Certara · partnership
A service provider licensed ANONYMIZE and runs it inside its own client delivery
- 850,000+
- pages anonymized
- 250+
- projects
- Since 2021
- ANONYMIZE licensed
Your name goes on the release decision. TrialAssure® provides a GDPR readiness service built for healthcare data privacy with quantified re-identification risk, consistent rule application, and a complete audit trail, so “we believe it’s compliant” becomes “here’s the number and here’s the record.”
For legal, privacy & compliance
Someone hands you a redacted document and asks whether it is safe to publish. For GDPR clinical trial data, a GDPR readiness service has to answer that with evidence. Quantified re-identification risk supports the judgment call with a number you can defend, and every transformation is logged and traceable.
WHAT CHANGES
Quantitative risk scores against your threshold give your team measurable evidence to support the release decision.
One engine applies the same rules every time — no operator-by-operator or vendor-by-vendor variation.
Risk-based, defensible anonymization aligned to both frameworks, with the anonymization-versus-pseudonymization distinction handled explicitly.
Every transformation is logged, timestamped, and traceable, giving your team a clear record to support audits and compliance reviews.
Security documentation pack on request — sub-processor list and DPA included, residency confirmed in writing; EU contracting via TrialAssure B.V. in Eindhoven.
Automated processing at scale with human sign-off on every release — that’s the model behind 850,000+ pages with one industry partner.
Define the acceptable re-identification risk and inventory the documents and datasets in scope for release. For EMA Policy 0070 and Health Canada PRCI, applicable risk thresholds help guide the anonymization approach.
ANONYMIZE transforms quasi-identifiers and offsets dates using patented (USPTO) methods, measuring residual risk against your threshold rather than blacking text out and destroying utility.
Your team or our transparency specialists verify the AI’s output and make the final decisions. AI Enabled. Human Driven.
Produce the quantified risk position and the complete audit trail, giving your team the clinical data privacy compliance evidence that stands up to a regulator, an auditor, or your own DPO.
Data privacy in healthcare does not stop at a single release. Maintain visibility into anonymization activity and status across teams, with a traceable record behind each release.
* Up to 80% is from an anonymous ANONYMIZE case study; results vary by document mix and release policy. The 850,000+ pages and 250+ projects are Certara partnership figures.
| Capability | TrialAssure | Generic redaction software | Manual judgment-call redaction |
|---|---|---|---|
| Re-identification risk | Quantified score against your threshold | No risk score produced | Reviewer’s judgment, undocumented |
| Method | Risk-based transformation (generalize, date-offset) | Black-box redaction | Manual black-out, case by case |
| Data utility | Preserved for scientific reuse | Degraded by over-redaction | Degraded and inconsistent |
| Audit trail | Every change logged and attributable | Limited or none | Reconstructed after the fact |
| Consistency | One engine, same rules every time | Varies by operator | Varies by person and vendor |
| Human oversight | Named-reviewer sign-off on every release | Tool-dependent | Present but rarely recorded |
| Defensibility | A number and a log | “We think it’s fine” | “We believe it’s compliant” |
Certara · partnership
It was great to collaborate with you on a strategic approach to CCI. This was one of our goals for the year!
SECURITY & COMPLIANCE
AI handles the time-intensive work. Your team or TrialAssure specialists review the output, with decisions captured in a traceable record.
Visit the Trust Center →Applies risk-based transformations and scores residual re-identification risk against your threshold.
Your team or our experts verify each release; sign-off is attributable to a named reviewer.
Every transformation is timestamped, attributable, and exportable for audit.
Risk-based anonymization with quantified re-identification risk and a complete transformation record.
See ANONYMIZE →Security architecture, certifications, and access to documentation including the sub-processor list and DPA.
Visit the Trust Center →Risk-based anonymization to support the public disclosure of clinical information in Europe.
See the requirement →Risk-based anonymization to support the public release of clinical information in Canada.
See the requirement →Self-assessment
Eight questions, two minutes, no form until the end. You get a readiness score by area and the three things to fix first. Email is only asked for if you want the full breakdown sent to you.
