Skip to content
CLINISTACK
Platform Current section

Trial work can move fast without losing control.

Start with the study record, then move into system exchange, AI review, compliance evidence, and security posture.

Platform overview How clinical work stays connected across trial systems. System exchange Connect existing trial systems to controlled study work and evidence. AI and automation AI suggestions, Data Contracts, reviewer authority, and manual review routes. Compliance evidence Control evidence mapped to artifacts teams can review. Security and trust Security posture, disclosure policy, and data-handling overview.
Products

Product pages by clinical workstream.

Move from CTMS and eTMF into connected EDC, RTSM, patient, finance, and safety work that shares study context.

CTMS Activation, delegation, training, amendments, RBM, and monitoring. eTMF CDISC TMF Reference Model, EDL, WORM, lifecycle, variants, and inspection. Suite map Where EDC, RTSM, safety, finance, and patient workstreams fit next.
For teams

Start with the team carrying the work.

Sponsors, CROs, sites, biotech, academic teams, and clinical functions share the same trial record. They need different work views, not different data stories.

Clinical teams Leadership, operations, sites, quality, IT, medical review, and safety. Organizations Sponsors, CROs, sites, biotech, academic, and nonprofit research groups. Sponsors Oversight, CRO accountability, safety context, and inspection evidence. CROs Repeatable delivery with Sponsor-specific evidence and country variation. Sites Coordinator work, DOA and training currency, source, and consent context. Biotech Lean Sponsor control, vendor oversight, and pivotal-trial scale. Academic and nonprofit IRB cadence, EHR/source realities, and multi-study PI accountability.
Resources
Talk to us Book a demo
Menu

Platform

Platform overview System exchange AI and automation Compliance evidence Security and trust

Products

CTMS eTMF Suite map

For teams

Clinical teams Organizations Sponsors CROs Sites Biotech Academic and nonprofit
Resources Talk to us Book a demo

Security

Security And Vulnerability Disclosure

Clinistack security is designed around regulated clinical operations: tenant isolation, accountable access, synchronous audit evidence, immutable document storage, AI review routes, and controlled handling for sensitive trial data.

Last updated: June 8, 2026

Security Posture

The architecture is designed around tenant isolation, least privilege, synchronous audit evidence, immutable document storage, controlled AI, encrypted transport, encrypted storage, minimum-necessary communication, and controlled infrastructure. We use current security guidance, including NIST CSF 2.0 and CISA Secure by Design principles, and we design control evidence with common customer diligence frameworks in mind.

Security and compliance diligence artifacts are shared through approved diligence channels or signed agreements. This page is an overview, not a certification or audit report.

HIPAA And Regulated Data

Public website and public email channels are for business, privacy, security, vendor, and product evaluation communication. Customer PHI or regulated clinical-trial records must be handled only through governed application routes and signed customer terms.

Public Site Protection

  • HTTPS-only public site delivery with security headers.
  • Private static origin behind a controlled CDN edge.
  • Deployment through short-lived cloud identity rather than long-lived access keys.
  • No advertising pixels, analytics cookies, or session replay on the public site.

Report A Vulnerability

Send security reports to security@clinistack.io. Include a clear description, affected URL or component, steps to reproduce, observed impact, and whether any data was exposed. Do not include PHI or regulated trial records in a public security report.

We aim to acknowledge credible reports within three business days and provide a triage update within ten business days. Timelines can change based on severity, reproducibility, third-party dependency involvement, and legal obligations.

Good-Faith Research Rules

For public assets you may perform non-destructive testing that stays within these rules:

  • Do not access, modify, delete, exfiltrate, or retain data that is not yours.
  • Stop testing and report immediately if you encounter non-public data.
  • Do not perform denial-of-service, spam, phishing, social engineering, physical attacks, or destructive tests.
  • Do not test customer tenants, non-public environments, employees, contractors, vendors, or personal accounts.
  • Do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and remediate it.

Safe Harbor

If your research follows this policy, is limited to public Clinistack-owned assets, avoids harm, and is reported promptly, Clinistack will not pursue legal action against you for that good-faith research. This does not authorize access to third-party systems or customer data, and it does not waive rights for conduct outside this policy.

Security Report Compensation

Paid rewards are not offered unless a written program states otherwise. Credible reports are reviewed under this disclosure policy; submission does not create a right to compensation, employment, attribution, or public acknowledgment.

Machine-Readable Contact

The machine-readable vulnerability contact file is available at /.well-known/security.txt.

CLINISTACK
Platform Integrations Security Resources Book a demo Contact Privacy Terms Review your trial setup