Skip to main content

Help us improve the Digital Marketplace - send your feedback

GLOBAL INITIATIVE LIMITED

Trial Deck - S3R Randomisation Module

S3R is a cloud based randomisation service for clinical research, providing secure, auditable participant allocation with reproducibility for review without enabling allocation predictability. It supports configurable methods, allocation concealment, dry run simulation using synthetic participants, emergency and offline contingency workflows, and full audit trails. Integrates with Trial Deck or standalone.

Features

  • Secure seeded randomisation ensuring reproducibility without allocation predictability
  • Roadmap: Adaptive and platform designs supported from Q4 2026
  • Modular combination of stratification, blocks, and covariate minimisation
  • Concealed allocation with role based visibility controls
  • Emergency offline allocations generated from pre-generated seeds
  • Full audit trail of randomisation configuration and execution
  • Dry run simulations using synthetic participants and variable seeds
  • Support for N-of-1, crossover, and staged randomisation designs
  • Recovery and reproducibility through frozen seeds and versioning
  • Integration with Trial Deck CTMS, EDC, and intervention workflows

Benefits

  • Enable reproducibility without predictability using frozen, auditable randomisation seeds
  • Combine stratification, blocks, and minimisation within a single statistical engine
  • Simulate allocation behaviour through repeatable dry runs before trial launch
  • Detect and manage sparse strata using explicit, configurable statistical strategies
  • Maintain allocation integrity across multi site and asynchronous recruitment
  • Support N-of-1 and complex longitudinal trial designs natively
  • Provide full audit traceability from protocol through every allocation decision
  • Reduce bias risk via deterministic recovery and controlled randomisation replay
  • Future-proof trials with adaptive and response based designs already planned
  • Support statistical review with versioned specifications and reproducible reruns

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ideas@global-initiative.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 4 1 6 5 4 8 8 0 2 4 1 1 1 6

Contact

GLOBAL INITIATIVE LIMITED Chris Sinclair
Telephone: 01865 203100
Email: ideas@global-initiative.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service requires an internet connection and a modern web browser. Planned maintenance is carried out at scheduled intervals and outside of UK working hours where possible. Support is provided during UK business hours. SMS and email notifications are subject to third party delivery services and additional fees may apply.
System requirements
  • Does not require local software installation.
  • Current versions of Chrome, Edge, Firefox and Safari.
  • An internet connection is required.
  • No additional software licences, plugins or buyer managed infrastructure required.

User support

Email or online ticketing support
Yes
Support response times
Standard SLA, we offer extended at extra cost.
Ticketing: Triage is complete and initial response within 2 working days.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
All SLAs apply during UK working hours only, Monday to Friday, 9am to 5pm, excluding UK public holidays. All SLAs are subject to the Call Off Contract. Planned & emergency maintenance outside business hours where possible. Maintenance, third party services, including SMS, email delivery, and external integrations, are excluded from availability guarantees. Delivery Manager assigned to each account.

Standard SLA (included)

The Standard SLA is included within the annual licence fee and is suitable for most academic and public sector research studies.
- Incident response time: within 2 working days
- Target time to recovery: within 2 working days
- Availability: best efforts

The supplier will use reasonable best efforts to restore service availability, taking account of issue severity and impact.

Extended SLA (optional)

An Extended SLA is available for an additional £10,000+VAT per annum, providing enhanced service commitments.
- Incident response time: same working day
- Target time to recovery: 1 working day
- Availability commitment: 99.9 percent uptime measured over rolling three month periods
- Exclusions: customer induced downtime, third party services, and force majeure events
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Trial Deck is designed as a user-driven randomisation system, allowing study teams to configure and manage randomisation directly, using tools that align closely with how randomisation is described in protocols and statistical analysis plans.

Getting started involves structured configuration of the S3R (Secure Seeded Study Randomisation) module by the study team, supported by training, clear documentation, and access to a delivery manager for practical questions and guidance. The interface provides step-by-step configuration screens, contextual explanations, and validation checks to support accurate translation of the intended randomisation design.