We’ll email your area-by-area scores with the specific Anonymization rules behind each question, and what a fix looks like at your scale. Work email, no newsletter unless you ask.
Regulatory guidance changes. Deadlines and requirements shown here are a summary, not legal advice — confirm them against the current text published by the relevant authority before you rely on them for a submission.
Under GDPR, truly anonymized data falls outside the Regulation’s scope, while pseudonymized data — reversible by design — remains personal data. In practice zero re-identification risk is not achievable, so the defensible standard for GDPR data anonymization is a risk you can measure and show, not a claim of perfection. TrialAssure ANONYMIZE® quantifies residual re-identification probability against the threshold you set, records which transformation was applied to each quasi-identifier, and keeps that methodology exportable. The distinction only helps you if you can evidence it: an unsupported assertion that data is anonymous is the hardest position to defend after the fact.
Re-identification risk is calculated as a probability and compared with a threshold you set before release, so the decision rests on a number rather than an opinion. The engine measures how uniquely the surviving quasi-identifiers — age, sex, site, visit dates, rare events — could single a participant out. The 0.09 (9%) reference threshold used by the EMA and Health Canada is a common starting point, and the score is taken against the highest-risk participant in the documents rather than an average, so one unusual case cannot hide behind the crowd. Scores above your threshold trigger further generalization and a rescore.
Redaction blacks out text; anonymization transforms it. Redaction produces no risk score and often destroys scientific value, because dose, timing and outcome context disappear along with the identifier. Anonymization generalizes values, offsets dates and masks quasi-identifiers so the data still supports analysis, then measures the residual re-identification risk. EMA and Health Canada guidance both favor risk-based anonymization over blunt redaction of personal data. Redaction still has a legitimate role for commercially confidential information, where the goal genuinely is to remove content rather than preserve its analytical value — the two techniques answer different questions, and most releases need both.
Transparency specialists sign off, not the model. The AI proposes transformations at scale; specialists review that work and correct it where it is wrong, so the release you sign off on has already been checked — with every verification logged, timestamped and attributable to a named reviewer. Nothing goes out on model output alone. That is what “AI Enabled. Human Driven.” means in practice, and for legal and privacy teams it matters twice over: you get a person who can explain a specific decision under questioning, and a record showing who made it and when — accountability that survives staff turnover.
No. Under our data processing terms, your data is not used to train public models, and it is never shared between customers. Processing runs in a closed, Azure-hosted environment with encryption in transit and at rest, so your documents are not handed to a third-party model provider to learn from. Those terms are documented in the Trust Center and repeated in the DPA, which means your privacy team can treat the commitment as a contractual obligation rather than a marketing line, and cite it directly in a vendor assessment or a record of processing activities.
The security architecture, our certifications, and how to request the security documentation pack — which contains the current sub-processor list and the DPA — are all set out in the Trust Center, so your privacy team can review them as part of its own assessment rather than waiting on a questionnaire response.
The platform runs on Azure as a closed system, with encryption in transit and at rest, and client data is never shared between customers. Where you need an EU counterparty, contracting runs through TrialAssure B.V. in Eindhoven. Exact region and residency options depend on how your instance is deployed, so we set them out in writing for your engagement rather than stating a single region here — worth settling before you scope a release rather than at contract stage.
Yes. Data processing agreements are available on request, and the DPA is the vehicle that turns the commitments described on this page into contractual terms — purpose limitation, confidentiality, security measures, breach response, sub-processor disclosure, and the term that your data is not used to train public models. For organizations that need an EU counterparty, contracting runs through TrialAssure B.V. in Eindhoven. The sub-processor list ships with the security documentation pack, requested through the Trust Center, so your privacy team can read it before legal review starts, which tends to shorten the negotiation rather than lengthen it.
