Skip to main content
Clinical research professional reviewing trial monitoring information on a laptop in a medical setting
Clinical Solutions

One CTMS your monitors actually use and your sponsors actually trust.

Custom Clinical Trial Management Systems for US sponsors, biotechs, and CROs — one operational source of truth across studies, sites, visits, monitoring, issues, and site payments, built around the way your clinical operations team actually runs trials.

One source of truth
Across studies, sites, and visits
Risk-based monitoring
Central, remote, and on-site visits in one workflow
Built to coexist
With your EDC, eTMF, IRT, and safety stack
Portfolio visibility
Studies, sites, and visits in one place
Live operational visibility across the trial portfolio — country, study, site, subject, and visit — replacing scattered status decks and emailed trackers.
Faster site activation
Start-up tasks, essential docs, country approvals
Activation workflows that surface the next blocking task per site, so country approvals and essential-document collection stop being a hunt across inboxes.
Risk-based monitoring
Risk indicators, thresholds, visit triggers
A monitoring engine that supports central, remote, and on-site visit workflows, with risk indicators and thresholds tuned to your monitoring plan.
Payments off the spreadsheet
Visit-triggered accruals, holdbacks, pass-throughs
Site budgets, holdbacks, and pass-throughs handed off to finance via documented APIs, so site payments stop being a quarter-end reconciliation exercise.

Portfolio & study management

Portfolio, program, study, country, and site views with milestones, status, and risk signals. Configurable study templates so each new protocol does not start from a blank page.

Site selection, start-up & activation

Investigator and site database, feasibility tracking, essential-document checklists, country approval timelines, and activation task workflows — visible at every level from portfolio to site.

Subject enrollment & status tracking

Screening, enrollment, randomization, screen-fail, discontinuation, and completion tracking per site and per cohort, kept in sync with upstream EDC and IRT systems through documented APIs your IT team controls.

Monitoring visit workflows

Pre-visit planning, on-site, remote, and central monitoring visit reports, findings capture, follow-up letters, and CRA / CRO oversight — engineered to fit risk-based and traditional monitoring plans alike.

Issue, action, and CAPA tracking

Findings, action items, deviations, and CAPAs tracked with owners, due dates, escalation, and resolution history — so issues survive monitor turnover and stay visible to study managers and sponsors.

Site budgets, contracts & payments

Per-visit fee schedules, holdbacks, pass-throughs, and milestone-driven site payment accruals, exportable to your finance and AP systems via documented APIs — no shadow spreadsheet of what each site is owed.

Clearer signals for monitors and study managers

Dashboards that surface enrollment, monitoring, and risk signals across the portfolio — supporting your monitors, study managers, and sponsor leads instead of replacing their judgement.

Clinical operations professional reviewing trial status data on a laptop in a hospital corridor

Site payments your finance team will actually accept

Visit-triggered accruals, holdbacks, and pass-throughs engineered as part of the platform — so site payments stop being a spreadsheet exercise reconciled at quarter end.

Finance and clinical operations team members reviewing site payment records together
Engineering posture

Engineered with audit-trail, validation, and inspection awareness for regulated clinical operations

Engineering posture aligned with the practices common in ICH-GCP, 21 CFR Part 11, EU Annex 11, HIPAA, and GDPR environments

Audit-trail-aware engineering

Audit logging, e-signature support, and approval gates designed as first-class engineering features. Your QA team executes validation; the platform supplies the engineering evidence.

Traceability your QA team can use

Requirements, design, build, and test artifacts produced with traceability in mind — engineered as inputs your QA function can use during computer-systems validation (CSV) rather than reconstructed at the end.

Subject and PHI data treated as first class

Subject and patient data is segmented, tokenized, and access-scoped at the application layer by default, with role-scoped views for sponsor, CRO, monitor, and finance users.

ICH-GCP21 CFR Part 11EU Annex 11HIPAAGDPRCDISCHL7 FHIR
How it all connects

One control plane for every study, site, and visit.

Setup inputs flow down through the operations lifecycle, and every action the lifecycle produces flows back out as audit-trail-aware evidence your QA, monitoring, and sponsor teams can read.

