Security & Compliance Certifications

At Emmes Group, a leading technology-enabled Clinical Research Organization (CRO), we prioritize data security, compliance, and ethical technology use across all operations. Built on a strong foundation of trust and scientific integrity, our commitment to safeguarding client data is reflected in our certifications to international standards. Additionally, we are GDPR and HIPAA compliant, ensuring robust data protection and privacy across our global operations.

ISO

These certifications, issued by DNV (MGMT. SYS. RvA C 024), reinforce our dedication to secure cloud computing, clinical data privacy, and regulatory compliance in the life sciences sector. Emmes ensures that all technology-driven solutions meet the highest benchmarks for information governance, data protection, and risk management, particularly in the regulated environment of clinical research.

  • ISO ISO/IEC 27001:2022 – Information Security Management System (ISMS)
  • logo ISO/IEC 27018:2019 – Protection of Personal Data in the Cloud

FISMA

Emmes' Advantage eClinical Suite has been granted an independent agency Authority to Operate (ATO) by ISIT Consultants, Pvt. Ltd. under the Federal Information Security Modernization Act (FISMA), following the assessment against NIST SP 800-53 Rev. 5 (Moderate baseline) covering identification and access control, incident response, contingency planning, and system integrity, among other control families. This independent agency-level authorization is separate from, and precedes, the FedRAMP Marketplace authorization described below, which would extend reuse of that authorization to other federal agencies. Together, they reflect Emmes' commitment to protecting federally sponsored research data with the same rigor required of U.S. government systems.

FedRAMP

Our Advantage eClinical platform has achieved FedRAMP in progress status at the Moderate impact level, following an independent Readiness Assessment by an accredited Third-Party Assessment Organization (3PAO). This designation reflects that our cloud infrastructure, including encryption, identity verification, and continuous monitoring capabilities, meets FedRAMP's technical and procedural requirements at the readiness stage, as we progress toward full FedRAMP Authorization.

Security Vulnerability Disclosure Policy

Veridix is committed to maintaining the security of our systems and the data we manage on behalf of our customers. We value the work of independent security researchers and welcome reports that help us identify and address potential vulnerabilities.

If you believe you have discovered a security vulnerability affecting Veridix systems or services, please report it to us at security@veridix.com. Include as much detail as possible — a description of the issue, steps to reproduce it, and any supporting evidence — so our security team can investigate promptly.

We ask that researchers act in good faith: avoid accessing, modifying, or exfiltrating data beyond what is necessary to demonstrate a vulnerability, avoid disrupting production services, and give us a reasonable opportunity to investigate and remediate before any public disclosure. Reports submitted in good faith and in accordance with this policy will not result in legal action from Veridix.

We aim to acknowledge all reports within a reasonable timeframe and will keep researchers informed as we work toward resolution. Thank you for helping us keep Veridix secure.