Runharbor · Trust Center

Runharbor Trust Center

Trust center

Harbor's security & compliance posture, captured from runharbor.com/security. As an eClinical platform handling ePHI and regulated clinical-trial data, Harbor operates as a HIPAA Business Associate (executes BAAs with clients) and designs the platform for 21 CFR Part 11 (unique user identification, immutable audit trails, electronic signatures). Validation is guided by ISPE GAMP 5 and ISO 13485, aligned to ICH E6 (GCP). No SOC 2, ISO 27001, or FedRAMP certification is claimed on the page. This is not a trust. subdomain trust center; it is the human-verified compliance posture from the /security page.

Runharbor maintains a public trust center documenting 21 CFR Part 11, HIPAA, ICH E6 (GCP), ISPE GAMP 5, and ISO 13485 compliance.

CompanyClinical TrialsHealthcareContract Research OrganizationElectronic Data CaptureLife SciencesComplianceArtificial IntelligenceeClinical
Trust center: https://runharbor.com/security

Certifications & Compliance

21 CFR Part 11HIPAAICH E6 (GCP)ISPE GAMP 5ISO 13485

Source

Trust Center

runharbor-trust-center.yml Raw ↑
generated: '2026-07-21'
method: searched
probe: false
source: https://runharbor.com/security
url: https://runharbor.com/security
description: >-
  Harbor's security & compliance posture, captured from runharbor.com/security.
  As an eClinical platform handling ePHI and regulated clinical-trial data,
  Harbor operates as a HIPAA Business Associate (executes BAAs with clients) and
  designs the platform for 21 CFR Part 11 (unique user identification, immutable
  audit trails, electronic signatures). Validation is guided by ISPE GAMP 5 and
  ISO 13485, aligned to ICH E6 (GCP). No SOC 2, ISO 27001, or FedRAMP
  certification is claimed on the page. This is not a trust.<domain> subdomain
  trust center; it is the human-verified compliance posture from the /security
  page.
certifications:
- {name: 21 CFR Part 11, scope: electronic records & signatures, note: unique user identification, immutable audit trails, e-signature workflows}
- {name: HIPAA, role: Business Associate, note: BAAs executed with clients; ePHI safeguards}
- {name: ICH E6 (GCP), note: quality framework aligned with Good Clinical Practice}
- {name: ISPE GAMP 5, note: risk-based computerized-system validation methodology}
- {name: ISO 13485, note: medical-device quality-management alignment for validation}
security_controls:
- Zero standing access; temporary access only via formal break-glass procedures
- AES-256 encryption at rest; TLS 1.2+ in transit
- Per-trial logically isolated dedicated databases
- Hosted on Google Cloud Platform and AWS with private network architecture
docs:
- https://runharbor.com/security
evidence:
- {source: https://runharbor.com/security, keywords: [21 cfr part 11, hipaa, ich e6, gamp 5, iso 13485, audit trail, encryption]}