Trial Deck - Electronic Data Capture
Trial Deck Electronic Data Capture is a cloud based system for designing, collecting, and managing structured clinical research data. It enables study teams to build electronic case report forms, apply validation logic, and capture participant data securely, supporting multi-site, decentralised studies, regulatory compliance, and audit ready data collection. Tailoring Available.
Features
- Electronic case report form creation with configurable validation rules
- Real-time data validation and consistency checks at point of entry
- Full audit trails for all data creation, edits, and access
- Role based access controls for secure data entry and review
- Query management workflows for data clarification and resolution
- Integration with wearable and IoT platforms through secure integrations/APIs
- Data integrity controls aligned with ALCOA++ principles
- Secure data storage with encryption in transit and at rest
- Configurable inter- and intra-form logic
- Self service exports for monitoring, review, and downstream analysis
Benefits
- Reduce data entry errors through real time validation
- Accelerate database lock with structured query management workflows
- Improve inspection readiness with complete, searchable audit trails
- Ensure data integrity aligned with ALCOA++ principles
- Streamline multi-site data collection using consistent electronic forms
- Enable faster issue resolution through controlled data clarification queries
- Maintain secure access using role based permissions
- Support decentralised data capture without compromising governance
- Export clean datasets quickly for analysis and reporting
- Demonstrate inspection readiness through complete, traceable, auditable study datasets
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 9 1 8 9 5 2 0 7 6 4 6 1 6 9
Contact
GLOBAL INITIATIVE LIMITED
Chris Sinclair
Telephone: 01865 203100
Email: ideas@global-initiative.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires an internet connection and a modern web browser. Planned maintenance is carried out at scheduled intervals and outside of UK working hours where possible. Support is provided during UK business hours. SMS and email notifications are subject to third party delivery services and additional fees may apply.
- System requirements
-
- Does not require local software installation.
- Current versions of Chrome, Edge, Firefox and Safari.
- An internet connection is required.
- No additional software licences, plugins or buyer managed infrastructure required.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Standard SLA included. Extended SLA available at additional cost
Ticketing: Triage is complete and initial response within 2 working days.
Although not defined as such, our team usually responds to questions within 1 working day. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
All SLAs apply during UK working hours only, Monday to Friday, 9am to 5pm, excluding UK public holidays. All SLAs are subject to the Call Off Contract. Planned & emergency maintenance outside business hours where possible. Maintenance, third party services, including SMS, email delivery, and external integrations, are excluded from availability guarantees. Delivery Manager assigned to each account.
Standard SLA (included)
The Standard SLA is included within the annual licence fee and is suitable for most academic and public sector research studies.
- Incident response time: within 2 working days
- Target time to recovery: within 2 working days
- Availability: best efforts
The supplier will use reasonable best efforts to restore service availability, taking account of issue severity and impact.
Extended SLA (optional)
An Extended SLA is available for an additional £10,000+VAT per annum, providing enhanced service commitments.
- Incident response time: same working day
- Target time to recovery: 1 working day
- Availability commitment: 99.9 percent uptime measured over rolling three month periods
- Exclusions: customer induced downtime, third party services, and force majeure events - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Trial Deck provides structured onboarding to help users start using the service quickly and effectively. Online training sessions are provided for new researchers and study teams, supported by comprehensive online documentation and guidance materials. A service management portal is available for support requests and service coordination. Each customer is assigned a dedicated delivery manager to oversee onboarding and early study setup. Additional support for protocol validation, testing, and study configuration can be provided as an optional, chargeable service.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Jira service management portal
- End-of-contract data extraction
- Users can extract their data using a self service export capability that provides comprehensive study data exports in open, commonly used formats. Exports preserve data provenance, timestamps, audit history, and versioning to support ALCOA++ principles, and include data integrity checks for study datasets. Where required, Global Initiative can provide tailored end of study standard operating procedures covering data archiving, retention, and secure data destruction as an optional service.
- End-of-contract process
-
At the end of the contract, customers retain access to Trial Deck for an agreed exit period to complete data exports. The contract price includes use of the self service data export functionality, access to standard documentation, and support during the agreed offboarding period. Following successful data extraction, customer access to the service is withdrawn and study data is securely deleted or archived in line with agreed retention policies.
Where appropriate and subject to participant consent, participants may remain registered on the platform for use in future studies delivered by the same customer. Participant records are logically separated from study datasets and remain under strict access controls, with reuse governed by consent, protocol, and applicable data protection requirements.
