Data Security & Confidentiality
Data Security & Confidentiality
Data Security & Confidentiality
Operational safeguards, confidentiality commitments, and the security due-diligence pathway.
Operational safeguards, confidentiality commitments, and the security due-diligence pathway.
PRIVACY POLICY
PRIVACY POLICY
How personal information is collected, used, and protected.
How personal information is collected, used, and protected.
VIEW →
VIEW →
TERMS OF USE
TERMS OF USE
The terms that govern access to and use of the site.
The terms that govern access to and use of the site.
VIEW →
VIEW →
DATA SECURITY & CONFIDENTIALITY
DATA SECURITY & CONFIDENTIALITY
Operational safeguards and the due-diligence pathway.
Operational safeguards and the due-diligence pathway.
THIS PAGE
THIS PAGE
Data Security & Confidentiality
Operational safeguards, confidentiality commitments, and the security due-diligence pathway.
LAST UPDATED / JULY 6, 2026
LAST UPDATED / JULY 6, 2026
This page is informational only. It is not a contract, warranty, or service commitment. Executed written agreements govern engagement-specific obligations.
This page is informational only. It is not a contract, warranty, or service commitment. Executed written agreements govern engagement-specific obligations.
Practice descriptions are general; engagement-specific scope is governed by the applicable written agreements.
Practice descriptions are general; engagement-specific scope is governed by the applicable written agreements.
Four boundaries to understand first.
Four boundaries to understand first.
Four boundaries to understand first.
Four boundaries to understand first.
This summary helps readers locate the full statement. It does not replace, broaden, or qualify the agreement boundaries below.
This summary helps readers locate the full statement. It does not replace, broaden, or qualify the agreement boundaries below.
SECURITY AT A GLANCE
SECURITY AT A GLANCE
01
01
AGREEMENT BOUNDARIES
AGREEMENT BOUNDARIES
Executed written agreements govern engagement-specific security, confidentiality, and data-protection obligations.
Executed written agreements govern engagement-specific security, confidentiality, and data-protection obligations.
02
02
STANDARDS CONTEXT
STANDARDS CONTEXT
References are conditional operating context—not certification by, or affiliation with, a regulator or standards body.
References are conditional operating context—not certification by, or affiliation with, a regulator or standards body.
03
03
SYSTEM BOUNDARIES
SYSTEM BOUNDARIES
Work may occur in client-controlled systems. Safeguards and responsibilities depend on the system and engagement.
Work may occur in client-controlled systems. Safeguards and responsibilities depend on the system and engagement.
04
04
REPORTING
REPORTING
Use the approved security route for concerns. Do not send participant data or highly sensitive material through the website.
Use the approved security route for concerns. Do not send participant data or highly sensitive material through the website.
The complete operating and agreement context.
The complete operating and agreement context.
The complete operating and agreement context.
The complete operating and agreement context.
ON THIS PAGE
ON THIS PAGE
01
01
Purpose — read this first
Purpose — read this first
Purpose — read this first
02
02
Standards we operate under
Standards we operate under
Standards we operate under
03
03
Confidentiality
Confidentiality
Confidentiality
04
04
Our security program
Our security program
Our security program
05
05
Client-controlled systems
Client-controlled systems
Client-controlled systems
06
06
Personnel
Personnel
Personnel
07
07
Vendors and subprocessors
Vendors and subprocessors
Vendors and subprocessors
08
08
Incident response
Incident response
Incident response
09
09
Continuity and resilience
Continuity and resilience
Continuity and resilience
10
10
Retention and disposal
Retention and disposal
Retention and disposal
11
11
Your part
Your part
Your part
12
12
Report a security concern
Report a security concern
Report a security concern
13
13
No warranties; agreements
No warranties; agreements
No warranties; agreements
14
14
Contact us
Contact us
Contact us
01
01
Purpose of this page — read this first
Purpose of this page — read this first
This page describes, in general terms, how KARAMATA LLC (“KARAMATA,” “we,” “our”) approaches the security and confidentiality of information entrusted to us. It is provided for information only.
This page describes, in general terms, how KARAMATA LLC (“KARAMATA,” “we,” “our”) approaches the security and confidentiality of information entrusted to us. It is provided for information only.
It is not a contract, a warranty, or a service commitment, and it creates no rights in any person or entity.
It is not a contract, a warranty, or a service commitment, and it creates no rights in any person or entity.
Our binding security, confidentiality, and data protection obligations exist solely in executed written agreements with our clients—including service agreements, confidentiality agreements, quality agreements, and Business Associate Agreements where applicable—and, in any conflict between this page and such an agreement, the agreement controls. We may revise this page at any time without notice.
