
Randomization your statisticians trust. Supply your sites actually receive.
Custom Randomization and Trial Supply Management (RTSM / IRT) software for US sponsors, biotechs, and CROs — randomization, kit dispensation, depot and site inventory, expiry and resupply forecasting, and emergency unblinding on one role-aware platform built around your protocol.
Randomization & treatment-arm assignment
Ingest your statistician-generated randomization list, support stratified, block, and adaptive schemes, and assign treatment at the visit with deterministic, reproducible logic — no shadow randomization in spreadsheets.
Kit dispensation & visit workflows
Visit-driven kit requests, kit assignment, dispensation confirmation, and re-dispensation on a single subject-visit timeline — the site sees the kit ID, the unblinded pharmacist sees the actual treatment.
Depot & site inventory management
Depot inventory, lot and expiry tracking, depot-to-site shipments, site-level kit balances, and quarantine workflows on one inventory model — so supply, depot, and site state stay in sync.
Resupply forecasting & expiry management
Visit-projected demand, expiry-aware lot selection, configurable resupply thresholds, and depot-level triggers your clinical supply team can tune per study — instead of a quarterly spreadsheet exercise.
Emergency unblinding & code break
Authorized-role gated unblinding flows with reason capture, immediate notification, role-scoped revelation, and an immutable audit record — designed for pharmacovigilance and serious-adverse-event workflows.
EDC, CTMS, eTMF, eCOA & depot integration
Documented APIs and standard exchange formats for randomization, kit, visit, inventory, and shipment events — so your EDC, CTMS, eTMF, eCOA, and depot or CMO partners stay in sync without manual reconciliation.
Site supply your coordinators can rely on
Visit-driven dispensation, depot-to-site shipments, lot and expiry tracking, and resupply triggers in one model — so missed visits and screen-fails caused by stockouts stop being the story your study managers have to explain.

Randomization and visit decisions, role-aware
Site coordinators see the kit they need; the unblinded pharmacist and statistician see the treatment, drug pool, and depot view — both on one platform, separated by a blinding boundary engineered into the data model.

Engineered with blinding integrity, audit-trail, and validation awareness for regulated randomization and supply
Blinding boundary as first-class engineering
Blinded and unblinded lanes are designed into the data model, the API surface, and the UI — not bolted on. Role transitions, exports, and emergency-unblinding events are logged as engineering-first events your QA team can review.
Audit-trail-aware engineering
Audit logging, e-signature support, and approval gates designed as first-class engineering features. Your QA team executes validation; the platform supplies the engineering evidence.
Traceability your QA team can use
Requirements, design, build, and test artifacts produced with traceability in mind — engineered as inputs your QA function can use during computer-systems validation (CSV) rather than reconstructed at the end.
One control plane. One blinding boundary. Every kit, every visit.
Randomization design flows down through subject visits and out into depot and site supply — with a blinding boundary engineered into the data model so the right role sees the right view, every time.
What your biostatistics and supply leads configure
Schedule of events, visit windows, dispense rules
Site, region, cohort labels visible to study teams
Statistician-provided schedule, block / dynamic
Arm definitions, kit-type mix, dose levels
Where subjects, visits, and kits actually meet
Eligibility, screen-fail, randomization request
Kit number returned to site, dispense confirmation
Arm and dose per subject, recorded once, immutable
Kit-to-lot mapping, lot-level usage by visit
What keeps sites stocked and depots accountable
Available kits per site — quantities only, no arm detail
Lot, expiry, quarantine, depot-to-site shipments
Projected demand, expiry-aware lot selection, triggers
Designed to fit alongside the EDC, CTMS, eTMF, eCOA, depot, and CMO systems your team already runs.
Compliance by design
Blinding boundary enforced at the data layer
Blinded and unblinded roles are scoped at the application and data layer. Blinded users never receive treatment, drug pool, or unblinded inventory data through any view, export, or API. Unblinded views are separately authorized and separately logged.
Engineering artifacts for your validation work
We structure the build so your QA function has the documentation, traceability, and test evidence they need to execute computer-systems validation (CSV) under GAMP 5 expectations. We do not perform validation, write IQ/OQ/PQ, or accept the system on your behalf.
