Trial Deck - S3R Randomisation Module
S3R is a cloud based randomisation service for clinical research, providing secure, auditable participant allocation with reproducibility for review without enabling allocation predictability. It supports configurable methods, allocation concealment, dry run simulation using synthetic participants, emergency and offline contingency workflows, and full audit trails. Integrates with Trial Deck or standalone.
Features
- Secure seeded randomisation ensuring reproducibility without allocation predictability
- Roadmap: Adaptive and platform designs supported from Q4 2026
- Modular combination of stratification, blocks, and covariate minimisation
- Concealed allocation with role based visibility controls
- Emergency offline allocations generated from pre-generated seeds
- Full audit trail of randomisation configuration and execution
- Dry run simulations using synthetic participants and variable seeds
- Support for N-of-1, crossover, and staged randomisation designs
- Recovery and reproducibility through frozen seeds and versioning
- Integration with Trial Deck CTMS, EDC, and intervention workflows
Benefits
- Enable reproducibility without predictability using frozen, auditable randomisation seeds
- Combine stratification, blocks, and minimisation within a single statistical engine
- Simulate allocation behaviour through repeatable dry runs before trial launch
- Detect and manage sparse strata using explicit, configurable statistical strategies
- Maintain allocation integrity across multi site and asynchronous recruitment
- Support N-of-1 and complex longitudinal trial designs natively
- Provide full audit traceability from protocol through every allocation decision
- Reduce bias risk via deterministic recovery and controlled randomisation replay
- Future-proof trials with adaptive and response based designs already planned
- Support statistical review with versioned specifications and reproducible reruns
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 4 1 6 5 4 8 8 0 2 4 1 1 1 6
Contact
GLOBAL INITIATIVE LIMITED
Chris Sinclair
Telephone: 01865 203100
Email: ideas@global-initiative.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires an internet connection and a modern web browser. Planned maintenance is carried out at scheduled intervals and outside of UK working hours where possible. Support is provided during UK business hours. SMS and email notifications are subject to third party delivery services and additional fees may apply.
- System requirements
-
- Does not require local software installation.
- Current versions of Chrome, Edge, Firefox and Safari.
- An internet connection is required.
- No additional software licences, plugins or buyer managed infrastructure required.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Standard SLA, we offer extended at extra cost.
Ticketing: Triage is complete and initial response within 2 working days. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
All SLAs apply during UK working hours only, Monday to Friday, 9am to 5pm, excluding UK public holidays. All SLAs are subject to the Call Off Contract. Planned & emergency maintenance outside business hours where possible. Maintenance, third party services, including SMS, email delivery, and external integrations, are excluded from availability guarantees. Delivery Manager assigned to each account.
Standard SLA (included)
The Standard SLA is included within the annual licence fee and is suitable for most academic and public sector research studies.
- Incident response time: within 2 working days
- Target time to recovery: within 2 working days
- Availability: best efforts
The supplier will use reasonable best efforts to restore service availability, taking account of issue severity and impact.
Extended SLA (optional)
An Extended SLA is available for an additional £10,000+VAT per annum, providing enhanced service commitments.
- Incident response time: same working day
- Target time to recovery: 1 working day
- Availability commitment: 99.9 percent uptime measured over rolling three month periods
- Exclusions: customer induced downtime, third party services, and force majeure events - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Trial Deck is designed as a user-driven randomisation system, allowing study teams to configure and manage randomisation directly, using tools that align closely with how randomisation is described in protocols and statistical analysis plans.
Getting started involves structured configuration of the S3R (Secure Seeded Study Randomisation) module by the study team, supported by training, clear documentation, and access to a delivery manager for practical questions and guidance. The interface provides step-by-step configuration screens, contextual explanations, and validation checks to support accurate translation of the intended randomisation design.
The system includes a dedicated testing area using synthetic participants, allowing teams to run dry runs, review allocation behaviour, confirm reproducibility, and explore edge cases such as sparse strata or changing recruitment patterns. Outputs can be reviewed internally by the study statistician or sponsor as part of routine checks.
As this is a self-service system, responsibility for confirming that the implemented algorithm reflects the approved statistical design remains with the study team. Trial Deck can provide a technical fit for purpose statement confirming that the configuration matches the supplied specification.
For studies requiring complex or bespoke designs, we work directly with the statistician to implement custom randomisation approaches under a separate consultancy arrangement. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Jira service management portal
- End-of-contract data extraction
- Study teams can export all randomisation related data using a self service export capability in the S3R module. Exports include the randomisation specification, frozen seed values, allocation ratios, stratification factors, covariates and weights, block definitions, version history, and full audit trails. Where concealment rules permit, exports can include participant level allocations with timestamps, reveal status, and identification of any emergency or offline allocations. Exports are provided in open formats suitable for archiving and statistical review. Each export includes an integrity check, including a signed cryptographic hash, so buyers can verify that the exported package matches the source system at the point of export.
