Security & Compliance

Built for protected health information

Recruiting for clinical trials means handling sensitive data. Trialflow is engineered with the controls sponsors, CROs, and IRBs expect — so your team can move fast without compromising trust.

HIPAA-Conscious by Design

PHI is handled with encryption in transit and at rest, strict access controls, and audit logging on sensitive actions.

Role-Based Access Control

Granular permissions ensure team members only see the data their role requires — down to the study and site level.

Audit Logging

Every meaningful action is recorded, giving you the traceability sponsors, CROs, and IRBs expect.

Secure Communications

Email and SMS outreach with compliant opt-out handling and delivery tracking on every message.

Security practices, end to end

From authentication to outreach, every layer is designed to protect participant data.

  • Encryption of data in transit (TLS) and at rest
  • Role-based access control down to study and site level
  • Audit logging on sensitive actions
  • Secure, token-based authentication with password reset flows
  • Compliant opt-out handling on all outbound messaging
  • Principle-of-least-privilege team permissions
  • Secure document storage linked to studies and participants
  • BAAs available for Enterprise customers

Working through a security or compliance review? Our team will walk your stakeholders through our architecture, data handling, and BAA process.

Talk to us about your compliance needs

We're happy to support your security review and answer your team's questions.