Audit trail as an engineering default
Every action — randomization, dispensation, shipment, inventory adjustment, unblinding, role transition, and configuration change — is logged with actor, timestamp, resource, before/after state, and outcome. Audit records are immutable and exportable for your QA, sponsor, and inspection reviewers.
E-signature support designed for regulated workflows
E-signature flows are engineered with re-authentication, signed-meaning capture, and tamper-evident records — aligned with the practices common in 21 CFR Part 11 and EU Annex 11 environments. Acceptance of those signatures for any specific regulatory purpose is your team’s decision.
Subject / PHI data segmentation
Subject and patient data is tokenized at the application gateway, scoped by role, and kept out of supply, depot, and shipment-facing layers wherever the work allows. Least-privilege defaults across modules and APIs.
Identity & access control
Standards-based identity with enforced MFA, role-scoped access across sponsor, CRO, biostatistics, pharmacy, supply, depot, and IT users, and session controls designed for regulated clinical environments.
Cloud infrastructure for regulated environments
Hosted on cloud regions and configurations commonly used for sensitive clinical data, with private endpoints, infrastructure defined and reviewed via Terraform, and environment promotion gates your QA and IT teams can sign.
Audit-ready on day one
Every component is engineered with blinding-aware role scoping, audit-trail logging, traceability, and lifecycle artifacts your QA, biostatistics, clinical supply, IT, and regulatory teams can use as inputs into their own computer-systems validation (CSV) and inspection-readiness work. Statistical-randomization list generation, randomization-list QC, blinding-design sign-off, final validation execution, IQ/OQ/PQ authoring, sponsor acceptance, and any regulatory submission remain solely the customer’s responsibility, executed by the customer’s biostatistics, QA, clinical supply, and regulatory functions. Sorento Software does not represent, attest, or warrant compliance with ICH-GCP, 21 CFR Part 11, EU Annex 11, GAMP 5, HIPAA, GDPR, or any other regulatory framework on behalf of any customer.
Partner agreements in place
Randomization integrity your statisticians trust
Randomization, stratification, and kit assignment run on a deterministic engine, with a full audit trail and role-scoped access — so the integrity of the schedule and the blind is preserved across the trial.
Blinding boundary that survives audit
Blinded and unblinded roles are enforced at the application and data layer, with separate views, separate exports, and separate API surfaces — so the blind survives staff turnover, sponsor reviews, and inspections.
Site supply your coordinators can rely on
Visit-driven dispensation, depot-to-site shipments, lot and expiry tracking, and resupply triggers in one model — so missed visits and screen-fails caused by stockouts stop being the story.
Less drug waste, fewer expiry write-offs
Expiry-aware lot selection, projected demand, and configurable resupply thresholds give your clinical supply team a forecasting tool that matches the way they actually plan — not a spreadsheet they re-build every cycle.
Coexists with the stack your team already runs
Documented APIs and standard data formats let the RTSM platform sit alongside your EDC, CTMS, eTMF, eCOA, and depot partners — your IT team owns the connectors, and the systems your team relies on stay in place.
Our Implementation Process
Discovery, scope & engineering framing
We map your protocol families, randomization design, blinding model, depot and site supply chain, current IRT / RTSM landscape, and integration points; identify the highest-pain workflows; and frame the engineering and integration shape before scoping the build. Randomization-list generation, statistical sign-off, and validation strategy stay with your team.
Architecture & validation-aware engineering plan
Design the randomization engine, kit and visit data model, blinding-aware role model, inventory and resupply model, audit-trail architecture, and integration topology, alongside your IT, biostatistics, QA, and clinical supply stakeholders. Documents are produced as inputs into your computer-systems validation work.
Build & iterate
Iterative full-stack development of the platform — randomization, kit dispensation, depot and site inventory, expiry and resupply, emergency unblinding, and reporting modules — with engineering artifacts (test coverage, traceability matrices, change logs) captured as part of the build rather than reverse-engineered at the end.
