Skip to content
ARION
Security

GDPR-native, EU-hosted, and built for regulated change control

How Arion handles data protection, access control, audit and electronic signatures — as a data processor under GDPR, with a Data Processing Agreement accepted at organization creation.

Request a demo
How, not just what

Six mechanisms, not a badge

What actually enforces data protection, access control, and change control on the platform.

Data processor under GDPR

Arion acts as a data processor. A Data Processing Agreement is accepted at organization creation, not negotiated separately after the fact.

EU-hosted

The platform runs on Cloud Run in europe-west1. Patient data does not leave the EU as part of normal operation.

Append-only audit trail

Every study and study-value mutation is recorded with actor identity, timestamp, and the full before/after payload — including organization membership changes.

API-enforced access control

Permissions are derived from one role-definition map and checked at the API layer directly — not only hidden in the interface. A role that cannot do something cannot do it through a direct request either.

Password-confirmed signatures

Where a study requires PI eligibility confirmation, enrolment requires a password re-entry as part of the signature interaction — designed to support the intent of 21 CFR Part 11 and ICH E6(R3), not to claim formal certification.

Versioned change control

Studies move draft → testing → production. Publishing to production requires typed confirmation, locks the live design, and permanently clears disposable testing data. After go-live, authorized builders work through a private amendment draft: the impact is reviewed, a reason is recorded, and publishing creates a new version without deleting collected data. The new version applies prospectively to new subjects and visits not yet started; existing visits keep their collection version until an explicit migration.

Where we are today

We haven't completed a formal audit yet

Arion has not completed an ISO 27001, SOC 2, or formal 21 CFR Part 11 validation audit. What's above is what the platform actually does — verify it, ask us for detail on any of it, and treat that as more useful than a badge you can't inspect.

See it on your protocol

Bring a protocol or an existing study and we'll show you what this looks like in Arion.

Request a demo