Your security review, answered.
TrialAssure security posture, certifications, data handling, sub-processors, and how our AI is governed — documented here, downloadable, and kept current.
Credentials
Certifications & compliance
Third-party audited certifications are shown with their issuing body, certificate number and expiry. Where we state alignment rather than certification, we say so.
-
Certified
Information security
ISO/IEC 27001:2022
View certificate PDF(opens in a new tab) -
Certified
Quality management
ISO 9001:2015
View certificate PDF(opens in a new tab) -
Aligned
Data protection
GDPR
EU entity: TrialAssure B.V., Eindhoven. DPA available; sub-processor list on request.
-
Aligned
Protected health data
HIPAA
Aligned handling for protected health information across data and documents.
Certified rows are independently audited. Full scope, our Statement of Applicability, the DPA and sub-processor list are in the security documentation pack — request it here.
Architecture
Security architecture
Everything runs inside a closed, Azure-hosted environment that is audited under our ISO/IEC 27001:2022 scope.
Built with Microsoft, OpenAI and NVIDIA technologies and programs — all inside that boundary.
Closed-system deployment
Azure-hosted and closed by design. Your documents and datasets are processed inside that boundary, not used to train public AI models.
Encrypted in transit and at rest
Encryption applied to data moving between services and to data stored at rest.
Your data never trains public models
Client data is not used to train public models and is not shared between customers. It is written into our AI Policy, not just promised.
Access control, logging and monitoring
Role-based access, activity logging and monitoring, all within the audited ISMS scope.
Technology
What the platform is built on
Governance
How the AI is governed
AI Enabled. Human Driven.™ is an architecture, not a tagline — here is what enforces it.
Human in the loop, structurally
AI-assisted work is designed for human review and approval. The checkpoint is built into the workflow, keeping experienced professionals in control of the final output.
Source-referenced drafting
Every drafted statement carries the source document and passage it came from, so a reviewer can verify rather than trust.
Audit trail
Every transformation is logged and attributable — who ran it, what changed, and when.
Model isolation
Models run in a closed environment. No client data goes into public-model training.
How do I complete a security review of TrialAssure?
Start with the certification table above, which separates independently audited certifications from frameworks we align to. Then read the architecture and AI-governance sections, which describe where your data is processed and what stops it reaching a public model. Anything not published here — full ISO scope, our Statement of Applicability, the DPA, the sub-processor list — is available on request.
“Certified” and “aligned” are not the same claim
We label them differently on purpose, because the distinction matters. ISO/IEC 27001:2022 and ISO 9001:2015 are certified: a third party audited them, and the certificate carries an issuing body, a number and an expiry you can check. GDPR and HIPAA are aligned: we handle data to meet those requirements, but no external auditor issues a certificate against them. That distinction gives security and compliance teams a clearer picture of what has been independently audited and what represents our alignment with applicable requirements.
Where the work happens
Everything runs inside a closed, Azure-hosted environment audited under our ISO/IEC 27001:2022 scope with client data isolated from public-model training. Data is encrypted in transit and at rest, access is role-based, and activity is logged and monitored within that audited boundary. Delivery work is performed from our two offices: our U.S. headquarters in Canton, Michigan, and TrialAssure B.V. in Eindhoven, Netherlands.
What we will not do with your data
Client data is never used to train public models and is never shared between customers. That is written into our AI Policy rather than left as a reassurance in a sales call, and model isolation is the architectural reason it holds: the models run inside the same closed environment as everything else.
What to ask us for
Security teams usually want the full ISO/IEC 27001 scope statement and Statement of Applicability, the Data Processing Agreement, the current sub-processor list, and our AI Policy. Both ISO certificates are already published above. Send your questionnaire and we will complete it against these rather than returning a brochure. If your review also covers how anonymization decisions are evidenced, ANONYMIZE sets out the risk model and legal, privacy & compliance covers the defensibility argument.
TrialAssure security & compliance — FAQ
Is our data used to train AI models?
No — your documents, datasets and prompts are never used to train public models, and they are never shared between customers. Models run inside a closed, Azure-hosted environment that falls within our ISO/IEC 27001:2022 audit scope, so the isolation is a property of how the system is deployed rather than a setting someone could switch off. Client data is encrypted in transit and at rest, and access to it is role-based, logged and monitored. The commitment is written into our AI Policy, not just promised, and the security documentation pack includes the sub-processor list showing which services touch your data at all.
Where is data processed and stored?
Processing and storage run on Azure-hosted infrastructure inside a closed environment covered by our ISO/IEC 27001:2022 scope, and EU customers can contract with TrialAssure B.V. in Eindhoven, so the contracting entity sits in the EU. Your documents and datasets are handled inside that boundary rather than on shared public services, with encryption in transit and at rest and role-based access, logging and monitoring around them. Exact region and residency options depend on how your instance is deployed, so we set them out in writing in the security documentation pack, alongside the sub-processor list and the DPA, rather than generalizing here.
Which certifications do you hold?
ISO/IEC 27001:2022 for information security, certified by Intertek under UKAS accreditation (certificate 0251375, valid to 18 July 2029), and ISO 9001:2015 for quality management, certified by BSI under ANAB accreditation (certificate FS 797863, valid to 23 April 2027). Both certificates are published above. For data protection we are GDPR-aligned, with an EU contracting entity in Eindhoven, and our handling of protected health information is HIPAA-aligned. Scope statements, our Statement of Applicability and the DPA are in the security documentation pack.
Can we get your security documentation?
Yes — request the pack via the button above and your security team gets what it needs to complete a review without a sales call first. It contains the architecture summary, the ISO/IEC 27001:2022 and ISO 9001:2015 certificates, our Statement of Applicability, the DPA and the sub-processor list. If your organization works from its own questionnaire instead, send it over and our team completes it directly rather than returning a generic response. Anything that is deployment-specific — data residency, for example — we answer in writing rather than leaving it to a general statement.
Who reviews AI outputs?
Tenured transparency specialists — medical writers, data analysts and regulatory reviewers — check every output before it ships, and their sign-off is logged per record. No AI output reaches a health authority without a named human approving it. That is what AI Enabled. Human Driven.™ means in practice: the checkpoint sits in the workflow, not in a policy document. Reviewers are not asked to trust the model either — drafted statements carry the source document and passage they came from, so checking is a read-and-compare rather than a judgment call, and every transformation is logged and attributable to the person who ran it.
Bring us your security questionnaire
ISO/IEC 27001:2022 and ISO 9001:2015 certified — certificates published above.