Security is the product
under the product.

Trial IQ sits between patient records and clinical research. That position only works if it's earned. Here is how we handle the data practices trust us with, stated plainly enough to forward to your compliance officer.

HIPAA compliant

The platform operates under HIPAA. Administrative, physical, and technical safeguards apply to all protected health information, and workforce access follows minimum-necessary principles.

SOC 2 Type I certified

Our controls for security, availability, and confidentiality have been independently audited, and the Type II observation period is underway. The current report is available to customers and prospects under NDA; request it through the demo form or your Trial IQ contact.

BAA with every practice

We execute a Business Associate Agreement with every connected practice, network, and infusion center before any data flows. Your obligations and ours are on paper first.

Identity stays at the practice

Matched patients are identified to their treating practice, and only their practice. The practice decides how to engage each patient, and no patient information reaches a sponsor until the patient consents through their own provider.

Looking for the documents themselves? Privacy policy, terms of service, and acceptable use policy live in the Legal Center.

How data moves
through the layer.

Four commitments that hold at every step, from EHR connection to trial enrollment.

Your data stays under your governance

Connected practices decide what is shared, and disconnecting is always available. We do not sell patient data, and sponsors and CROs never receive patient identities: they receive verified counts and, after consent, trial-specific referrals.

Consent is the gate, the provider is the door

Patients hear about trials from the physician they already trust, not from us. A patient's identity leaves their care team only after they say yes, and only for the trial they said yes to.

Encryption and access controls throughout

Data is encrypted in transit and at rest. Access is role-based, logged, and reviewed: the controls covered by our SOC 2 audit, not a policy binder on a shelf.

Answers for your diligence process

Security questionnaires, our SOC 2 report, subprocessor list, and BAA terms are available on request. Procurement will ask. We would rather answer early.

Bring your compliance officer.

The fastest way through security review is a direct conversation. We'll walk your team through the architecture and hand over the documents they need.