Skip to main content

Help us improve the Digital Marketplace - send your feedback

GLOBAL INITIATIVE LIMITED

Trial Deck - Electronic Data Capture

Trial Deck Electronic Data Capture is a cloud based system for designing, collecting, and managing structured clinical research data. It enables study teams to build electronic case report forms, apply validation logic, and capture participant data securely, supporting multi-site, decentralised studies, regulatory compliance, and audit ready data collection. Tailoring Available.

Features

  • Electronic case report form creation with configurable validation rules
  • Real-time data validation and consistency checks at point of entry
  • Full audit trails for all data creation, edits, and access
  • Role based access controls for secure data entry and review
  • Query management workflows for data clarification and resolution
  • Integration with wearable and IoT platforms through secure integrations/APIs
  • Data integrity controls aligned with ALCOA++ principles
  • Secure data storage with encryption in transit and at rest
  • Configurable inter- and intra-form logic
  • Self service exports for monitoring, review, and downstream analysis

Benefits

  • Reduce data entry errors through real time validation
  • Accelerate database lock with structured query management workflows
  • Improve inspection readiness with complete, searchable audit trails
  • Ensure data integrity aligned with ALCOA++ principles
  • Streamline multi-site data collection using consistent electronic forms
  • Enable faster issue resolution through controlled data clarification queries
  • Maintain secure access using role based permissions
  • Support decentralised data capture without compromising governance
  • Export clean datasets quickly for analysis and reporting
  • Demonstrate inspection readiness through complete, traceable, auditable study datasets

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ideas@global-initiative.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 9 1 8 9 5 2 0 7 6 4 6 1 6 9

Contact

GLOBAL INITIATIVE LIMITED Chris Sinclair
Telephone: 01865 203100
Email: ideas@global-initiative.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service requires an internet connection and a modern web browser. Planned maintenance is carried out at scheduled intervals and outside of UK working hours where possible. Support is provided during UK business hours. SMS and email notifications are subject to third party delivery services and additional fees may apply.
System requirements
  • Does not require local software installation.
  • Current versions of Chrome, Edge, Firefox and Safari.
  • An internet connection is required.
  • No additional software licences, plugins or buyer managed infrastructure required.

User support

Email or online ticketing support
Yes
Support response times
Standard SLA included. Extended SLA available at additional cost
Ticketing: Triage is complete and initial response within 2 working days.
Although not defined as such, our team usually responds to questions within 1 working day.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
All SLAs apply during UK working hours only, Monday to Friday, 9am to 5pm, excluding UK public holidays. All SLAs are subject to the Call Off Contract. Planned & emergency maintenance outside business hours where possible. Maintenance, third party services, including SMS, email delivery, and external integrations, are excluded from availability guarantees. Delivery Manager assigned to each account.

Standard SLA (included)

The Standard SLA is included within the annual licence fee and is suitable for most academic and public sector research studies.
- Incident response time: within 2 working days
- Target time to recovery: within 2 working days
- Availability: best efforts

The supplier will use reasonable best efforts to restore service availability, taking account of issue severity and impact.

Extended SLA (optional)

An Extended SLA is available for an additional £10,000+VAT per annum, providing enhanced service commitments.
- Incident response time: same working day
- Target time to recovery: 1 working day
- Availability commitment: 99.9 percent uptime measured over rolling three month periods
- Exclusions: customer induced downtime, third party services, and force majeure events
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Trial Deck provides structured onboarding to help users start using the service quickly and effectively. Online training sessions are provided for new researchers and study teams, supported by comprehensive online documentation and guidance materials. A service management portal is available for support requests and service coordination. Each customer is assigned a dedicated delivery manager to oversee onboarding and early study setup. Additional support for protocol validation, testing, and study configuration can be provided as an optional, chargeable service.
Service documentation
Yes
Documentation formats
  • HTML
  • Other
Other documentation formats
Jira service management portal
End-of-contract data extraction
Users can extract their data using a self service export capability that provides comprehensive study data exports in open, commonly used formats. Exports preserve data provenance, timestamps, audit history, and versioning to support ALCOA++ principles, and include data integrity checks for study datasets. Where required, Global Initiative can provide tailored end of study standard operating procedures covering data archiving, retention, and secure data destruction as an optional service.
End-of-contract process
At the end of the contract, customers retain access to Trial Deck for an agreed exit period to complete data exports. The contract price includes use of the self service data export functionality, access to standard documentation, and support during the agreed offboarding period. Following successful data extraction, customer access to the service is withdrawn and study data is securely deleted or archived in line with agreed retention policies.

Where appropriate and subject to participant consent, participants may remain registered on the platform for use in future studies delivered by the same customer. Participant records are logically separated from study datasets and remain under strict access controls, with reuse governed by consent, protocol, and applicable data protection requirements.