The system includes a dedicated testing area using synthetic participants, allowing teams to run dry runs, review allocation behaviour, confirm reproducibility, and explore edge cases such as sparse strata or changing recruitment patterns. Outputs can be reviewed internally by the study statistician or sponsor as part of routine checks.

As this is a self-service system, responsibility for confirming that the implemented algorithm reflects the approved statistical design remains with the study team. Trial Deck can provide a technical fit for purpose statement confirming that the configuration matches the supplied specification.

For studies requiring complex or bespoke designs, we work directly with the statistician to implement custom randomisation approaches under a separate consultancy arrangement.
Service documentation
Yes
Documentation formats
  • HTML
  • Other
Other documentation formats
Jira service management portal
End-of-contract data extraction
Study teams can export all randomisation related data using a self service export capability in the S3R module. Exports include the randomisation specification, frozen seed values, allocation ratios, stratification factors, covariates and weights, block definitions, version history, and full audit trails. Where concealment rules permit, exports can include participant level allocations with timestamps, reveal status, and identification of any emergency or offline allocations. Exports are provided in open formats suitable for archiving and statistical review. Each export includes an integrity check, including a signed cryptographic hash, so buyers can verify that the exported package matches the source system at the point of export.
End-of-contract process
At contract end, customers retain access for an agreed exit period to complete exports and confirm receipt. The contract price includes access to self service exports, standard documentation, and support during the agreed offboarding window. Once export is complete, customer access is withdrawn. Randomisation data is then retained, archived, or securely destroyed in line with the agreed retention period and contractual arrangements. Optional services include extended access periods, managed export packs for inspection or statistical review, and long term archiving support.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Only the participant and supporter interface is mobile-first. Researcher's GUI is desktop first and tablet compatible.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Yes. The service is accessed through a secure, browser based web interface for researchers and study teams. The service also provides documented APIs to support system integrations and data exchange where required.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface has been tested against WCAG 2.2 AA criteria, including keyboard navigation, focus management, colour contrast, and screen reader compatibility. Testing has included use with common assistive technologies such as screen readers and browser accessibility tools. Accessibility issues identified are tracked and addressed as part of ongoing product development and quality assurance.
API
Yes
What users can and can't do using the API
Trial Deck S3R provides a documented REST API to support secure integration of randomisation and allocation workflows with external systems. API access is managed through a secure token based authentication mechanism and is subject to authorisation and rate limiting.

Authorised systems may:

Allocate participants using the S3R randomisation engine

Retrieve a participant’s allocation status

Reveal treatment allocation where protocol and role permissions allow

Trigger emergency or contingency allocation workflows where configured

Synchronise allocation outcomes with CTMS, EDC, pharmacy, or logistics systems

Support offline or deferred allocation recovery

All allocation and reveal actions performed via the API are fully audited, timestamped, and attributable, only where protocol and role permissions allow

The API does not permit:

Modification of randomisation configuration, strata, covariates, or weights

Alteration of seeds, allocation ratios, or concealment rules

Deletion or rewriting of allocation history or audit records

Bypassing role based permissions or protocol defined constraints

Randomisation design, configuration, testing, and governance controls are managed exclusively through the secure web interface to preserve statistical integrity, concealment, and regulatory compliance.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The S3R Randomisation Module supports both configurable randomisation design and optional bespoke statistical development.

Authorised users can configure randomisation schemes through the secure web interface, including:

- Randomisation method selection, including simple, block, stratified, and minimised approaches

- Definition of stratification factors and covariates, including weights and tie breaking rules

- Allocation ratios, block sizes, fixed or variable blocks, and concealment settings

- Emergency allocation and offline envelope generation

- Reproducibility controls including seed management and versioning

- Testing and dry run simulations using synthetic participants

Bespoke randomisation algorithms

Where study designs require novel or highly complex randomisation approaches, the S3R engine supports the integration of custom randomisation algorithms. In these cases, Trial Deck developers work directly with the customer’s statistician to design, implement, and validate study specific logic, including adaptive or hybrid approaches.