Integration & handoff to your QA / clinical supply function
Connect to your existing EDC, CTMS, eTMF, eCOA, depot, and CMO systems via documented APIs and standard data formats, run end-to-end UAT with your clinical supply, biostatistics, and CRA teams, and assemble the engineering documentation your QA function uses as inputs into IQ/OQ/PQ and CSV.
Deployment, hypercare & lifecycle operations
Phased rollout to study teams, depot partners, and sites with an initial hypercare period covering randomization stability, supply behavior, change-control reviews, and adoption support — so the platform stays in a known state as studies progress and protocols amend.
Frequently Asked Questions
Will this RTSM replace our EDC, CTMS, eTMF, or eCOA system?
No. The RTSM we build is designed to coexist with the EDC, CTMS, eTMF, eCOA, depot, and CMO systems you already run, using documented APIs and standard data exchange formats (for example, HL7 FHIR R4 and CDISC ODM where applicable). It is the role-aware engine for randomization, kit dispensation, depot and site inventory, expiry and resupply, and emergency unblinding — and it hands off to your validated upstream and downstream systems through connections your IT and integration teams own.
How do you handle blinding integrity and emergency unblinding?
Blinded and unblinded lanes are enforced at the application and data layer — not by an honor system on top of a single view. Blinded study teams, CRAs, and sites see kit IDs, visit status, and site-level kit counts; unblinded pharmacists, statisticians, and supply managers see treatment, drug pool, depot detail, and shipment lots. Emergency unblinding runs through an authorized-role gated workflow with re-authentication, reason capture, immediate notification, role-scoped revelation, and an immutable audit record your QA and pharmacovigilance teams can reconstruct.
Will the platform satisfy a sponsor or FDA / EMA inspection?
We are a software engineering partner. We engineer the platform with the blinding-aware, audit-trail, e-signature, role-scoped access, and traceability practices that are common in ICH-GCP, 21 CFR Part 11, EU Annex 11, and GAMP 5 environments, and we deliver an engineering artifact set your QA team can use as inputs into computer-systems validation (CSV). Statistical-randomization list generation, list QC, blinding-design sign-off, IQ/OQ/PQ authoring, sponsor acceptance, and inspection responses are owned by your biostatistics, QA, clinical supply, and regulatory functions. We do not represent compliance with any framework on your behalf.
How are depot, site inventory, expiry, and resupply handled?
Depot inventory, site inventory, lot and expiry, quarantine, and shipment status all live on one inventory model. Visit-driven dispensation updates site balances; depot-to-site shipments are tracked with lot detail and expiry windows; expiry-aware lot selection chooses which kit to assign next; and configurable resupply thresholds — set per study and per depot — generate the triggers your clinical supply team plans against. Forecasting is projected from the protocol visit schedule and configured demand assumptions your supply lead controls.
How do you handle subject data, PHI, and access control?
Subject and patient data is tokenized at the application gateway, segmented by sensitivity, and access-scoped by role — sponsor, CRO, site, pharmacy, biostatistics, supply, depot, and IT users each see only what their role requires. PHI is kept out of supply, depot, and shipment-facing layers wherever the work allows. Every action is logged with actor, timestamp, resource, and outcome so your QA and sponsor reviewers can trace activity through the platform. The engineering practices are aligned with what customers in regulated clinical environments typically expect; we make no compliance certifications on your behalf.
What does a typical engagement look like, and how do you scope it?
Scope, timeline, and investment vary by program and are defined during discovery — we do not quote fixed durations, fixed costs, or fixed inspection outcomes on a public page. Discovery is where we map your protocol families, randomization design, blinding model, depot and site supply chain, current IRT / RTSM landscape, and integration points, then frame the engineering and integration shape before any production-bound code is written. After discovery, the build is typically phased so the highest-priority capability goes live first and your clinical supply, biostatistics, and QA teams can review the platform before later phases land.
Bringing randomization and trial supply onto one platform?
Book a free 30-minute discovery call. We will review your protocol families, randomization design, blinding model, depot and site supply chain, current systems, and integration constraints, then outline a realistic engineering and integration shape. Statistical sign-off, validation, sponsor acceptance, and regulatory decisions remain with your team.