TrialAssure is GDPR-aligned and HIPAA-aligned, and holds two ISO certifications: ISO 9001:2015 for quality management, certified by BSI under ANAB accreditation (certificate FS 797863, valid to 23 April 2027), and ISO/IEC 27001:2022 for information security, certified by Intertek under UKAS accreditation (certificate 0251375, valid to 18 July 2029). The distinction is worth being precise about: the ISO certificates are independently audited, while GDPR and HIPAA alignment describes how the platform and our processing terms are built to support your obligations as controller. The 27001 certificate is published in the Trust Center, and the wider security documentation pack is available on request for your procurement and security reviewers.
Yes. Every transformation is logged, timestamped and attributable to a named reviewer, and the record is exportable, so the audit response is a file you produce rather than a story you reconstruct. The trail shows what was changed, which method was applied, who reviewed it, and the residual risk score the release was signed off against — the four things an auditor, a DPO or opposing counsel actually asks for. Because the log is generated as the work happens, it does not depend on anyone remembering a decision made months or years earlier, which is where manual processes usually fail.
Manual redaction varies by person and by vendor, leaves an incomplete trail, and rests on judgment you may later have to defend without evidence. One engine applies the same rules to every document, scores the residual risk and records each change, so consistency stops depending on who was assigned the file and how late in the release window it landed. That is what replaces “we believe it’s compliant” with a number and a log. It does not remove judgment: you still set the threshold, define scope and sign off. It moves judgment to the decisions that deserve it, and out of every individual field-level call.
Either. You can license the platform and run releases with your own team, run it alongside our transparency specialists when volume spikes or in-house expertise is thin, or hand the whole package to TrialAssure Services and receive finished, signed-off deliverables. Defensibility does not change with the model: the same engine, the same threshold you set, the same named-reviewer sign-off and the same exportable audit trail in every case. Which model fits usually comes down to release volume and the review capacity you have, so it is worth talking through before you scope the work.
TrialAssure anonymizes clinical documents and datasets using risk-based methods that score re-identification probability against a defined threshold that you set and log transformations for traceability. Legal, privacy, and compliance teams get a quantified risk number and a complete audit trail, turning “we believe it’s compliant” into “here’s the number and here’s the record.”
When your name goes on a data release, “reasonable effort” is not a position you want to defend after the fact. Regulators and auditors want to know how risk was measured and how decisions were made. TrialAssure ANONYMIZE® answers both. It applies risk-based anonymization — generalizing values, offsetting dates with patented (USPTO) methods, and transforming quasi-identifiers — then scores the residual re-identification risk against a threshold that you set. The output gives your team measurable evidence to support the judgment call.
Redaction removes information from view, but it does not quantify re-identification risk and can reduce the scientific value of the data. Risk-based anonymization measures re-identification probability against a defined threshold while preserving data utility. One quantified methodology can support requirements across jurisdictions, helping your team maintain a consistent approach for regulatory disclosure, data-sharing requests, and partner needs.
Every transformation that TrialAssure ANONYMIZE applies is logged, timestamped, and attributable. When a DPO, an auditor, or a legal team asks how information was handled or anonymized, the answer is readily available rather than reconstructed. That traceability gives compliance teams a clear view of the decisions behind each release instead of chasing records across teams and vendors.
The Trust Center sets out the security architecture, certifications, and how to request the security documentation pack, which contains the current sub-processor list, our Statement of Applicability, and the DPA. Data residency is deployment-specific, so exact region and residency options are confirmed in writing for each engagement. DPAs are available on request, EU contracting runs through TrialAssure B.V. in Eindhoven, and under our data processing terms, your data is never used to train public AI models.
You can license the platform, work alongside our transparency specialists, or let TrialAssure manage the package. The wider disclosure workflow shows how anonymization fits into the full release process. For public records rather than clinical data, explore our government solution for FOIA and public-records redaction.
Tell us what is in scope: the studies and documents you need released, the risk threshold you have to meet, and when it is due. We come back with who would run it, what the work takes at that volume, and how soon we can start, whether you license ANONYMIZE or hand the package to our transparency specialists for finished, signed-off deliverables. A privacy specialist replies within one business day.
A quantified risk number and a complete audit trail — on every release.