Optional services, available at additional cost, include extended access periods, bespoke data exports, long term data archiving, tailored end of study standard operating procedures, and managed support for validation, testing, or regulatory aligned offboarding activities.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Only the participant and supporter interface is mobile-first. Researcher's GUI is desktop first and tablet compatible.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Yes. The service is accessed through a secure, browser based web interface for researchers and study teams. The service also provides documented APIs to support system integrations and data exchange where required.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface has been tested against WCAG 2.2 AA criteria, including keyboard navigation, focus management, colour contrast, and screen reader compatibility. Testing has included use with common assistive technologies such as screen readers and browser accessibility tools. Accessibility issues identified are tracked and addressed as part of ongoing product development and quality assurance.
API
Yes
What users can and can't do using the API
The service provides a documented REST API that allows authorised users to integrate Trial Deck EDC with external systems and automate limited aspects of data exchange. API access is managed through a secure token management interface.

The API currently exposes four core endpoints focused on participant context data:

GET all participants and their context variables

GET all context variables for a single participant, identified by UUID

SET a single context variable for all participants

SET a single context variable for an individual participant, identified by UUID

Using the API, users can support automated data exchange, synchronise participant state, and integrate Trial Deck with third party systems such as laboratories, logistics providers, wearables, and other external data sources relevant to data capture.

The service is designed to interface with third party APIs, and the supplier has extensive experience implementing secure integrations with external operational and research systems.

Limitations

The API does not provide full administrative control of the platform. Study configuration, user management, CRF design, validation rules, and workflow definition are managed through the web interface. API access is subject to authentication, authorisation, and rate limiting, and is intended for controlled integration and data synchronisation rather than full platform management.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The purpose of the service is to enable needs led, protocol driven data capture by allowing study teams to configure electronic data collection without software development. This can be augmented by the rest of Trial Deck's features.

What can be customised?

Users can configure electronic case report forms and datasets tailored to study protocols. Customisation includes CRF structure, field types, validation rules, inter form and intra form logic, mandatory fields, visit schedules, notifications, reporting exports, and role based access permissions. Data capture behaviour can be tailored by site, cohort, or visit, supporting multi site and decentralised studies.

How users can customise?

Customisation is carried out through a secure, browser based configuration interface. Authorised users can design and modify CRFs, define validation and conditional logic, and manage form visibility without writing code. Limited configuration to support integrations can be applied through the API where required.

Who can customise?

Customisation is performed by authorised study team members, including trial managers, data managers, statisticians, and administrators. Role based access controls ensure only approved users can make changes. The supplier can support initial setup and complex configurations as part of onboarding or optional support services.

Scaling

Independence of resources
Trial Deck is delivered using logically segregated environments with role based access controls and workload isolation where appropriate. System resources are monitored continuously, and capacity is scaled to ensure individual customer usage does not adversely affect the performance or availability experienced by other users. Where required, dedicated environments or resource allocations can be provided by agreement. All resource management is handled centrally and does not require customer intervention.

Analytics

Service usage metrics
Yes
Metrics types
Trial Deck provides service usage and operational metrics through a dedicated Matomo analytics instance. Metrics include platform usage, user activity, feature interaction, and session trends, with visibility segmented by user roles and user types. Metrics can be extended through additional Matomo modules or configuration where required, subject to agreement. All metrics are collected and reported in line with applicable data protection requirements, remain within the UK, and are not shared.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Study teams can export data using a self service export capability that provides comprehensive study datasets in open, commonly used formats. Exports include audit history, timestamps, and data provenance to support ALCOA++ principles, with data integrity checks.

Participants can request access to their personal data through the platform in line with data protection requirements. Subject Access Requests are supported through a semi automated process, with verification, review, and secure delivery of participant data handled by the service team. This ensures participant rights are respected while maintaining data security and study integrity.
Data export formats
  • CSV
  • Other
Other data export formats
  • Excel
  • 2026: CDISC
  • 2026: SAS XPT
  • 2026: XML
  • PDF
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • PDF
  • 2026: CDISC ODM or SDTM
  • 2026: SAS XPT
  • 2026: XML

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Trial Deck is provided with a standard service level agreement included within the annual licence fee, which operates on a best efforts basis and does not include a guaranteed availability percentage. Service hours for the standard SLA are 9am to 5pm UK working days, with defined response and recovery targets.

An extended SLA is available at additional cost and includes a guaranteed availability target of 99.9% uptime, measured over a rolling 3-monthly period and excluding planned or emergency maintenance. All SLAs, including availability commitments and any associated service credits, are subject to the individual call off contract.
Approach to resilience
Trial Deck is designed to be resilient through a combination of platform controls, operational processes, and resilient third party infrastructure. The service is hosted on established cloud providers which operate resilient datacentre environments with redundant power, cooling, and network connectivity.

At platform level, the service uses monitored infrastructure, automated health checks, and regular backups to protect against data loss and service disruption. Backups are encrypted and stored separately to support recovery. Capacity is actively monitored and scaled to manage demand and reduce the risk of performance degradation caused by individual workloads.

