Castor is committed to protecting your clinical research data with industry-leading security, data residency, and disaster recovery standards. All customer data is hosted in dedicated, fully managed virtual private environments hosted on Microsoft Azure.
Castor applications and databases run on security-hardened virtual private servers operated on Microsoft Azure.
Geographic Data Residency
To comply with local regulations and data sovereignty requirements (such as GDPR, HIPAA, and the Australian Privacy Act), studies are hosted in distinct regional environments. Data remains stored within the region chosen for your study or organization:
- European Union (EU) — Netherlands / Ireland
- United States (US)
- United Kingdom (UK)
- Australia (AU)
- Dedicated / Private Clusters (available for enterprise deployments)
Note: Data is never transferred outside of your designated hosting region without explicit agreement.
Backup Schedules & Disaster Recovery
To safeguard against data loss, Castor maintains automated, multi-tiered backup procedures:
- Frequency: Automated database backups are generated at least twice per day.
- Geographic Redundancy: Backup files are encrypted and replicated daily to a separate, physically distinct geographic data center within the same geopolitical jurisdiction to ensure business continuity and disaster recovery.
-
Retention Schedule:
- Daily backups: Retained for 28 days.
- Monthly backups: Retained for 1 year.
- Database Isolation: Production databases are isolated behind network firewalls and security groups, with no direct public internet exposure.
User-Controlled Data Backups
In addition to automated system backups, authorized study users can export their study data (in CSV, Excel, SPSS, or XML formats) and CRF structures at any time for local archiving. Learn more in our guide on How to export data.
Data Encryption Standards
All data processed within Castor is encrypted at multiple layers:
- Data in Transit: All network traffic to and from Castor applications requires modern, industry-standard encryption over TLS 1.2 or higher.
- Data at Rest: Data is encrypted at rest on underlying storage systems using AES-256 encryption.
- Application-Level Field Encryption: For studies collecting sensitive or personally identifiable information (PII), Castor provides an optional Field Encryption Module utilizing libsodium ciphers (XSalsa20/XChaCha20 with Poly1305 MAC) with keys managed independently.
Certifications & Regulatory Compliance
Both Castor and its cloud infrastructure meet the highest international security, quality, and clinical trial standards:
-
Castor Quality & Security Certifications:
- ISO 27001 (Information Security Management)
- ISO 9001 (Quality Management Systems)
-
Clinical & Regulatory Compliance:
- ICH-GCP (E6 R2) compliance and audit trail integrity
- FDA 21 CFR Part 11 and EU Annex 11 computerized system compliance
- GDPR (General Data Protection Regulation) and HIPAA compliant
- NEN 7510 (Health Information Security)
-
Hosting Infrastructure (Microsoft Azure) Standards:
- SOC 1, SOC 2, and SOC 3
- HITRUST CSF
- PCI-DSS Level 1
Further Information & Compliance Requests
- For full technical and organizational security measures, please consult our Helpdesk: Security Statement.
- To learn more about backup restoration policies and self-service exports, see Helpdesk: Is there a data back-up in Castor CDMS?.
- If your institution or sponsor requires Castor’s ISO certificates, third-party audit summaries, or completion of vendor security questionnaires, please contact our support team at support@castoredc.com.