Bespoke algorithm development, validation, and documentation are provided at our hourly rate.

Standard configuration is performed through a secure, browser based interface without software development. Bespoke randomisation algorithms are developed, tested, and deployed by the supplier following documented change control, validation, and audit procedures.

Scaling

Independence of resources
Trial Deck is delivered using logically segregated environments with role based access controls and workload isolation where appropriate. System resources are monitored continuously, and capacity is scaled to ensure individual customer usage does not adversely affect the performance or availability experienced by other users. Where required, dedicated environments or resource allocations can be provided by agreement. All resource management is handled centrally and does not require customer intervention.

Analytics

Service usage metrics
Yes
Metrics types
Trial Deck provides service usage and operational metrics through a dedicated Matomo analytics instance. Metrics include platform usage, user activity, feature interaction, and session trends, with visibility segmented by user roles and user types. Metrics can be extended through additional Matomo modules or configuration where required, subject to agreement. All metrics are collected and reported in line with applicable data protection requirements, remain within the UK, and are not shared.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Study teams can export randomisation data using a self service export capability, providing complete randomisation records in open, commonly used formats. Exports include randomisation configuration, seed values, allocation ratios, stratification factors, covariates, block definitions, participant allocations, timestamps, version history, and full audit trails, supporting ALCOA++ principles.

Each export includes a signed cryptographic hash, enabling verification of export integrity against the source system and confirming that data has not been altered post export. Exports respect concealment and role based access rules. Emergency or offline allocations are clearly identified and fully traceable.
Data export formats
  • CSV
  • Other
Other data export formats
  • Excel
  • 2026: CDISC
  • 2026: SAS XPT
  • 2026: XML
  • PDF
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • PDF
  • 2026: CDISC ODM or SDTM
  • 2026: SAS XPT
  • 2026: XML

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Trial Deck is provided with a standard service level agreement included within the annual licence fee, which operates on a best efforts basis and does not include a guaranteed availability percentage. Service hours for the standard SLA are 9am to 5pm UK working days, with defined response and recovery targets.

An extended SLA is available at additional cost and includes a guaranteed availability target of 99.9% uptime, measured over a rolling 3-monthly period and excluding planned or emergency maintenance. Where availability under the extended SLA falls below the guaranteed level, service credits are applied in accordance with the agreed call off contract terms. All SLAs, including availability commitments and any associated service credits, are subject to the individual call off contract.
Approach to resilience
Trial Deck is designed to be resilient through a combination of platform controls, operational processes, and resilient third party infrastructure. The service is hosted on established cloud providers which operate resilient datacentre environments with redundant power, cooling, and network connectivity.

At platform level, the service uses monitored infrastructure, automated health checks, and regular backups to protect against data loss and service disruption. Backups are encrypted and stored separately to support recovery. Capacity is actively monitored and scaled to manage demand and reduce the risk of performance degradation caused by individual workloads.

Operational resilience is supported through defined incident management procedures, role based access controls, audit logging, and change management processes. Planned maintenance is carried out outside UK business hours where possible to minimise user impact.

Detailed information about underlying datacentre resilience, including physical controls and infrastructure redundancy, is managed by the hosting providers and can be made available on request.
Outage reporting
Service availability and incidents are communicated to customers through direct notifications. Service interruptions and significant incidents are reported by email to nominated customer contacts. A public status dashboard or outage reporting API is not provided as part of the standard service. Where required, a dedicated status dashboard can be provided as an optional, chargeable service. Outage updates and incident summaries may also be shared through the service management portal.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through role based access control and least privilege principles. Organisational user accounts are created and managed by the Trial Deck administrative team, following approval and verification. Administrative access is limited to authorised personnel only and protected using strong authentication, including multi factor authentication where appropriate. Access rights are granted on a need to know basis and reviewed regularly. All management actions and support access are logged and auditable. Support requests are handled through controlled channels, with identity verification performed before any action affecting customer data or service configuration.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
NHS DSPT
Cyber Essentials
Information security policies and processes
Global Initiative operates a documented information security management system aligned with ISO 27001, NHS DSPT, and Cyber Essentials requirements. Information security policies cover access control, data protection, incident management, supplier assurance, change control, and business continuity.