Optional services, available at additional cost, include extended access periods, bespoke data exports, long term data archiving, tailored end of study standard operating procedures, and managed support for validation, testing, or regulatory aligned offboarding activities. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Only the participant and supporter interface is mobile-first. Researcher's GUI is desktop first and tablet compatible.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Yes. The service is accessed through a secure, browser based web interface for researchers and study teams. The service also provides documented APIs to support system integrations and data exchange where required.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface has been tested against WCAG 2.2 AA criteria, including keyboard navigation, focus management, colour contrast, and screen reader compatibility. Testing has included use with common assistive technologies such as screen readers and browser accessibility tools. Accessibility issues identified are tracked and addressed as part of ongoing product development and quality assurance.
- API
- Yes
- What users can and can't do using the API
-
The service provides a documented REST API that allows authorised users to integrate Trial Deck EDC with external systems and automate limited aspects of data exchange. API access is managed through a secure token management interface.
The API currently exposes four core endpoints focused on participant context data:
GET all participants and their context variables
GET all context variables for a single participant, identified by UUID
SET a single context variable for all participants
SET a single context variable for an individual participant, identified by UUID
Using the API, users can support automated data exchange, synchronise participant state, and integrate Trial Deck with third party systems such as laboratories, logistics providers, wearables, and other external data sources relevant to data capture.
The service is designed to interface with third party APIs, and the supplier has extensive experience implementing secure integrations with external operational and research systems.
Limitations
The API does not provide full administrative control of the platform. Study configuration, user management, CRF design, validation rules, and workflow definition are managed through the web interface. API access is subject to authentication, authorisation, and rate limiting, and is intended for controlled integration and data synchronisation rather than full platform management. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The purpose of the service is to enable needs led, protocol driven data capture by allowing study teams to configure electronic data collection without software development. This can be augmented by the rest of Trial Deck's features.
What can be customised?
Users can configure electronic case report forms and datasets tailored to study protocols. Customisation includes CRF structure, field types, validation rules, inter form and intra form logic, mandatory fields, visit schedules, notifications, reporting exports, and role based access permissions. Data capture behaviour can be tailored by site, cohort, or visit, supporting multi site and decentralised studies.
How users can customise?
Customisation is carried out through a secure, browser based configuration interface. Authorised users can design and modify CRFs, define validation and conditional logic, and manage form visibility without writing code. Limited configuration to support integrations can be applied through the API where required.
Who can customise?
Customisation is performed by authorised study team members, including trial managers, data managers, statisticians, and administrators. Role based access controls ensure only approved users can make changes. The supplier can support initial setup and complex configurations as part of onboarding or optional support services.
Scaling
- Independence of resources
- Trial Deck is delivered using logically segregated environments with role based access controls and workload isolation where appropriate. System resources are monitored continuously, and capacity is scaled to ensure individual customer usage does not adversely affect the performance or availability experienced by other users. Where required, dedicated environments or resource allocations can be provided by agreement. All resource management is handled centrally and does not require customer intervention.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Trial Deck provides service usage and operational metrics through a dedicated Matomo analytics instance. Metrics include platform usage, user activity, feature interaction, and session trends, with visibility segmented by user roles and user types. Metrics can be extended through additional Matomo modules or configuration where required, subject to agreement. All metrics are collected and reported in line with applicable data protection requirements, remain within the UK, and are not shared.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Study teams can export data using a self service export capability that provides comprehensive study datasets in open, commonly used formats. Exports include audit history, timestamps, and data provenance to support ALCOA++ principles, with data integrity checks.
Participants can request access to their personal data through the platform in line with data protection requirements. Subject Access Requests are supported through a semi automated process, with verification, review, and secure delivery of participant data handled by the service team. This ensures participant rights are respected while maintaining data security and study integrity. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- 2026: CDISC
- 2026: SAS XPT
- 2026: XML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- 2026: CDISC ODM or SDTM
- 2026: SAS XPT
- 2026: XML
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Trial Deck is provided with a standard service level agreement included within the annual licence fee, which operates on a best efforts basis and does not include a guaranteed availability percentage. Service hours for the standard SLA are 9am to 5pm UK working days, with defined response and recovery targets.
An extended SLA is available at additional cost and includes a guaranteed availability target of 99.9% uptime, measured over a rolling 3-monthly period and excluding planned or emergency maintenance. All SLAs, including availability commitments and any associated service credits, are subject to the individual call off contract. - Approach to resilience
-
Trial Deck is designed to be resilient through a combination of platform controls, operational processes, and resilient third party infrastructure. The service is hosted on established cloud providers which operate resilient datacentre environments with redundant power, cooling, and network connectivity.
At platform level, the service uses monitored infrastructure, automated health checks, and regular backups to protect against data loss and service disruption. Backups are encrypted and stored separately to support recovery. Capacity is actively monitored and scaled to manage demand and reduce the risk of performance degradation caused by individual workloads.
