generated: '2026-09-05' method: searched source: https://www.4gclinical.com/trust-center note: >- 4G Clinical publishes no machine-readable contract (see x-coverage in apis.yml), so every entry below is graded from the provider's own published prose, not from a specification. Nothing here was derived from a spec because there is no spec to derive from; standards that could only be confirmed inside a contract are recorded as unknown rather than false. standards: - id: soc2-type2 conforms: true evidence: https://www.4gclinical.com/trust-center — SOC 2 Type 2 report for the 12-month period ending 2025-08-31 (Security, Availability, Confidentiality) - id: 21-cfr-part-11 conforms: true evidence: https://www.4gclinical.com/trust-center — "4G Clinical ensures compliance with 21 CFR Part 11, Electronic Records and Signatures" - id: eu-annex-11 conforms: true evidence: https://www.4gclinical.com/trust-center — "Annex 11 Computerized Systems (EU Annex 11)" - id: gdpr conforms: true evidence: https://www.4gclinical.com/trust-center and https://www.4gclinical.com/legal — compliant as a data processor; Netherlands establishment removes the Article 27 requirement - id: ccpa conforms: true evidence: https://www.4gclinical.com/trust-center — "compliant with ... the California Consumer Privacy Act as amended" - id: eu-us-data-privacy-framework conforms: true evidence: https://www.4gclinical.com/trust-center — active DPF participant, incl. UK Extension and Swiss-US DPF - id: alcoa-plus-plus conforms: true evidence: https://www.4gclinical.com/trust-center — ALCOA++ data integrity principles implemented via the QMS - id: hipaa conforms: false evidence: https://www.4gclinical.com/trust-center FAQ — 4G Clinical states it is neither a covered entity nor a business associate because it receives only pseudonymized subject IDs - id: iso-27001 conforms: false evidence: not claimed anywhere on the Trust Center as of 2026-09-05 - id: oauth2 conforms: unknown evidence: no public securityScheme or auth documentation; api.4gclinical.com returns HTTP 403 ForbiddenException to every anonymous request - id: oidc conforms: unknown evidence: /.well-known/openid-configuration returned 404 or 403 on all five probed hosts — see well-known/4gclinical-well-known.yml - id: rfc9457-problem-details conforms: unknown evidence: no published error contract domain_standards: market: clinical research technology (RTSM / IRT) verdict: not-verifiable-from-contract note: >- The domain standards a clinical randomization and trial supply system would normally declare — CDISC ODM, SDTM, CDASH, Define-XML, HL7/FHIR, E2B — are not named anywhere on 4G Clinical's public site, and there is no contract in which to look for a signature (no OpenAPI, no XML schema, no message profile). 21 CFR Part 11 and EU Annex 11 are the regulatory frameworks the company does declare, and they govern the system, not the wire format. Recorded as unknown rather than false: this is an absence of public evidence, not evidence of absence. probed: - id: cdisc-odm conforms: unknown evidence: not named on 4gclinical.com; no contract to inspect - id: cdisc-sdtm conforms: unknown evidence: not named on 4gclinical.com; no contract to inspect - id: hl7-fhir conforms: unknown evidence: not named on 4gclinical.com; no contract to inspect