Our binding security, confidentiality, and data protection obligations exist solely in executed written agreements with our clients—including service agreements, confidentiality agreements, quality agreements, and Business Associate Agreements where applicable—and, in any conflict between this page and such an agreement, the agreement controls. We may revise this page at any time without notice.
02
02
The standards we operate under
The standards we operate under
KARAMATA delivers clinical trial services under the operating standards the work demands:
KARAMATA delivers clinical trial services under the operating standards the work demands:
—
—
GCP / ICH-E6 — Good Clinical Practice is the operating standard for our trial services, including documentation practices, delegation, and data handling within engagements.
GCP / ICH-E6 — Good Clinical Practice is the operating standard for our trial services, including documentation practices, delegation, and data handling within engagements.
GCP / ICH-E6 — Good Clinical Practice is the operating standard for our trial services, including documentation practices, delegation, and data handling within engagements.
—
—
21 CFR Part 11 — where an engagement involves electronic records and signatures subject to Part 11, we operate within validated, client-controlled systems and follow processes aligned with Part 11 requirements as directed by the engagement.
21 CFR Part 11 — where an engagement involves electronic records and signatures subject to Part 11, we operate within validated, client-controlled systems and follow processes aligned with Part 11 requirements as directed by the engagement.
21 CFR Part 11 — where an engagement involves electronic records and signatures subject to Part 11, we operate within validated, client-controlled systems and follow processes aligned with Part 11 requirements as directed by the engagement.
—
—
HIPAA — where our services make us a business associate of a covered entity, we execute Business Associate Agreements and handle protected health information in accordance with them and with HIPAA’s requirements. We are BAA-ready.
HIPAA — where our services make us a business associate of a covered entity, we execute Business Associate Agreements and handle protected health information in accordance with them and with HIPAA’s requirements. We are BAA-ready.
HIPAA — where our services make us a business associate of a covered entity, we execute Business Associate Agreements and handle protected health information in accordance with them and with HIPAA’s requirements. We are BAA-ready.
—
—
U.S. state privacy laws — as described in our Privacy Policy.
U.S. state privacy laws — as described in our Privacy Policy.
U.S. state privacy laws — as described in our Privacy Policy.
—
—
International engagements — where an engagement involves personal data subject to the GDPR, UK GDPR, or similar regimes, we implement the safeguards and contractual terms the engagement and applicable law require.
International engagements — where an engagement involves personal data subject to the GDPR, UK GDPR, or similar regimes, we implement the safeguards and contractual terms the engagement and applicable law require.
International engagements — where an engagement involves personal data subject to the GDPR, UK GDPR, or similar regimes, we implement the safeguards and contractual terms the engagement and applicable law require.
NOTE
NOTE
Descriptions of standards on this page indicate how we operate; they are not representations of certification by, or affiliation with, any regulator or standards body.
Descriptions of standards on this page indicate how we operate; they are not representations of certification by, or affiliation with, any regulator or standards body.
Descriptions of standards on this page indicate how we operate; they are not representations of certification by, or affiliation with, any regulator or standards body.
03
03
Confidentiality
Confidentiality
Confidentiality is a condition of employment and engagement at KARAMATA. Client information, study information, and business information received under an engagement are used only for that engagement, disclosed only as the governing agreements permit, and protected by written confidentiality obligations binding our personnel and our vendors.
Confidentiality is a condition of employment and engagement at KARAMATA. Client information, study information, and business information received under an engagement are used only for that engagement, disclosed only as the governing agreements permit, and protected by written confidentiality obligations binding our personnel and our vendors.
Two boundaries protect everyone:
Two boundaries protect everyone:
—
—
Information sent outside an agreement is not confidential. Material submitted through this website, or sent to us before a written confidentiality agreement is in place, is handled as described in our Privacy Policy and Terms of Use but is not subject to confidentiality obligations. Share evaluation-stage information accordingly.
Information sent outside an agreement is not confidential. Material submitted through this website, or sent to us before a written confidentiality agreement is in place, is handled as described in our Privacy Policy and Terms of Use but is not subject to confidentiality obligations. Share evaluation-stage information accordingly.
Information sent outside an agreement is not confidential. Material submitted through this website, or sent to us before a written confidentiality agreement is in place, is handled as described in our Privacy Policy and Terms of Use but is not subject to confidentiality obligations. Share evaluation-stage information accordingly.
—
—
Trial participant data is governed elsewhere. Where engagements involve participant data, our handling is governed by the executed agreements, the study protocol, informed consent documentation, and applicable law—as described in Section II of our Privacy Policy. This website neither collects nor accepts participant data, and none should ever be submitted through it.
