Trust

Security, Compliance and Validation

Last reviewed28 July 2026 Trust Center Version1.1

Security

  • End-to-end encryption
  • Encryption in transit and at rest
  • Role-based access control
  • Immutable audit trail
  • Single sign-on
  • OWASP-aligned security practices

Compliance Support

  • GCP / ICH E6(R3)
  • ALCOA+
  • 21 CFR Part 11
  • GDPR
  • KVKK
  • ISO 9001-aligned quality management
  • ISO 27001-aligned information security management

Validation

  • Documented CSV approach
  • IQ, OQ and PQ documentation
  • Version and change control
  • Validation package available under NDA

Security

Overview

Security is built into CROMS rather than added on. Detailed artifacts are available to qualified prospects under NDA.

Access Control

Access is governed by role-based access control (RBAC) and a defined authorization matrix on a least-privilege basis, scoped by organization, study and site where relevant.

Immutable Audit Trail

The system maintains a durable, tamper-evident audit trail of record creation, changes and relevant user activity. Audit records cannot be modified or deleted through the application and are protected through restricted administrative access. Access to the system is logged.

Electronic Approval and Signature Records

Approvals and sign-offs are captured as electronic approval and signature records within the system, attributable to the acting user and time-stamped, supporting Part 11-style controls.

Encryption

CROMS uses end-to-end encryption for supported sensitive data flows. Data is also encrypted in transit using TLS 1.2 or higher and encrypted at rest.

Single Sign-On (SSO)

CROMS supports single sign-on (SSO) with enterprise identity providers.

Backup, Recovery and Retention

The platform is backed up on a regular basis to support recovery. Retention periods are set out in the KVKK Disclosure Text.

Incident Response

A defined incident-response process governs the detection, handling and notification of security incidents.

Hosting and Data Residency

CROMS is hosted on UpCloud in the Europe-2 region in Frankfurt, Germany. Primary application data is hosted in the EU. Limited data may be processed by disclosed sub-processors according to the applicable privacy documentation.

Sub-processors

We disclose the third parties used to deliver the service: UpCloud (hosting), Google (calendar and email delivery), Natro (email infrastructure) and PayTR (payments). The current list is in the KVKK Disclosure Text.

Payment Security

Card payments are processed through PayTR; card details are not stored on CROMS systems.

Testing and Audits

Security is verified through penetration testing and security audits.

Secure Development and OWASP

CROMS is developed and maintained using security practices aligned with OWASP guidance, including secure coding, access-control review, dependency management and vulnerability assessment.

Compliance

Overview

This section maps the standards our customers are assessed against to the platform capabilities that support them; detailed evidence is available under NDA.

GCP / ICH E6(R3)

Designed to support Good Clinical Practice and the current ICH E6(R3) guideline through structured workflows, role-based responsibilities and a complete, attributable record of activity.

ALCOA+ Data Integrity

Data-integrity principles (Attributable, Legible, Contemporaneous, Original, Accurate; plus Complete, Consistent, Enduring, Available) are supported by the immutable audit trail, time-stamped entries, user attribution and controlled access.

21 CFR Part 11

Features supporting Part 11 requirements: an immutable audit trail that cannot be deleted, role-based access control, and electronic approval and signature records attributable to the acting user.

GDPR

A Data Processing Agreement, EU data residency (Frankfurt, Germany), encryption in transit and at rest, access control, and support for data-subject requests.

KVKK

Processing is described in the KVKK Disclosure Text, with the technical and organizational measures required under the KVKK.

ISO 9001 and ISO 27001 Alignment

CROMS is developed and operated in alignment with ISO 9001 quality management and ISO 27001 information security management systems.

Validation

Overview

CROMS maintains documented vendor-validation evidence for released versions using a Computer System Validation approach, including IQ, OQ and PQ documentation. Customers remain responsible for assessing and validating their configured intended use where required by their quality system or applicable regulations.

Installation Qualification (IQ)

Verifies that the system is installed and configured correctly in the target environment.

Operational Qualification (OQ)

Verifies that the system operates according to specifications across its functions.

Performance Qualification (PQ)

Verifies that the system performs reliably under real operating conditions and workflows.

Change Control

The validated state is maintained through documented release and change-control processes.

Documentation

IQ, OQ and PQ documentation is available to qualified prospects under NDA. For requests: info@croms.com.tr

Request the Security and Validation Package

Detailed security, compliance and validation documentation is available to qualified customers and prospects following a confidentiality agreement.

Book a Demo