A practical overview for IT, security, quality, and procurement teams. The controls below can be reviewed during product and technical diligence.
Data separation and external access
- TrialCurrent is a multi-tenant platform. Each record is tied to an organization, and organization-level access checks are applied on the server for reads and writes. Tenant separation does not depend on hiding records in the user interface.
- External participants, such as sites completing feasibility questionnaires, do not need a TrialCurrent account. They receive a unique, time-limited link scoped to the requested response. Expired or cancelled links no longer accept submissions.
- Users review and approve feasibility outreach before it is sent. Messages are sent through the Customer's connected mailbox; TrialCurrent does not independently initiate external outreach.
Access and permissions
- TrialCurrent currently includes three standard roles: Admin, Sales User, and View Only. Permission checks are enforced on the server, not only through visible or hidden interface controls.
- Deletion permissions vary by role and record type. Admins have broader rights, while standard users have limited deletion rights for specific records. Current permissions should be reviewed during implementation against the Customer's internal retention policy.
Auditability and review
- Selected stage changes require supporting information. When an authorized user overrides a gate, TrialCurrent requires a written reason and records the action in the deal history with the user and timestamp.
- Win probability is calculated from defined inputs. Users can open "Show the math" to review the components. A manual override requires a reason and expires after 14 days.
- System-created records identify their creator. Audit fields are read-only in the interface. Re-uploaded documents are maintained as versions rather than separate copies. Vendor recommendations retain the scores, weights, supporting evidence, and age of that evidence used in the recommendation.
How TrialCurrent uses AI
AI supports specific drafting, extraction, and matching tasks. It does not approve decisions or send outreach on a user's behalf. The following rules describe the intended behavior and can be tested during a product review:
| AI behavior | How it works in TrialCurrent |
|---|---|
| AI proposes; people approve | AI can extract information, draft outreach, and suggest vendor requirements. A user reviews the result before it becomes an approved record or an external message. |
| Preserve user-entered information | AI fills empty fields where appropriate. If a source document conflicts with information already entered by a user, TrialCurrent flags the difference for review instead of replacing the existing value. |
| Use approved values | Tags and matched values use the Customer's configured taxonomies. Values that do not match an approved option are flagged for review. |
| Do not guess when the source is unclear | When information is ambiguous, TrialCurrent asks for clarification or leaves the field unresolved rather than inventing a value. |
| Keep forecasts rule-based | Stage gates, probability calculations, and management metrics use defined rules and stored records. AI-generated text does not directly change the forecast. |
- The Discover feature uses public sources such as trial registries, company announcements, job postings, and government filings. Results include links to supporting sources. Discover does not contact companies or individuals.
- Customer workspace data remains under the Customer's control. When a user invokes an AI-assisted feature, limited content may be processed through Anthropic's commercial API. Commercial API inputs and outputs are not used for generative-model training unless the account holder expressly opts in; TrialCurrent does not opt in on a Customer's behalf.
When a service is unavailable
- An unavailable AI service or an integration that has not been configured should not prevent users from accessing the rest of the application. TrialCurrent displays a clear message in place of the affected feature. Uploaded files are stored before optional processing begins.
- TrialCurrent retries certain temporary service errors once. If the issue continues, the user sees a plain-language message and, where appropriate, an option to try again. Raw internal error details are not shown in the application.
Suggested diligence review
A product review can include tenant separation, permission behavior, a stage-gate override and its history entry, the inputs behind a win-probability calculation, a vendor recommendation breakdown, and AI-assisted extraction using Customer-provided sample data. Technical architecture, available audit exports, data handling, and integration details can be reviewed separately based on the proposed implementation.
Entity and commercial terms
TrialCurrent is operated by Greenlight Advisory LLC, a Wyoming limited liability company, with a principal address at 6515 Heather Way, West Palm Beach, FL 33406. TrialCurrent is priced per site. The per-site rate may be adjusted based on the Customer's business type, operating model, volume, and contracted scope, as stated in the applicable Order Form.
Related documents
- Security & Data Practices — infrastructure, storage, access control, and the current subprocessor list.
- Data Processing Agreement — the contractual processing terms, including Attachments 1 and 2.
- Privacy Policy — how TrialCurrent handles personal information as a controller.
Security questions and vendor reviews: security@trialcurrent.com.
