risk that an individual can be re-identified while preserving data utility. ANONYMIZE supports multiple techniques and uses risk-based anonymization to help teams determine the appropriate approach based on the information, regulatory requirements, and acceptable re-identification risk.
TrialAssure ANONYMIZE quantitatively assesses the probability that an individual could be re-identified from clinical information and compares that risk against an established threshold. The assessment considers combinations of quasi-identifiers such as dates, ages, sites, and rare events, helping teams understand risk beyond direct identifiers alone. When risk exceeds the defined threshold, ANONYMIZE helps identify appropriate transformations to reduce it while preserving data utility. The risk score, rules applied, and resulting decisions are captured for traceability and human review.
TrialAssure ANONYMIZE supports documents, datasets, and images, giving teams one risk-based approach across different types of clinical information. This includes unstructured documents, structured datasets such as SAS and XPT, scanned content through OCR, and DICOM medical imaging. Applying consistent rules and risk assessment across formats helps protect sensitive information wherever it appears while preserving data utility.
TrialAssure ANONYMIZE supports anonymization and de-identification requirements across EMA Policy 0070, Health Canada PRCI, HIPAA, GDPR, and FOIA. Built-in rules and risk thresholds give teams a starting point for applying the appropriate approach across different regulatory frameworks. For HIPAA de-identification, ANONYMIZE supports both Safe Harbor and Expert Determination approaches. For risk-based frameworks such as Policy 0070, the platform helps teams quantify re-identification risk and apply appropriate transformations while preserving data utility.
Yes. You can license TrialAssure ANONYMIZE and manage the process in-house, work alongside TrialAssure’s data anonymization experts, or have our team manage the work for you. The same technology, rule sets, risk model, and audit trail support each approach, giving you the flexibility to choose the level of support that fits your team.
Microsoft Office files, emails, CSV, SAS, XPT and PDF, plus scanned documents and images through OCR and DICOM medical imaging. Format coverage matters more than it sounds: a submission package mixes native documents, legacy scans, and analysis datasets, and anything the engine cannot open has to be redacted by hand — which is exactly where rules start drifting between reviewers. If a format you use is not listed, talk with our team about your specific requirements.
Rule-based transformations: scrambling patient IDs to pseudonymize them, masking company and patient information, shifting dates, generalizing ages into ranges, and applying full or pseudo-anonymization — all managed from one centralized view of every project and task. Each rule is chosen for what the risk score requires rather than applied uniformly, so a date can be offset instead of deleted and an age can become a band instead of a blank. Our date-offset method is patented with the USPTO. Because rules are defined once and applied across the corpus, the same identifier is handled the same way in every document.
Yes. DICOM is the third modality alongside documents and datasets. ANONYMIZE transforms the identifying metadata attached to each image — age, demographics, dates — using the same risk-based rules, the same thresholds and the same audit trail as your documents and datasets, so imaging travels with the rest of the trial record instead of sitting in a separate manual process beside it. The honest limit: pixel-level work, such as blurring or facial de-identification, is a custom engagement rather than part of the standard product.
Replacements are fitted to the page: pagination, layout, and tables stay intact even when a substitution runs longer than the original text, so the anonymized document reads like it was written that way — not a patchwork. That matters because a substitution that breaks pagination can also break the cross-references that make the document reviewable — the failure mode that separates purpose-built clinical document redaction software from a generic PDF editor.
Yes. Context-aware AI rules distinguish where a term appears, not merely that it appears: “type 2 diabetes” in a subject’s medical history can be generalized, because history combined with dates and site narrows the population, while the same words in an adverse-event table or lab listing are left alone — there they are the finding, not an identifier. That contextual layer is what lets you take out just enough instead of blanket-redacting every match, and it is the difference between a document that still answers a research question and a page of black boxes. Flagged context decisions go to a specialist for sign-off.
Voice and video are available as custom solutions rather than part of the standard product. Voice masking changes the speaker’s voice while preserving the speech pattern under study — a stutter or a slur stays audible, the identity does not — which matters when the recording itself is the measurement. Video is handled case by case, because what identifies a participant differs between a movement recording and a clinic consultation. Describe the recording types in your program and we can tell you what is feasible before you plan around it: contact us.
Send a few documents that look like the ones you actually release. We will run them and walk you through the risk report they produce — including where the engine would over-redact and how your reviewer overrides it. A specialist replies within one business day.