Vitruvian Shield
Compliance

Built for the Most Demanding Regulatory Environments

Every module, every data point, every workflow, designed from the ground up for regulatory inspection readiness.

Compliance Frameworks

Pre-validated against global clinical research and data protection standards.

ALCOA++

Compliant

Every data point in Vitruvian Shield satisfies ALCOA++ data integrity principles. Attributable (who created it), Legible (clearly readable), Contemporaneous (recorded at time of activity), Original (first-capture source), Accurate (correct and verified), plus Complete, Consistent, Enduring, and Available. Automatic audit trails, timestamping, and reason for change capture ensure unbroken data provenance.

HIPAA

Designed for HIPAA alignment

Platform architecture is designed for HIPAA Administrative, Physical, and Technical Safeguards alignment, including minimum-necessary access, protected health information de-identification pathways, and comprehensive audit logging. Business Associate Agreement program and United States Security Rule attestation are part of our US market expansion roadmap.

EU GDPR

Compliant

Full compliance with the European General Data Protection Regulation, including lawful basis management for clinical trial data processing, data subject rights workflows, Data Protection Impact Assessment documentation, cross-border transfer mechanisms (SCCs), data minimization controls, purpose limitation enforcement, and automated breach notification workflows. Privacy-by-design is embedded in every feature, with study-specific Data Protection Impact Assessments and documented cross-border transfer mechanisms under Standard Contractual Clauses.

ISO 27001

In progress

Our Information Security Management System follows ISO 27001 framework requirements. We implement comprehensive risk assessment processes, security controls across all 14 domains, continuous monitoring and incident response, and management review cycles. Third-party certification audit is in progress.

ISO 13485

In progress

Our development processes follow ISO 13485 quality management system requirements for medical device software. This includes design and development controls, risk management per ISO 14971, traceability from user requirements through verification and validation, CAPA processes, and supplier quality management for all third party components.

ICH E6(R3) GCP

Planned

Vitruvian Shield is architected around the latest ICH E6(R3) Good Clinical Practice guidelines. Our platform supports risk-proportionate approaches to trial oversight, technology enabled participant engagement, and quality-by-design principles. Every module, from eConsent to RPM. implements the R3 emphasis on participant centric, digitally native trial processes with built in quality tolerance limits and centralized monitoring capabilities.

FDA 21 CFR Part 11

Planned

Full compliance with FDA electronic records and signatures regulation. Includes validated electronic signatures with two-factor identity verification, complete audit trails with timestamp and reason for change, system access controls with unique user credentials, authority checks for signature privileges, and document lifecycle management with version control and archival.

EU MDR

Planned

Vitruvian Shield is designed in accordance with European Medical Device Regulation requirements for clinical decision support software. Our quality management system, risk management processes, clinical evaluation procedures, and post market surveillance frameworks align with EU MDR Annex I essential safety and performance requirements for Class IIa medical device software.

Data Security & Infrastructure

Enterprise-grade security architecture built on Microsoft Azure cloud with defense-in-depth protection.

Microsoft Azure Cloud

Hosted on Microsoft Azure with SOC 2 Type II certified data centers. Geo-redundant deployments with automatic failover across European regions.

AES-256 Encryption

All data encrypted at rest using AES-256 encryption. Database-level encryption with customer-managed key options for maximum control.

TLS 1.3 in Transit

All data in transit protected with TLS 1.3. Certificate pinning, HSTS enforcement, and perfect forward secrecy across all API endpoints.

Data Residency Controls

Choose where your data lives. EU-only, US-only, or region-specific data residency configurations to meet local regulatory requirements.

Role-Based Access Control

Granular RBAC with study-level, site level, and module-level permission matrices. Principle of least privilege enforced across all user roles.

Multi-Factor Authentication

Mandatory MFA for all user accounts with support for TOTP, hardware security keys, and SSO integration with enterprise identity providers.

Comprehensive Audit Logging

Every user action, data access, and system event logged with immutable, tamper-evident audit trails. Exportable for regulatory inspections.

Penetration Testing

Scheduled third-party penetration testing as part of our ISO 27001 certification pathway, with continuous vulnerability scanning across platform components.

Public Recognitions and Certifications

Formal certifications and government-issued eligibility held by Vitruvian Shield group entities.

ANI Idoneidade Cientifica

Portuguese national certification for research and development scientific idoneity, held by Vitruvian Shield PT LDA.

Armenia High-Tech Sector Certification

Granting preferential tax treatment for qualifying information technology activities, held by Vitruvian Shield AM.

SIFIDE II Eligibility

Portuguese research and development tax incentives applied to qualifying R&D activities.