One operational record
Band 1 · Setup

What your study coordinators configure

Protocol & milestones

Versioned schedule of events, study calendar

Sites & investigators

Country, region, activation tracking

Budgets & contracts

Per-visit fees, holdbacks, pass-throughs

Risk & monitoring plan

Risk indicators, visit cadence, thresholds

Band 2 · Operations lifecycle

Where the study actually runs

Start-up

Activation tasks, essential docs, country approvals

Enrollment

Screen, randomize, screen-fail, withdrawal tracking

Monitoring

Remote, on-site, and risk-based visit reports

Issues & actions

Findings, CAPAs, follow-up, escalation

Close-out

Site close visits, document reconciliation, archive

Band 3 · Evidence & outputs

What your QA, sponsor, and finance teams consume

Audit trail

Immutable record per action, user, timestamp

eTMF & DM handoffs

Essential-doc events, data-mgmt sync via APIs

Site payments

Visit-triggered accruals, holdbacks, pass-throughs

Inspection-ready reporting

Portfolio, study, country, site, and risk views

21 CFR Part 11ICH-GCPHIPAAGDPRCDISCEMA Annex 11

Designed to fit alongside the EDC, eTMF, IRT, safety, and finance systems your team already runs.

Compliance by design

ICH-GCP (Good Clinical Practice)21 CFR Part 11 (electronic records & signatures)EU Annex 11 (computerised systems)HIPAA + HITECHGDPRCDISC standards (ODM / SDTM / Define-XML, where applicable)

Engineering artifacts for your validation work

We structure the build so your QA function has the documentation, traceability, and test evidence they need to execute computer-systems validation (CSV). We do not perform validation, write IQ/OQ/PQ, or accept the system on your behalf.

Audit trail as an engineering default

Every action — create, read, update, delete, sign, approve, and re-open — is logged with actor, timestamp, resource, before/after state, and outcome. Audit records are immutable and exportable for your QA, sponsor, and inspection reviewers.

E-signature support designed for regulated workflows

E-signature flows are engineered with re-authentication, signed-meaning capture, and tamper-evident records — aligned with the practices common in 21 CFR Part 11 and EU Annex 11 environments. Acceptance of those signatures for any specific regulatory purpose is your team’s decision.

Subject / PHI data segmentation

Subject and patient data is tokenized at the application gateway, scoped by role, and kept out of monitoring and reporting layers wherever the work allows. Least-privilege defaults across modules and APIs.

Identity & access control

Standards-based identity with enforced MFA, role-scoped access across sponsor, CRO, monitor, finance, and IT users, and session controls designed for regulated clinical environments.

Cloud infrastructure for regulated environments

Hosted on cloud regions and configurations commonly used for sensitive clinical data, with private endpoints, infrastructure defined and reviewed via Terraform, and environment promotion gates your QA and IT teams can sign.

Audit-ready on day one

Every component is engineered with audit-trail logging, role-scoped access, traceability, and lifecycle artifacts your QA, clinical operations, IT, and regulatory teams can use as inputs into their own computer-systems validation (CSV) and inspection-readiness work. Final validation execution, IQ/OQ/PQ authoring, sponsor acceptance, and any regulatory submission remain solely the customer’s responsibility, executed by the customer’s QA and regulatory functions. Sorento Software does not represent, attest, or warrant compliance with ICH-GCP, 21 CFR Part 11, EU Annex 11, HIPAA, GDPR, or any other regulatory framework on behalf of any customer.

Partner agreements in place

BAADPASLA

One operational truth across the portfolio

Sponsors, study managers, monitors, and CRO leads see the same status, the same risk signals, and the same site state — replacing the patchwork of decks, spreadsheets, and emailed trackers.

Faster, cleaner site activation

Start-up tasks, essential-document checklists, and country-approval timelines tracked per site so the next blocking step is always visible — and activation stops being a hunt across inboxes.

Risk-based monitoring you can actually execute

Configurable risk indicators, thresholds, and visit cadences support central, remote, and on-site monitoring in one workflow, so your monitoring plan becomes operational instead of aspirational.

Coexists with the stack your team already runs

Documented APIs and standard data formats let the CTMS sit alongside your EDC, eTMF, IRT/RTSM, safety, and finance systems — your IT team owns the connectors, and the systems your team relies on stay in place.

Site payments off the spreadsheet

Visit-triggered accruals, holdbacks, and pass-through tracking flow into finance via documented APIs, so site payments stop being a spreadsheet exercise reconciled at quarter end.

Our Implementation Process

1
Scoped during discovery

Discovery, scope & engineering framing

We map your trial portfolio, monitoring model, current spreadsheet / system landscape, and integration points; identify the highest-pain workflows; and frame the engineering and integration shape before scoping the build. Validation strategy and sponsor acceptance criteria stay with your team.

