Row-level data isolation, encrypted communications, and compliance-ready architecture — designed from day one for the regulatory demands of the life sciences industry.
Multi-layered security controls protect your trial intelligence
Every user's data is isolated at the database level through PostgreSQL Row-Level Security (RLS) policies. Followed trials, custom columns, confirmations, preferences, and portfolio configurations are scoped to individual accounts. No user can access another user's data — enforced by the database engine, not application logic.
OWASP-aligned protections across the real-time search path and long-running session lifecycle
ClinicaLister's real-time search backend is hardened against the OWASP Top 10 and integrated with the application through a secure, authenticated client connection.
Long-running searches gracefully recover from transient disruptions without losing progress or leaving stale server sessions behind.
Transparent data handling with regulatory compliance built in
Built to GDPR expectations. Consent is granular — analytics and marketing are opt-in and default off — and every consent change is written to an immutable consent audit log. You can exercise your rights of access, rectification, erasure, and objection (GDPR Articles 15–21) from your account, with sensitive requests re-authentication-gated. A Data Protection Officer is designated and a Data Processing Agreement is available for organizations.
Automated data-retention policies run on a scheduled job so personal data is never kept longer than needed. A breach-incident register and subject-notification workflow support the 72-hour GDPR breach-notification standard, and Records of Processing Activities (RoPA) are maintained.
User confirmations and rejections of AI suggestions are stored privately and aggregated anonymously. No user can see another user's individual voting activity — only aggregate community metrics (total confirmations, total rejections, approval rate) are visible.
Change logging tracks data modifications for regulatory compliance, and high-risk account actions are recorded in a structured activity log. The monitoring system records when trial data was last synchronized, what fields changed, and the before/after values — a verifiable record of data evolution.
Development and production environments are fully isolated with independent data stores, separate authentication systems, and distinct access controls. No development activity can affect production data. Error monitoring receives only an anonymous user ID — never your email or personal data.
ClinicaLister is actively working toward SOC 2 Type II, with a documented roadmap and controls mapped to the Trust Services Criteria; authentication targets NIST 800-63B AAL2 and controls are designed against the OWASP ASVS and OWASP Top 10. We are not yet SOC 2 certified. Our core infrastructure providers — Supabase, Cloudflare, and Render — each maintain their own SOC 2 Type II attestations.
Enterprise-grade hosting and database architecture
ClinicaLister delivers full feature parity across all devices — ensuring field teams, executives, and analysts have equal access regardless of device.
Switch between table and card views on any screen size. The preference persists across page navigations for a consistent experience.