Run consent, audit, and data provenance for CRISPR trials on GxP-validated infrastructure built for 21 CFR Part 11, ICH E6(R3), and GDPR — sitting alongside the Medidata and Veeva systems you already run, not replacing them.
Built for trial sponsors, CROs, and authorised treatment centres running gene-editing programs — and the regulatory, clinical-ops, and security teams who have to sign off on them.
Gene-editing programs stack four demands that conventional trial software handles individually, at best — and never together.
Eligibility depends on variant-level genomic analysis across federated datasets that legally can't be centralised. Your EDC can't score patients on data it's not allowed to hold.
Editing a human genome demands a level of tamper-evident provenance and consent traceability that spreadsheet-era audit trails simply don't provide.
Consent and provenance span jurisdictions and treatment centres. When a patient withdraws, that has to propagate everywhere — provably, and without anyone quietly altering the record.
Casgevy has 75+ authorised treatment centres but only ~60 patients treated in two years. The bottleneck is stem cell collection logistics, ATC capacity scheduling, and manufacturing slot coordination — problems your CTMS doesn't even try to solve.
Not three technologies loosely "integrated" — three that each own a distinct, regulator-grounded stretch of the trial and hand off cleanly. The AI works out what to do, CRISPR does it, and every step in between is consented and provable.
Twelve regulatory-grounded capabilities, each mapped to a specific instrument. Here's what they mean for the people running the trial.
Federated scoring and stratification across genomic datasets — Tier-1 data never leaves the originating institution.
Patient Intelligence · ICH E6(R3), GDPR, GINAGuide-RNA design, off-target prediction, and delivery recommendation — with the model governance the EU AI Act and FDA AI/ML guidance now require.
Molecular Intelligence · EU AI Act, FDA AI/MLAdaptive design, simulation, interim analysis, and safety-signal detection under an ICH E9(R1) estimands framework.
Trial Design · ICH E6(R3), E9(R1)Granular consent with a full, tamper-evident lifecycle — and 60-second withdrawal propagation across every capability. Smart-contract option available via Provenance+ upgrade.
Consent Governance · GDPR Art 6–9, HIPAAHash-chained WORM trails and audit-timestamped filings that stand up to inspection. Blockchain timestamping available via Provenance+.
Data Provenance · 21 CFR Part 11LIMS/MES integration, batch records, and QC across manufacturing and reinfusion — patient-safety chain of custody intact.
Manufacturing Integration · 21 CFR 210/211Engraftment, biomarkers, adverse events, and long-term follow-up on the timelines gene-therapy guidance mandates.
Outcome Monitoring · FDA Gene Therapy (15yr)eCTD assembly, safety reports, and timestamped filings — the regulatory spine of the program in one place.
Regulatory Submission · FDA eCTD, ICH M4A dedicated inspection surface so an FDA/EMA/MHRA reviewer can verify trails and submissions without touching live data.
Identity & Access · 21 CFR Part 11, GDPRA versioned target-to-therapy design workflow with full design history — the scientific pipeline that feeds your IND.
Therapy Pipeline · FDA Gene Therapy, EMA ATMPATC qualification, manufacturing-capability assessment, capacity scheduling, and patient-logistics coordination — the operational layer that gets more patients treated.
Site Qualification & Activation · ICH E6(R3), FDA Gene Therapy GuidanceStandard TMF Reference Model compliance plus gene-editing-specific document types — gRNA design records, off-target analyses, batch certificates, provenance proofs — all anchored to the audit trail.
Trial Master File · ICH E6(R3), FDA/EMA TMF GuidanceHelixChain's default audit infrastructure uses conventional WORM storage — append-only records with cryptographic hashing. For organisations that want additional tamper-evidence, the Provenance+ upgrade adds blockchain-anchored audit. Here's how the GDPR erasure concern is resolved for blockchain deployments:
The objection every DPO raises about blockchain in a trial: you can't delete from an immutable ledger, so how do you honour a GDPR erasure request? HelixChain answers it structurally.
Personal data lives off-chain; only cryptographic hashes go on-chain. Erasing the off-chain record and destroying its per-record key renders the on-chain hash meaningless — practical erasure achieved, ledger integrity preserved. It's the difference between a platform your DPO blocks and one they can approve.
Standards-first integration, with proprietary connectors only where no standard exists. Keep Medidata Rave and Veeva Vault; HelixChain adds the genomic, consent, and provenance layer they lack.
| Connects to | Standard | Direction |
|---|---|---|
| Electronic Health Records | HL7 FHIR R4 | Patient data in, outcomes out |
| Genomic data sources | GA4GH htsget / DRS | Federated variant queries in |
| EDC (Medidata Rave, Veeva Vault) | CDISC ODM / SDTM | Bidirectional CRF exchange |
| LIMS / MES | HL7 v2 / SiLA2 | Manufacturing data both ways |
| Regulatory portals | eCTD / FHIR | Submission packages out |
| Your identity provider | OAuth2 / OIDC / SAML | Federated single sign-on |
Integration with existing EDC and institutional IT is real work — we scope it explicitly with you up front rather than pretending it's plug-and-play. Professional-services effort is quoted, not hidden.
What's specified, what's planned, and what's on the certification roadmap — so your vendor assessment gets straight answers.
Security controls are specified in the architecture and will be validated during design-partner deployments. Certification timelines begin from first production deployment.
Existing platforms each own a slice. Running a gene-editing trial across four of them means four integrations, four audit surfaces, and four vendors pointing at each other when something breaks.
| Platform | Patient Intel | Molecular Intel | Consent Gov | Manufacturing | Data Provenance | Site Qual. | TMF |
|---|---|---|---|---|---|---|---|
| Medidata (Dassault) | Limited | — | — | — | Partial | Strong | Strong |
| Veeva Systems | Basic | — | — | — | Partial | Strong | Market leader |
| Recursion Pharma | Strong | Strong | — | — | — | — | — |
| Insilico Medicine | — | Strong | — | — | — | — | — |
| ConsentChain / DWARNA | — | — | PoC only | — | PoC only | — | — |
| HelixChain | Full | Full | Full | Full | Full | Gene-editing | Gene-editing |
Medidata and Veeva are strong on site qualification and TMF for conventional trials. HelixChain's versions are gene-editing-specific — ATC qualification, manufacturing-capability assessment, and gene-editing document types (gRNA design records, off-target analyses, provenance proofs).
Full-program visibility for sponsors, biostatisticians, molecular biologists, regulatory affairs, and pharmacovigilance.
Site-scoped data capture, patient care, and manufacturing for clinical investigators and manufacturing leads.
Consent, withdrawal, and own-data access for trial participants. Own data only.
Read-only audit surface for FDA/EMA/MHRA reviewers to inspect trails and submissions.
We're building the Governance Foundation with a small group of treatment centres and sponsors running CRISPR programs. Design partners shape what we build, see it first, and help establish regulatory acceptance — before anyone else. Not ready for that? A 30-minute discovery conversation is a good place to start.