Trial participant data is governed elsewhere. Where engagements involve participant data, our handling is governed by the executed agreements, the study protocol, informed consent documentation, and applicable law—as described in Section II of our Privacy Policy. This website neither collects nor accepts participant data, and none should ever be submitted through it.
Trial participant data is governed elsewhere. Where engagements involve participant data, our handling is governed by the executed agreements, the study protocol, informed consent documentation, and applicable law—as described in Section II of our Privacy Policy. This website neither collects nor accepts participant data, and none should ever be submitted through it.
04
04
Our security program
Our security program
We maintain a security program with administrative, technical, and physical safeguards appropriate to the size of our organization and the sensitivity of the information we handle. Depending on the system and engagement, these measures include: role-based access on the principle of least privilege; multi-factor authentication; encryption of data in transit and, where appropriate, at rest; logging and monitoring of access to sensitive systems; segregation of client information by engagement; secure configuration and patching practices; and periodic review of the program itself. We describe these measures at the level of practice rather than implementation detail—publishing system-level specifics serves attackers, not clients. Clients with diligence or audit requirements may request further information under an appropriate confidentiality agreement.
We maintain a security program with administrative, technical, and physical safeguards appropriate to the size of our organization and the sensitivity of the information we handle. Depending on the system and engagement, these measures include: role-based access on the principle of least privilege; multi-factor authentication; encryption of data in transit and, where appropriate, at rest; logging and monitoring of access to sensitive systems; segregation of client information by engagement; secure configuration and patching practices; and periodic review of the program itself. We describe these measures at the level of practice rather than implementation detail—publishing system-level specifics serves attackers, not clients. Clients with diligence or audit requirements may request further information under an appropriate confidentiality agreement.
05
05
Working inside client-controlled systems
Working inside client-controlled systems
A structural feature of our model matters here: much of our work—EDC data entry, query resolution, document filing, financial reconciliation—is performed inside sponsor- and site-controlled systems (for example, sponsor-designated EDC, CTMS, and eTMF platforms), under credentials, permissions, and audit trails those systems’ owners administer. In those engagements, the client’s validated environment and access controls govern the data, and our personnel operate within them. Where KARAMATA systems are used, the safeguards in Section IV apply.
A structural feature of our model matters here: much of our work—EDC data entry, query resolution, document filing, financial reconciliation—is performed inside sponsor- and site-controlled systems (for example, sponsor-designated EDC, CTMS, and eTMF platforms), under credentials, permissions, and audit trails those systems’ owners administer. In those engagements, the client’s validated environment and access controls govern the data, and our personnel operate within them. Where KARAMATA systems are used, the safeguards in Section IV apply.
06
06
Personnel
Personnel
Our personnel are bound by written confidentiality obligations, receive training appropriate to their role—including GCP and data protection training—and are granted access to client information only as their engagement responsibilities require. Access is removed promptly when a role or engagement ends. Background screening is performed where permitted by law and appropriate to the role.
Our personnel are bound by written confidentiality obligations, receive training appropriate to their role—including GCP and data protection training—and are granted access to client information only as their engagement responsibilities require. Access is removed promptly when a role or engagement ends. Background screening is performed where permitted by law and appropriate to the role.
07
07
Vendors and subprocessors
Vendors and subprocessors
Vendors that process information on our behalf are engaged under written agreements containing confidentiality and data protection obligations appropriate to the information involved, and are assessed for suitability before engagement. We remain responsible for our vendors’ handling of client information to the extent our agreements provide.
Vendors that process information on our behalf are engaged under written agreements containing confidentiality and data protection obligations appropriate to the information involved, and are assessed for suitability before engagement. We remain responsible for our vendors’ handling of client information to the extent our agreements provide.
08
08
Incident response
Incident response
We maintain a documented incident response process covering identification, containment, assessment, and remediation. If an incident affects a client’s information, we notify the affected client without undue delay, consistent with our executed agreements and applicable law, and cooperate in the client’s own assessment and notification obligations. Specific notification timelines, where committed, are committed in the governing agreements.
We maintain a documented incident response process covering identification, containment, assessment, and remediation. If an incident affects a client’s information, we notify the affected client without undue delay, consistent with our executed agreements and applicable law, and cooperate in the client’s own assessment and notification obligations. Specific notification timelines, where committed, are committed in the governing agreements.
09
09
Continuity and resilience
Continuity and resilience
We maintain reasonable measures for the continuity of our services and the recoverability of the information we control, proportionate to our operations. Continuity commitments specific to an engagement are set out in the governing agreement.