Workflow map, system inventory, integration outline, prioritized roadmap, engineering and integration framing document
2
Phased per engagement

Architecture & validation-aware engineering plan

Design the data model, audit-trail architecture, role-scoped access model, monitoring engine, and integration topology, alongside your IT, security, QA, and clinical operations stakeholders. Documents are produced as inputs into your computer-systems validation work.

Architecture document, data model, audit-trail design, security architecture, integration outline, validation-input package
3
Phased per engagement

Build & iterate

Iterative full-stack development of the platform — portfolio, study, site, subject, monitoring, issue, and payment modules — with engineering artifacts (test coverage, traceability matrices, change logs) captured as part of the build rather than reverse-engineered at the end.

Working platform, engineering artifact set, audit-trail dashboards, configurable study templates, integration hooks
4
Phased per engagement

Integration & handoff to your QA / clinical operations function

Connect to your existing EDC, eTMF, IRT/RTSM, safety, and finance systems via documented APIs and standard data formats, run end-to-end UAT with your clinical operations and CRA teams, and assemble the engineering documentation your QA function uses as inputs into IQ/OQ/PQ and CSV.

Integration runbooks, UAT sign-off, security test report, engineering documentation set for QA / CSV intake
5
Defined per engagement

Deployment, hypercare & lifecycle operations

Phased rollout to study teams, monitors, and CRO partners with an initial hypercare period covering monitoring stability, change-control reviews, and adoption support — so the platform stays in a known state as studies progress.

Production deployment, monitoring dashboards, change-control playbook, hypercare support, training materials

Frequently Asked Questions

Will this CTMS replace our EDC, eTMF, IRT, or safety system?

No. The CTMS we build is designed to coexist with the EDC, eTMF, IRT/RTSM, safety, and finance systems you already run, using documented APIs and standard data exchange formats (for example, HL7 FHIR R4 and CDISC ODM where applicable). It is the operational source of truth for study conduct — sites, subjects, visits, monitoring, issues, and payments — and it hands off to your validated upstream and downstream systems through connections your IT and integration teams own.

Will the platform satisfy a sponsor or FDA / EMA inspection?

We are a software engineering partner. We engineer the platform with the audit-trail, e-signature, role-scoped access, and traceability practices that are common in ICH-GCP, 21 CFR Part 11, and EU Annex 11 environments, and we deliver an engineering artifact set your QA team can use as inputs into computer-systems validation (CSV). Final validation execution, IQ/OQ/PQ authoring, sponsor acceptance, and inspection responses are owned by your QA, clinical operations, and regulatory functions. We do not represent compliance with any framework on your behalf.

How do you handle subject data, PHI, and access control?

Subject and patient data is tokenized at the application gateway, segmented by sensitivity, and access-scoped by role — sponsor, CRO, monitor, study manager, finance, and IT users each see only what their role requires. PHI is kept out of monitoring and reporting layers wherever the work allows. Every action is logged with actor, timestamp, resource, and outcome so your QA and sponsor reviewers can trace activity through the platform. The engineering practices are aligned with what customers in regulated clinical environments typically expect; we make no compliance certifications on your behalf.

Can you support risk-based monitoring, remote monitoring, and on-site visits in one workflow?

Yes. The monitoring engine is engineered around a single visit-and-finding model that supports central, remote, and on-site monitoring visits, with configurable risk indicators, thresholds, and visit cadences tuned to your monitoring plan. Findings, action items, deviations, and CAPAs are tracked with owners, due dates, escalation, and resolution history — so issues survive monitor turnover and stay visible to study managers and sponsors.

How are site payments handled?

Site budgets, per-visit fee schedules, holdbacks, and pass-throughs are configured per study. As visits complete and milestones are reached, the platform calculates accruals and prepares them for handoff to your finance and AP systems via documented APIs. Payment status and history live alongside the operational record for each site, so finance, clinical operations, and site management see the same numbers.

What does a typical engagement look like, and how do you scope it?

Scope, timeline, and investment vary by program and are defined during discovery — we do not quote fixed durations, fixed costs, or fixed inspection outcomes on a public page. Discovery is where we map your trial portfolio, monitoring model, current system and spreadsheet landscape, and integration points, then frame the engineering and integration shape before any production-bound code is written. After discovery, the build is typically phased so the highest-priority capability goes live first and your clinical operations and QA teams can review the platform before later phases land.

Bringing your CTMS into one control plane?

Book a free 30-minute discovery call. We will review your trial portfolio, monitoring model, current systems, and integration constraints, then outline a realistic engineering and integration shape. Validation, sponsor acceptance, and regulatory decisions remain with your team.