Operational resilience is supported through defined incident management procedures, role based access controls, audit logging, and change management processes. Planned maintenance is carried out outside UK business hours where possible to minimise user impact.
Detailed information about underlying datacentre resilience, including physical controls and infrastructure redundancy, is managed by the hosting providers and can be made available on request. - Outage reporting
- Service availability and incidents are communicated to customers through direct notifications. Service interruptions and significant incidents are reported by email to nominated customer contacts. A public status dashboard or outage reporting API is not provided as part of the standard service. Where required, a dedicated status dashboard can be provided as an optional, chargeable service. Outage updates and incident summaries may also be shared through the service management portal.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through role based access control and least privilege principles. Organisational user accounts are created and managed by the Trial Deck administrative team, following approval and verification. Administrative access is limited to authorised personnel only and protected using strong authentication, including multi factor authentication where appropriate. Access rights are granted on a need to know basis and reviewed regularly. All management actions and support access are logged and auditable. Support requests are handled through controlled channels, with identity verification performed before any action affecting customer data or service configuration.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
NHS DSPT
Cyber Essentials - Information security policies and processes
-
Global Initiative operates a documented information security management system aligned with ISO 27001, NHS DSPT, and Cyber Essentials requirements. Information security policies cover access control, data protection, incident management, supplier assurance, change control, and business continuity.
Responsibility for information security sits with senior management, with clear reporting lines to the Managing Director. Security incidents, risks, and compliance matters are logged, reviewed, and escalated in line with defined procedures. Policies are communicated to staff through onboarding, regular training, and ongoing awareness activities.
Compliance with policies is enforced through role based access controls, logging and monitoring, internal reviews, and periodic audits. Corrective actions are tracked to resolution. Third party suppliers are assessed and managed through due diligence and contractual controls to ensure alignment with security requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration and change management for Trial Deck is controlled through documented processes operated in line with ISO 27001 and 9001 requirements.
Application code, configuration, and dependencies are tracked using version control and managed deployment pipelines. Changes are recorded, traceable, and auditable from development through release, with defined configuration baselines maintained across environments.
All changes are assessed prior to deployment for potential security, availability, and data protection impact. Higher risk changes require approval and testing before release. Changes are deployed in a controlled manner with rollback procedures where appropriate. Logs and audit records are retained to support accountability and continuous improvement. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability management for Trial Deck follows documented processes aligned with ISO 27001 and ISO 9001.
Threats are assessed through automated monitoring, dependency review, penetration testing, and review of configuration and access controls. Vulnerabilities are prioritised based on risk to confidentiality, integrity, and availability.
Security patches are deployed through controlled change management. Critical updates are applied as soon as practicable, with lower risk updates scheduled weekly.
Threat intelligence is obtained from vendor advisories, cloud provider notifications, vulnerability databases, penetration testing reports, and relevant NCSC portal alerts. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Global Initiative operates layered server and service monitoring to support availability, performance, and security. Metrics and logs are collected centrally to provide visibility of system health, capacity, and behaviour. Monitoring dashboards and alerting are used to detect abnormal conditions and notify administrators.
Protective monitoring includes operating system level auditing using auditd to support intrusion detection and investigation, alongside application and service level monitoring. Hosting providers also supply infrastructure level monitoring and alerts. Monitoring data supports incident detection, forensic analysis, and recovery activities, and is reviewed regularly in line with documented incident management procedures. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a documented incident management process aligned with ISO 27001 and ISO 9001, with predefined playbooks for common events including service outages, security incidents, and data breaches.
Incidents are reported via the service desk, support email, or automated monitoring. The InfoSec team triages incidents based on risk, impact, urgency, and cost. Containment, investigation, forensic analysis, and recovery are completed before closure.
Incident reports are provided to buyers. Our typical response time is within 1 working day, but the contractual commitment is within 2 working days under the Standard SLA, with an RPO of 24 hours. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Trial Deck provides a self service evaluation version with basic training, supporting up to 50 participants for six months. It excludes audit trail search, SAE workflows, custom roles, localisation, referrals, SMS, randomisation customisation, cloud storage links, API access, and notification centre features. Any customisations and SLAs are not included.
- Link to free trial
- Contact us, please
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau / Amtivo
- ISO/IEC 27001 accreditation date
- Friday 11 July 2025
- What the ISO/IEC 27001 doesn’t cover
-
Marketing websites, typically under £20,000+VAT
MVP products, typically under £30,000+VAT
Projects that are exclusively Design focused (QMS only)
SoA control A.14.2.7 Outsourced development (We do not outsource development) - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau / Amtivo
- ISO 9001 accreditation date
- Friday 11 July 2025
- What the ISO 9001 doesn’t cover
- British Assessment Bureau / Amtivo
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- NHS DSPT
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-