- End-of-contract process
- At contract end, customers retain access for an agreed exit period to complete exports and confirm receipt. The contract price includes access to self service exports, standard documentation, and support during the agreed offboarding window. Once export is complete, customer access is withdrawn. Randomisation data is then retained, archived, or securely destroyed in line with the agreed retention period and contractual arrangements. Optional services include extended access periods, managed export packs for inspection or statistical review, and long term archiving support.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Only the participant and supporter interface is mobile-first. Researcher's GUI is desktop first and tablet compatible.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Yes. The service is accessed through a secure, browser based web interface for researchers and study teams. The service also provides documented APIs to support system integrations and data exchange where required.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface has been tested against WCAG 2.2 AA criteria, including keyboard navigation, focus management, colour contrast, and screen reader compatibility. Testing has included use with common assistive technologies such as screen readers and browser accessibility tools. Accessibility issues identified are tracked and addressed as part of ongoing product development and quality assurance.
- API
- Yes
- What users can and can't do using the API
-
Trial Deck S3R provides a documented REST API to support secure integration of randomisation and allocation workflows with external systems. API access is managed through a secure token based authentication mechanism and is subject to authorisation and rate limiting.
Authorised systems may:
Allocate participants using the S3R randomisation engine
Retrieve a participant’s allocation status
Reveal treatment allocation where protocol and role permissions allow
Trigger emergency or contingency allocation workflows where configured
Synchronise allocation outcomes with CTMS, EDC, pharmacy, or logistics systems
Support offline or deferred allocation recovery
All allocation and reveal actions performed via the API are fully audited, timestamped, and attributable, only where protocol and role permissions allow
The API does not permit:
Modification of randomisation configuration, strata, covariates, or weights
Alteration of seeds, allocation ratios, or concealment rules
Deletion or rewriting of allocation history or audit records
Bypassing role based permissions or protocol defined constraints
Randomisation design, configuration, testing, and governance controls are managed exclusively through the secure web interface to preserve statistical integrity, concealment, and regulatory compliance. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The S3R Randomisation Module supports both configurable randomisation design and optional bespoke statistical development.
Authorised users can configure randomisation schemes through the secure web interface, including:
- Randomisation method selection, including simple, block, stratified, and minimised approaches
- Definition of stratification factors and covariates, including weights and tie breaking rules
- Allocation ratios, block sizes, fixed or variable blocks, and concealment settings
- Emergency allocation and offline envelope generation
- Reproducibility controls including seed management and versioning
- Testing and dry run simulations using synthetic participants
Bespoke randomisation algorithms
Where study designs require novel or highly complex randomisation approaches, the S3R engine supports the integration of custom randomisation algorithms. In these cases, Trial Deck developers work directly with the customer’s statistician to design, implement, and validate study specific logic, including adaptive or hybrid approaches.
Bespoke algorithm development, validation, and documentation are provided at our hourly rate.
Standard configuration is performed through a secure, browser based interface without software development. Bespoke randomisation algorithms are developed, tested, and deployed by the supplier following documented change control, validation, and audit procedures.
Scaling
- Independence of resources
- Trial Deck is delivered using logically segregated environments with role based access controls and workload isolation where appropriate. System resources are monitored continuously, and capacity is scaled to ensure individual customer usage does not adversely affect the performance or availability experienced by other users. Where required, dedicated environments or resource allocations can be provided by agreement. All resource management is handled centrally and does not require customer intervention.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Trial Deck provides service usage and operational metrics through a dedicated Matomo analytics instance. Metrics include platform usage, user activity, feature interaction, and session trends, with visibility segmented by user roles and user types. Metrics can be extended through additional Matomo modules or configuration where required, subject to agreement. All metrics are collected and reported in line with applicable data protection requirements, remain within the UK, and are not shared.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Study teams can export randomisation data using a self service export capability, providing complete randomisation records in open, commonly used formats. Exports include randomisation configuration, seed values, allocation ratios, stratification factors, covariates, block definitions, participant allocations, timestamps, version history, and full audit trails, supporting ALCOA++ principles.
Each export includes a signed cryptographic hash, enabling verification of export integrity against the source system and confirming that data has not been altered post export. Exports respect concealment and role based access rules. Emergency or offline allocations are clearly identified and fully traceable. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- 2026: CDISC
- 2026: SAS XPT
- 2026: XML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- 2026: CDISC ODM or SDTM
- 2026: SAS XPT
- 2026: XML
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Trial Deck is provided with a standard service level agreement included within the annual licence fee, which operates on a best efforts basis and does not include a guaranteed availability percentage. Service hours for the standard SLA are 9am to 5pm UK working days, with defined response and recovery targets.
An extended SLA is available at additional cost and includes a guaranteed availability target of 99.9% uptime, measured over a rolling 3-monthly period and excluding planned or emergency maintenance. Where availability under the extended SLA falls below the guaranteed level, service credits are applied in accordance with the agreed call off contract terms. All SLAs, including availability commitments and any associated service credits, are subject to the individual call off contract. - Approach to resilience
-
Trial Deck is designed to be resilient through a combination of platform controls, operational processes, and resilient third party infrastructure. The service is hosted on established cloud providers which operate resilient datacentre environments with redundant power, cooling, and network connectivity.