We maintain reasonable measures for the continuity of our services and the recoverability of the information we control, proportionate to our operations. Continuity commitments specific to an engagement are set out in the governing agreement.
10
10
Retention and disposal
Retention and disposal
Information is retained as described in our Privacy Policy and, for engagement records, for the periods our agreements and applicable regulation require—which for clinical trial records can be substantial. When information is no longer required, it is securely deleted, returned, or de-identified as the governing agreement provides.
Information is retained as described in our Privacy Policy and, for engagement records, for the periods our agreements and applicable regulation require—which for clinical trial records can be substantial. When information is no longer required, it is securely deleted, returned, or de-identified as the governing agreement provides.
11
11
Your part
Your part
Security is shared. If you work with us: safeguard the credentials you use to interact with us or with shared systems; do not send PHI, participant data, or highly sensitive material through this website or by unencrypted email; verify unexpected payment-instruction changes by a known phone number before acting—we will never change banking instructions by email alone; and tell us promptly at operations@karamataclinical.com if you suspect any compromise touching our shared work.
Security is shared. If you work with us: safeguard the credentials you use to interact with us or with shared systems; do not send PHI, participant data, or highly sensitive material through this website or by unencrypted email; verify unexpected payment-instruction changes by a known phone number before acting—we will never change banking instructions by email alone; and tell us promptly at operations@karamataclinical.com if you suspect any compromise touching our shared work.
12
12
Reporting a security concern
Reporting a security concern
If you believe you have found a vulnerability in this website or a security issue involving KARAMATA, report it to operations@karamataclinical.com with enough detail for us to evaluate it.
If you believe you have found a vulnerability in this website or a security issue involving KARAMATA, report it to operations@karamataclinical.com with enough detail for us to evaluate it.
We ask that you act in good faith: do not access, alter, or exfiltrate data that is not yours, and do not disrupt service. We review all reports; we do not operate a bounty program.
We ask that you act in good faith: do not access, alter, or exfiltrate data that is not yours, and do not disrupt service. We review all reports; we do not operate a bounty program.
13
13
No warranties; relationship to agreements
No warranties; relationship to agreements
No security program eliminates risk, and nothing on this page warrants that our systems, or any system, are free of vulnerability or that incidents will not occur.
No security program eliminates risk, and nothing on this page warrants that our systems, or any system, are free of vulnerability or that incidents will not occur.
THIS PAGE IS PROVIDED “AS IS,” CREATES NO CONTRACTUAL OR THIRD-PARTY RIGHTS, AND DOES NOT AMEND ANY AGREEMENT.
THIS PAGE IS PROVIDED “AS IS,” CREATES NO CONTRACTUAL OR THIRD-PARTY RIGHTS, AND DOES NOT AMEND ANY AGREEMENT.
Our enforceable obligations—and our clients’ remedies—are those stated in the executed agreements governing each engagement.
Our enforceable obligations—and our clients’ remedies—are those stated in the executed agreements governing each engagement.
14
14
Contact us
Contact us
KARAMATA LLC
3101 N. Central Ave. Ste 183 #6830
Phoenix, AZ 85012
operations@karamataclinical.com
(888) 407-5682
KARAMATA LLC
3101 N. Central Ave. Ste 183 #6830
Phoenix, AZ 85012
operations@karamataclinical.com
(888) 407-5682
Use the route that matches the question.
Use the route that matches the question.
Use the route that matches the question.
Use the route that matches the question.
Engagement-specific diligence and security concerns require controlled routing. Public statements remain limited to verified scope.
Engagement-specific diligence and security concerns require controlled routing. Public statements remain limited to verified scope.
SECURITY ROUTES
SECURITY ROUTES
SECURITY REQUIREMENTS
SECURITY REQUIREMENTS
Use Contact with the security topic selected for requirements or due diligence.
Use Contact with the security topic selected for requirements or due diligence.
APPROVED INFORMATION
APPROVED INFORMATION
Request further information through an appropriate confidentiality agreement.
Request further information through an appropriate confidentiality agreement.
SECURITY CONCERN
SECURITY CONCERN
Report a suspected vulnerability or issue to operations@karamataclinical.com with enough detail for evaluation.
Report a suspected vulnerability or issue to operations@karamataclinical.com with enough detail for evaluation.
SAFETY
SAFETY
Do not send PHI, participant data, or highly sensitive material through this website or by unencrypted email.
Do not send PHI, participant data, or highly sensitive material through this website or by unencrypted email.
Do not send PHI, participant data, or highly sensitive material through this website or by unencrypted email.
