Security audit
for REDCap
Your REDCap instance stores patient data and clinical research information. We verify it is protected, up to date, and compliant with current regulations.
Instances analysed in Spain
With high-risk findings
Compliance verification
ICH alignment
The problem nobody checks
Most REDCap instances in Spain are installed and forgotten. No updates, no configuration review, no security verification. Meanwhile, they store special-category data protected under GDPR.
Data exposure
Publicly accessible file directories, patient documents indexed by search engines.
Insecure configuration
Accessible installation pages, outdated versions with known vulnerabilities, missing security headers.
Regulatory non-compliance
No audit trail, indefinite retention policies, no formal validation for ICH E6(R3) or the Spanish National Security Framework (ENS).
Patient data exposed publicly
During a routine assessment, we found that a biomedical research institution had its REDCap instance's file directory accessible without authentication. Documents containing patient data were indexable by any search engine.
The centre was notified and the issue was fixed within 24 hours. Without a specialised audit, the exposure could have continued indefinitely.
Three levels of
protection
Basic Security Assessment
- External attack surface analysis
- Sensitive information exposure check
- Server security configuration assessment
- Best-practice compliance check
- Report with findings and recommendations
Delivery: 1-2 days
Request assessmentSecurity and Compliance Audit
- Everything in the previous level
- Access control and authentication assessment
- GDPR and ICH E6(R3) compliance analysis
- Data and retention policy review
- OWASP Top 10 vulnerability scan
- Executive + technical report + risk matrix
Delivery: 3-5 days
Request auditAudit + Remediation
- Everything in the previous level
- Fixes for all findings
- System hardening and updates
- Verification re-test
- Remediation certificate
Delivery: 1-2 weeks
Request a quoteAnnual security maintenance
Periodic audits, REDCap updates, threat monitoring, and priority incident support. Your instance always protected and up to date.
Why Tiviztech
REDCap specialists
We're not a generic cybersecurity firm. We know REDCap from the inside: its architecture, its common weak points, and its regulatory requirements.
Spanish ecosystem
We have analysed 42 REDCap instances across Spanish hospitals, medical societies and universities.
Regulatory compliance
We assess against GDPR, ICH E6(R3), the Spanish National Security Framework (ENS) and OWASP. We don't just find technical issues: we verify regulatory compliance.
Free initial assessment
We show you the most relevant findings for your instance with no obligation. You decide if you want to go further.
Request a free initial assessment
We analyse your REDCap instance and show you the main findings. No cost, no obligation.
Frequently asked questions
Why do I need a REDCap-specific audit?
REDCap stores health data protected under GDPR. Inadequate configuration can expose patient information, breach ICH E6(R3), and lead to penalties. A specialised audit detects vulnerabilities that a generic assessment does not cover.
How is this different from a generic pentest?
A generic pentest reviews standard web vulnerabilities. Our audit understands REDCap's internal architecture, its common weak points, and the regulatory requirements of the healthcare and clinical trials sector.
Is it remote or on-site?
The basic assessment and the full audit are carried out remotely. Only the remediation package may require on-site access, depending on the complexity of the infrastructure.
How long does it take?
The basic assessment is completed in 1-2 days. The full audit takes 3 to 5 days. The audit with remediation can extend to 1-2 weeks depending on the number of findings.