At platform level, the service uses monitored infrastructure, automated health checks, and regular backups to protect against data loss and service disruption. Backups are encrypted and stored separately to support recovery. Capacity is actively monitored and scaled to manage demand and reduce the risk of performance degradation caused by individual workloads.
Operational resilience is supported through defined incident management procedures, role based access controls, audit logging, and change management processes. Planned maintenance is carried out outside UK business hours where possible to minimise user impact.
Detailed information about underlying datacentre resilience, including physical controls and infrastructure redundancy, is managed by the hosting providers and can be made available on request. - Outage reporting
- Service availability and incidents are communicated to customers through direct notifications. Service interruptions and significant incidents are reported by email to nominated customer contacts. A public status dashboard or outage reporting API is not provided as part of the standard service. Where required, a dedicated status dashboard can be provided as an optional, chargeable service. Outage updates and incident summaries may also be shared through the service management portal.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through role based access control and least privilege principles. Organisational user accounts are created and managed by the Trial Deck administrative team, following approval and verification. Administrative access is limited to authorised personnel only and protected using strong authentication, including multi factor authentication where appropriate. Access rights are granted on a need to know basis and reviewed regularly. All management actions and support access are logged and auditable. Support requests are handled through controlled channels, with identity verification performed before any action affecting customer data or service configuration.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
NHS DSPT
Cyber Essentials - Information security policies and processes
-
Global Initiative operates a documented information security management system aligned with ISO 27001, NHS DSPT, and Cyber Essentials requirements. Information security policies cover access control, data protection, incident management, supplier assurance, change control, and business continuity.
Responsibility for information security sits with senior management, with clear reporting lines to the Managing Director. Security incidents, risks, and compliance matters are logged, reviewed, and escalated in line with defined procedures. Policies are communicated to staff through onboarding, regular training, and ongoing awareness activities.
Compliance with policies is enforced through role based access controls, logging and monitoring, internal reviews, and periodic audits. Corrective actions are tracked to resolution. Third party suppliers are assessed and managed through due diligence and contractual controls to ensure alignment with security requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration and change management for Trial Deck is controlled through documented processes operated in line with ISO 27001 and 9001 requirements.
Application code, configuration, and dependencies are tracked using version control and managed deployment pipelines. Changes are recorded, traceable, and auditable from development through release, with defined configuration baselines maintained across environments.
All changes are assessed prior to deployment for potential security, availability, and data protection impact. Higher risk changes require approval and testing before release. Changes are deployed in a controlled manner with rollback procedures where appropriate. Logs and audit records are retained to support accountability and continuous improvement. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability management for Trial Deck follows documented processes aligned with ISO 27001 and ISO 9001.
Threats are assessed through automated monitoring, dependency review, penetration testing, and review of configuration and access controls. Vulnerabilities are prioritised based on risk to confidentiality, integrity, and availability.
Security patches are deployed through controlled change management. Critical updates are applied as soon as practicable, with lower risk updates scheduled weekly.
Threat intelligence is obtained from vendor advisories, cloud provider notifications, vulnerability databases, penetration testing reports, and relevant NCSC portal alerts. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Global Initiative operates layered server and service monitoring to support availability, performance, and security. Metrics and logs are collected centrally to provide visibility of system health, capacity, and behaviour. Monitoring dashboards and alerting are used to detect abnormal conditions and notify administrators.
Protective monitoring includes operating system level auditing using auditd to support intrusion detection and investigation, alongside application and service level monitoring. Hosting providers also supply infrastructure level monitoring and alerts. Monitoring data supports incident detection, forensic analysis, and recovery activities, and is reviewed regularly in line with documented incident management procedures. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a documented incident management process aligned with ISO 27001 and ISO 9001, with predefined playbooks for common events including service outages, security incidents, and data breaches.
Incidents are reported via the service desk, support email, or automated monitoring. The InfoSec team triages incidents based on risk, impact, urgency, and cost. Containment, investigation, forensic analysis, and recovery are completed before closure.
Incident reports are provided to buyers. We respond within one working day, with an RPO of 24 hours and an RTO of 8 working hours. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Trial Deck provides Simple Randomisation for free to all users (no API integrations or other services are included). This includes free trials of other services on Trial Deck.
- Link to free trial
- Contact us, please
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau / Amtivo
- ISO/IEC 27001 accreditation date
- Friday 11 July 2025
- What the ISO/IEC 27001 doesn’t cover
-
Marketing websites, typically under £20,000+VAT
MVP products, typically under £30,000+VAT
Projects that are exclusively Design focused (QMS only)
SoA control A.14.2.7 Outsourced development (We do not outsource development) - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau / Amtivo
- ISO 9001 accreditation date
- Friday 11 July 2025
- What the ISO 9001 doesn’t cover
- British Assessment Bureau / Amtivo
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- NHS DSPT
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-