Security
Overview
Security is built into CROMS rather than added on. Detailed artifacts are available to qualified prospects under NDA.
Access Control
Access is governed by role-based access control (RBAC) and a defined authorization matrix on a least-privilege basis, scoped by organization, study and site where relevant.
Immutable Audit Trail
The system maintains a durable, tamper-evident audit trail of record creation, changes and relevant user activity. Audit records cannot be modified or deleted through the application and are protected through restricted administrative access. Access to the system is logged.
Electronic Approval and Signature Records
Approvals and sign-offs are captured as electronic approval and signature records within the system, attributable to the acting user and time-stamped, supporting Part 11-style controls.
Encryption
CROMS uses end-to-end encryption for supported sensitive data flows. Data is also encrypted in transit using TLS 1.2 or higher and encrypted at rest.
Single Sign-On (SSO)
CROMS supports single sign-on (SSO) with enterprise identity providers.
Backup, Recovery and Retention
The platform is backed up on a regular basis to support recovery. Retention periods are set out in the KVKK Disclosure Text.
Incident Response
A defined incident-response process governs the detection, handling and notification of security incidents.
Hosting and Data Residency
CROMS is hosted on UpCloud in the Europe-2 region in Frankfurt, Germany. Primary application data is hosted in the EU. Limited data may be processed by disclosed sub-processors according to the applicable privacy documentation.
Sub-processors
We disclose the third parties used to deliver the service: UpCloud (hosting), Google (calendar and email delivery), Natro (email infrastructure) and PayTR (payments). The current list is in the KVKK Disclosure Text.
Payment Security
Card payments are processed through PayTR; card details are not stored on CROMS systems.
Testing and Audits
Security is verified through penetration testing and security audits.
Secure Development and OWASP
CROMS is developed and maintained using security practices aligned with OWASP guidance, including secure coding, access-control review, dependency management and vulnerability assessment.
Compliance
Overview
This section maps the standards our customers are assessed against to the platform capabilities that support them; detailed evidence is available under NDA.
GCP / ICH E6(R3)
Designed to support Good Clinical Practice and the current ICH E6(R3) guideline through structured workflows, role-based responsibilities and a complete, attributable record of activity.
ALCOA+ Data Integrity
Data-integrity principles (Attributable, Legible, Contemporaneous, Original, Accurate; plus Complete, Consistent, Enduring, Available) are supported by the immutable audit trail, time-stamped entries, user attribution and controlled access.
21 CFR Part 11
Features supporting Part 11 requirements: an immutable audit trail that cannot be deleted, role-based access control, and electronic approval and signature records attributable to the acting user.
GDPR
A Data Processing Agreement, EU data residency (Frankfurt, Germany), encryption in transit and at rest, access control, and support for data-subject requests.
KVKK
Processing is described in the KVKK Disclosure Text, with the technical and organizational measures required under the KVKK.
ISO 9001 and ISO 27001 Alignment
CROMS is developed and operated in alignment with ISO 9001 quality management and ISO 27001 information security management systems.
Validation
Overview
CROMS maintains documented vendor-validation evidence for released versions using a Computer System Validation approach, including IQ, OQ and PQ documentation. Customers remain responsible for assessing and validating their configured intended use where required by their quality system or applicable regulations.
Installation Qualification (IQ)
Verifies that the system is installed and configured correctly in the target environment.
Operational Qualification (OQ)
Verifies that the system operates according to specifications across its functions.
Performance Qualification (PQ)
Verifies that the system performs reliably under real operating conditions and workflows.
Change Control
The validated state is maintained through documented release and change-control processes.
Documentation
IQ, OQ and PQ documentation is available to qualified prospects under NDA. For requests: info@croms.com.tr