This page is for site networks and vendor-review teams evaluating TrialCurrent. It describes what the platform does and does not hold, and the controls actually in place today.
The product boundary comes first
This is a deliberate product boundary rather than a gap. Keeping patient-level information outside the platform can substantially reduce the scope and complexity of a security and compliance review, because the categories of data that drive the hardest questions are not present. Customers should not upload protocols or operational documents containing patient-level information.
Access control
- No self-registration. There is no signup path. Accounts are created only by an administrator within a customer organization.
- Role-based access. Roles distinguish administrators, standard users, and view-only users, and write and delete operations are checked against role on the server, not hidden in the interface.
- Organization scoping. Each customer organization's records carry an organization identifier, and every read and write is scoped to the requesting user's organization. A record belonging to another organization is not returned, and requesting one directly by identifier does not reveal that it exists.
Authentication
- Passwords are hashed with Argon2id and are never stored in readable form.
- Sessions use signed tokens verified on every request; identity claims cannot be forged by a client.
- Sessions can be revoked — deactivating a user, changing a role, or resetting a password invalidates existing sessions rather than waiting for them to expire.
- Sign-in attempts are rate limited, and failure responses do not distinguish an unknown email address from a wrong password, so the login page cannot be used to discover who has an account.
- Authentication events are logged without recording credentials.
Data in transit
All traffic is served over HTTPS/TLS.
Hosting and providers
The application runs on Vercel. Customer records are stored in a Supabase-hosted database. AI features send the relevant text to Anthropic's API. Transactional email is sent through Resend. The full list, and what each provider receives, is in the Privacy Policy.
AI boundaries
AI is used where the system reads — extracting structure from an uploaded protocol, capturing contacts and tasks from a written note, drafting the digest narrative. It is not used where the system decides: Control Tower signals, feasibility verdicts, win probability, health scores, and deal economics are rule-based and show the reasoning behind each figure. Protocol extraction goes through human review, and values that conflict with what a person already entered are surfaced rather than overwritten.
Protocols are sponsor-confidential, so the data flow matters. Only the text that feature needs is sent to Anthropic's API — not your database. Under Anthropic's commercial terms those inputs and outputs are not used for model training and are deleted from Anthropic's systems within 30 days. If your sponsor agreements require stricter handling, zero-data-retention terms are available from Anthropic for eligible customers; raise it during evaluation and we will work through what your agreements need.
Certifications and audits
TrialCurrent is a young product and does not yet hold third-party security certifications such as SOC 2 or ISO 27001. If your review process requires a specific attestation, questionnaire, or documentation package, raise it during evaluation — we will tell you plainly what exists today and what is planned, rather than leaving you to discover it later.
Reporting a vulnerability
Email info@trialcurrent.com with details and we will respond. Please do not test against production without written permission.
Contact
TrialCurrent LLC, a Wyoming limited liability company.
Security questions and vendor-review documentation: info@trialcurrent.com
