ISO
These certifications, issued by DNV (MGMT. SYS. RvA C 024), reinforce our dedication to secure cloud computing, clinical data privacy, and regulatory compliance in the life sciences sector. Emmes ensures that all technology-driven solutions meet the highest benchmarks for information governance, data protection, and risk management, particularly in the regulated environment of clinical research.
ISO/IEC 27001:2022 – Information Security Management System (ISMS)
ISO/IEC 27018:2019 – Protection of Personal Data in the Cloud
FISMA
Emmes' Advantage eClinical Suite has been granted an independent agency Authority to Operate (ATO) by ISIT Consultants, Pvt. Ltd. under the Federal Information Security Modernization Act (FISMA), following the assessment against NIST SP 800-53 Rev. 5 (Moderate baseline) covering identification and access control, incident response, contingency planning, and system integrity, among other control families. This independent agency-level authorization is separate from, and precedes, the FedRAMP Marketplace authorization described below, which would extend reuse of that authorization to other federal agencies. Together, they reflect Emmes' commitment to protecting federally sponsored research data with the same rigor required of U.S. government systems.
FedRAMP
Our Advantage eClinical platform has achieved FedRAMP in progress status at the Moderate impact level, following an independent Readiness Assessment by an accredited Third-Party Assessment Organization (3PAO). This designation reflects that our cloud infrastructure, including encryption, identity verification, and continuous monitoring capabilities, meets FedRAMP's technical and procedural requirements at the readiness stage, as we progress toward full FedRAMP Authorization.
Security Vulnerability Disclosure Policy
Veridix is committed to maintaining the security of our systems and the data we manage on behalf of our customers. We value the work of independent security researchers and welcome reports that help us identify and address potential vulnerabilities.
If you believe you have discovered a security vulnerability affecting Veridix systems or services, please report it to us at security@veridix.com. Include as much detail as possible — a description of the issue, steps to reproduce it, and any supporting evidence — so our security team can investigate promptly.
We ask that researchers act in good faith: avoid accessing, modifying, or exfiltrating data beyond what is necessary to demonstrate a vulnerability, avoid disrupting production services, and give us a reasonable opportunity to investigate and remediate before any public disclosure. Reports submitted in good faith and in accordance with this policy will not result in legal action from Veridix.
We aim to acknowledge all reports within a reasonable timeframe and will keep researchers informed as we work toward resolution. Thank you for helping us keep Veridix secure.