Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Contact Us
  • Home

Security Changes in version 2023.1 of Castor Connect

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • CDMS
    Castor CDMS Manual Castor CDMS Calculations Manual Frequently Asked Questions Articles for Data Managers Castor CDMS Compliance Release Documents
  • eConsent
    Castor eConsent Manual Castor eConsent Compliance Release Documents
  • SMS
    Castor SMS Manual Castor SMS Compliance Release Documents
  • Castor Connect
    Castor Connect Compliance Release Documents Castor Connect Manual Castor Connect - Participant Quick Start Guide
  • Helpdesk
    News Other Resources Castor products knowledge resources
  • Status page
  • Completing a Study
+ More

What is changing in version 2023.1 of Castor Connect?

Participants must currently create and use a unique 4 digit PIN to access the Castor Connect app. As of version 2023.1 of Castor Connect, participants will be asked to create a 6 digit PIN and enable native security on their device to access the app. Native security will be the primary method for accessing the app, with the PIN as a back-up.
 

What is ‘native security’ in this context?

Native security, or device security, are the methods used by Android and iOS devices to ensure the security of a user’s data. For example, Apple commonly includes Face ID or Touch ID on their devices for biometric authentication via a face scan or fingerprint respectively. Touch ID or pattern recognition is more common on Android devices. These methods of authentication rely either on the user’s biometric data or on a code/pattern the user creates themselves.

 

Is this personal security information stored or sent anywhere?

No. At no point does the participant’s security data - their fingerprint, facial data, passcode or otherwise - leave their device in the authentication process. Castor does not and will not store a participant’s device security information in order to facilitate authentication in Castor Connect. The only security credential for participants using Castor Connect that is stored by Castor is their back-up PIN to access the app.

 

Why is security changing now?

Castor continues to strongly believe in the future of users participating on studies from the comfort of their own devices (Bring Your Own Device, or BYOD.) We also believe in doing so in a secure way that fits with what a participant would expect of a consumer-grade application. The longer PIN requirements expand on the benefits of the existing security method, and native security means we can leverage biometrics to make authentication even more secure.
 

Does this mean it wasn’t secure before?

No. From a user experience perspective, the new security flow, once enabled, will be very similar to the pre-existing method of accessing the app. Castor feels this is an important step to ensuring security in the future, as the nature of security threats to personal and mobile devices evolves over time.
 

How will this be made available to my study participants?

For newly activated participants (i.e., participants who are either activating Castor Connect for the first time, or are re-activating having switched to a new devices), when they successfully activate the app, they will be asked to enable native security and then provide a 6 digit personal PIN
 

For participants already using the Castor Connect app, when they install the latest version of the app - they will be prompted to submit any/all data currently stored locally and then enable the new security method. Guidance on ensuring the app is updated is available in the Castor Connect Participant User Guide available on request. Users will not currently be forced to update the app if they do not already have automatic updates turned on.
 

Practically speaking, what does this mean for my study participants?

When a participant opens the app, they will be able to log in using the native security method they have set up for their device. If they have touch/fingerprint access set up for their phone, that very same access will be usable for accessing Castor Connect.
 

What if native security fails?

If the participant cannot remember their passcode or another native security method has failed - they will be able to use the PIN they set up on activation to access the app.
 

What if the participant either does not have or does not enable native security on their device?

The vast majority of, if not all, supported iOS and Android devices actively encourage users to set up some form of native security for their own protection in general use.

If a participant elects to not set up, enable, or use native security, the 6 digit PIN will be available as a back-up or primary means of authentication and accessing the app. It is important to note that, when a participant uses their back-up PIN, this is checked by our system to ensure it is correct. This means that an online connection is always required to make use of the back-up PIN.

security update castor connect 2023.1

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Release notes Castor SMS januari 2019 - versie 2019.1
  • Search participants on specific data values in CDMS
  • Castor EDC 2023.x.x 21 CFR Part 11 Statement of Compliance
  • Export data formats in CDMS
  • Castor SMS 2022.x.x 21 CFR Part 11 Statement of Compliance
ISO 27001
FDA - 21 CFR part 11
ICH GCP compliant
HIPAA compliant
CDISC
ISO 9001
gdpr compliant

Products & Industries

  • Electronic Data Capture (EDC)
  • ePRO
  • eConsent
  • Decentralized Clinical Trials (DCT)
  • Clinical Data Management
  • Medical Device & Diagnostics
  • Biotech & Pharma
  • CROs
  • Academic Research

Resources

  • Thought Leadership
  • Blog
  • Castor Academy
  • Knowledge Base

 

Company

  • About Us
  • Careers
  • News
  • Contact Support
  • Contact Us

Legal & Compliance

  • Terms of Use
  • Privacy & Cookie Statement
  • Responsible Disclosure Policy
  • Good Clinical Practice (GCP)
  • ISO Compliance Certificates
  • GDPR & HIPAA Compliance
  • Security Statement

© 2022, Castor. All Rights Reserved.

Follow us on social media


Knowledge Base Software powered by Helpjuice

Definition by Author

0
0
Expand