Skip to main content
Trust Center

Built for regulated
clinical environments.

CFR 21 Part 11 compliant for sites, sponsors, and CROs. Traceable, access-controlled AI that enables GCP-aligned work where trials run.

CFR 21 Part 11Compliant
Compliance

CFR 21 Part 11

FDA Electronic Records & Electronic Signatures

Full compliance with FDA 21 CFR Part 11 requirements for electronic records and electronic signatures. Audit trails, access controls, and system validation documentation are available for customer review.

  • Complete audit trail on all data access and modifications
  • Electronic signature workflows with identity verification
  • System validation documentation (IQ/OQ/PQ available on request)
  • User access controls with role-based permissions
  • Timestamped records with tamper detection

For SOC 2 Type II, HIPAA, and GxP/GCP documentation, we are able to share relevant architecture and security materials upon request as we work toward formal certifications.

Request documentation →
Clinical sites

Enabling GCP compliance

ICH E6 (Good Clinical Practice) at the investigative site

Under GCP, sites must ensure trial data and records are attributable and traceable, systems are fit for purpose, and monitoring and inspections can reconstruct what happened. Generic AI tools often break those requirements. Rightview exists so sites can adopt AI without giving up compliance: controlled access, time-stamped immutable audit trails, no model training on customer data, and ZDR with AI infrastructure providers—plus validation documentation you can fold into your IQ/OQ/PQ and quality agreements.

  • Enables attributable, time-stamped actions consistent with ALCOA+ for electronic trial-related work
  • Enables least-privilege and segregation-of-duties patterns through role-based access
  • Enables monitoring and inspection readiness with tamper-evident logs of who accessed what and when
  • Reduces GCP risk from third-party AI: no vendor retention of prompts or completions under our ZDR terms
  • Delivers validation packages and technical / quality agreements so you can qualify use under your QMS

GCP compliance is owned by the investigator and institution; Rightview is not “GCP certified.” We provide the system properties and evidence package that enable your site to use AI in a GCP-compliant way within your protocols and SOPs.

Discuss site rollout & documentation →
Security

How we protect your data.

No Model Training on Customer Data

Customer queries, results, and usage data are never used to train any AI model Rightview's or third-party. Your data is yours.

Zero Data Retention with AI Vendors

All third-party AI providers used by Rightview operate under zero data retention (ZDR) agreements. Unlike default OpenAI or Anthropic API terms, prompts and completions are not stored or used for training.

Role-Based Access Control

Granular permissions at the user, team, and data-type level. Principle of least privilege enforced. Access is logged and auditable per CFR 21 Part 11 requirements.

Immutable Audit Logs

Every data access, query, and system action is time-stamped and logged in a tamper-evident record creating the complete audit trail required under 21 CFR Part 11.

Infrastructure Security

Deployed on enterprise-grade cloud infrastructure with physically secured data centers, network-level isolation, and no public-facing database endpoints. All internal traffic runs over private networks with distributed redundancy across availability zones.

Database Backups & Recovery

Automated daily backups with point-in-time recovery. Backups are encrypted, stored in a separate region, and tested for recoverability on a defined schedule.

Incident Response

24/7 security monitoring with automated alerting. Documented incident response procedures with defined notification timelines aligned to regulatory expectations.

Multi-Tenant Data Isolation

Strict logical separation at the database and application layer. No shared data structures between customer accounts. Tenant boundaries enforced at every query.

Enables GCP Compliance at the Site

ICH E6 requires reliable trial data, clear accountability, and investigator oversight—including for computerized systems. Rightview gives sites attributable actions, least-privilege access, and audit-ready logs so AI use can stay within a GCP-compliant quality system.

Privacy

Common questions.

Need more detail?

We're happy to share validation documentation, architecture overviews, and security materials with qualified customers.

Contact our Security Team