Operational resilience is supported through defined incident management procedures, role based access controls, audit logging, and change management processes. Planned maintenance is carried out outside UK business hours where possible to minimise user impact.

Detailed information about underlying datacentre resilience, including physical controls and infrastructure redundancy, is managed by the hosting providers and can be made available on request.
Outage reporting
Service availability and incidents are communicated to customers through direct notifications. Service interruptions and significant incidents are reported by email to nominated customer contacts. A public status dashboard or outage reporting API is not provided as part of the standard service. Where required, a dedicated status dashboard can be provided as an optional, chargeable service. Outage updates and incident summaries may also be shared through the service management portal.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through role based access control and least privilege principles. Organisational user accounts are created and managed by the Trial Deck administrative team, following approval and verification. Administrative access is limited to authorised personnel only and protected using strong authentication, including multi factor authentication where appropriate. Access rights are granted on a need to know basis and reviewed regularly. All management actions and support access are logged and auditable. Support requests are handled through controlled channels, with identity verification performed before any action affecting customer data or service configuration.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
NHS DSPT
Cyber Essentials
Information security policies and processes
Global Initiative operates a documented information security management system aligned with ISO 27001, NHS DSPT, and Cyber Essentials requirements. Information security policies cover access control, data protection, incident management, supplier assurance, change control, and business continuity.

Responsibility for information security sits with senior management, with clear reporting lines to the Managing Director. Security incidents, risks, and compliance matters are logged, reviewed, and escalated in line with defined procedures. Policies are communicated to staff through onboarding, regular training, and ongoing awareness activities.

Compliance with policies is enforced through role based access controls, logging and monitoring, internal reviews, and periodic audits. Corrective actions are tracked to resolution. Third party suppliers are assessed and managed through due diligence and contractual controls to ensure alignment with security requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management for Trial Deck is controlled through documented processes operated in line with ISO 27001 and 9001 requirements.

Application code, configuration, and dependencies are tracked using version control and managed deployment pipelines. Changes are recorded, traceable, and auditable from development through release, with defined configuration baselines maintained across environments.

All changes are assessed prior to deployment for potential security, availability, and data protection impact. Higher risk changes require approval and testing before release. Changes are deployed in a controlled manner with rollback procedures where appropriate. Logs and audit records are retained to support accountability and continuous improvement.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management for Trial Deck follows documented processes aligned with ISO 27001 and ISO 9001.

Threats are assessed through automated monitoring, dependency review, penetration testing, and review of configuration and access controls. Vulnerabilities are prioritised based on risk to confidentiality, integrity, and availability.

Security patches are deployed through controlled change management. Critical updates are applied as soon as practicable, with lower risk updates scheduled weekly.

Threat intelligence is obtained from vendor advisories, cloud provider notifications, vulnerability databases, penetration testing reports, and relevant NCSC portal alerts.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Global Initiative operates layered server and service monitoring to support availability, performance, and security. Metrics and logs are collected centrally to provide visibility of system health, capacity, and behaviour. Monitoring dashboards and alerting are used to detect abnormal conditions and notify administrators.

Protective monitoring includes operating system level auditing using auditd to support intrusion detection and investigation, alongside application and service level monitoring. Hosting providers also supply infrastructure level monitoring and alerts. Monitoring data supports incident detection, forensic analysis, and recovery activities, and is reviewed regularly in line with documented incident management procedures.
Incident management type
Supplier-defined controls
Incident management approach
We follow a documented incident management process aligned with ISO 27001 and ISO 9001, with predefined playbooks for common events including service outages, security incidents, and data breaches.

Incidents are reported via the service desk, support email, or automated monitoring. The InfoSec team triages incidents based on risk, impact, urgency, and cost. Containment, investigation, forensic analysis, and recovery are completed before closure.

Incident reports are provided to buyers. Our typical response time is within 1 working day, but the contractual commitment is within 2 working days under the Standard SLA, with an RPO of 24 hours.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Trial Deck provides a self service evaluation version with basic training, supporting up to 50 participants for six months. It excludes audit trail search, SAE workflows, custom roles, localisation, referrals, SMS, randomisation customisation, cloud storage links, API access, and notification centre features. Any customisations and SLAs are not included.
Link to free trial
Contact us, please

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau / Amtivo
ISO/IEC 27001 accreditation date
Friday 11 July 2025
What the ISO/IEC 27001 doesn’t cover
Marketing websites, typically under £20,000+VAT

MVP products, typically under £30,000+VAT

Projects that are exclusively Design focused (QMS only)

SoA control A.14.2.7 Outsourced development (We do not outsource development)
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau / Amtivo
ISO 9001 accreditation date
Friday 11 July 2025
What the ISO 9001 doesn’t cover
British Assessment Bureau / Amtivo
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
NHS DSPT

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ideas@global-initiative.com. Tell them what format you need. It will help if you say what assistive technology you use.