Responsibility for information security sits with senior management, with clear reporting lines to the Managing Director. Security incidents, risks, and compliance matters are logged, reviewed, and escalated in line with defined procedures. Policies are communicated to staff through onboarding, regular training, and ongoing awareness activities.

Compliance with policies is enforced through role based access controls, logging and monitoring, internal reviews, and periodic audits. Corrective actions are tracked to resolution. Third party suppliers are assessed and managed through due diligence and contractual controls to ensure alignment with security requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management for Trial Deck is controlled through documented processes operated in line with ISO 27001 and 9001 requirements.

Application code, configuration, and dependencies are tracked using version control and managed deployment pipelines. Changes are recorded, traceable, and auditable from development through release, with defined configuration baselines maintained across environments.

All changes are assessed prior to deployment for potential security, availability, and data protection impact. Higher risk changes require approval and testing before release. Changes are deployed in a controlled manner with rollback procedures where appropriate. Logs and audit records are retained to support accountability and continuous improvement.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management for Trial Deck follows documented processes aligned with ISO 27001 and ISO 9001.

Threats are assessed through automated monitoring, dependency review, penetration testing, and review of configuration and access controls. Vulnerabilities are prioritised based on risk to confidentiality, integrity, and availability.

Security patches are deployed through controlled change management. Critical updates are applied as soon as practicable, with lower risk updates scheduled weekly.

Threat intelligence is obtained from vendor advisories, cloud provider notifications, vulnerability databases, penetration testing reports, and relevant NCSC portal alerts.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Global Initiative operates layered server and service monitoring to support availability, performance, and security. Metrics and logs are collected centrally to provide visibility of system health, capacity, and behaviour. Monitoring dashboards and alerting are used to detect abnormal conditions and notify administrators.

Protective monitoring includes operating system level auditing using auditd to support intrusion detection and investigation, alongside application and service level monitoring. Hosting providers also supply infrastructure level monitoring and alerts. Monitoring data supports incident detection, forensic analysis, and recovery activities, and is reviewed regularly in line with documented incident management procedures.
Incident management type
Supplier-defined controls
Incident management approach
We follow a documented incident management process aligned with ISO 27001 and ISO 9001, with predefined playbooks for common events including service outages, security incidents, and data breaches.

Incidents are reported via the service desk, support email, or automated monitoring. The InfoSec team triages incidents based on risk, impact, urgency, and cost. Containment, investigation, forensic analysis, and recovery are completed before closure.

Incident reports are provided to buyers. We respond within one working day, with an RPO of 24 hours and an RTO of 8 working hours.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Trial Deck provides Simple Randomisation for free to all users (no API integrations or other services are included). This includes free trials of other services on Trial Deck.
Link to free trial
Contact us, please

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau / Amtivo
ISO/IEC 27001 accreditation date
Friday 11 July 2025
What the ISO/IEC 27001 doesn’t cover
Marketing websites, typically under £20,000+VAT

MVP products, typically under £30,000+VAT

Projects that are exclusively Design focused (QMS only)

SoA control A.14.2.7 Outsourced development (We do not outsource development)
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau / Amtivo
ISO 9001 accreditation date
Friday 11 July 2025
What the ISO 9001 doesn’t cover
British Assessment Bureau / Amtivo
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
NHS DSPT

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ideas@global-initiative.com. Tell them what format you need. It will help if you say what assistive technology you use.