Vigía: Product description
The AI operating system for clinical trial sites, by Perpetua AI
Revised October 10, 2026.
What Vigía is
Vigía is one system that runs a clinical research site: scheduling, source data, the regulatory binder, consent, investigational product, safety, and money, all in a single record. It checks every act against the protocol at the moment someone performs it, so a deviation can be caught before it happens, and one that already happened is recorded and routed the same day instead of at monitoring.
It replaces the stack independent sites usually juggle: a CTMS, paper or electronic source worksheets, an eReg binder, an eConsent tool, spreadsheets for IP accountability, and a separate billing process. Vigía was built first for a multi-protocol independent site (CMRC, San Juan, Puerto Rico) and is multi-tenant ready. It is made by Perpetua AI.
The problem it removes is simple to state. A site's work is a long chain of small acts, each governed by a protocol, a delegation log, a training record, a consent version, and a rule from a regulation. Every link depends on someone remembering. Vigía does the remembering, shows its source for every rule, and leaves a person in charge of every decision.
The core idea: one record, three principles
Everything in Vigía reads from and writes to one site record. A participant, a visit, a dose, a lab value, an invoice line and an audit entry are all parts of the same object, so no screen can disagree with another. Business logic lives once, in a shared core; the server and the web client both call it, so the demo runs the same rules a live site does.
Three principles organize the product.
- Catch the error at the point of care. The Quality Guardian evaluates each act against 51 rules, every one with a citation. It blocks the act, never the record: if a gated step already happened, Vigía records it with a reason and routes a deviation to the PI.
- Type it once. Values the system already knows (central-lab results, device files, stable answers from earlier visits, a reading of a worksheet photo or a dictation) fill the form with their source attached. A person confirms each one before it is saved.
- Every number traces to a record. Any figure on any screen opens the records it counts. Money, enrollment forecasts, quality rates and risk scores are computed from the site's own data and say so when there is not enough of it.
A fourth habit runs through all three. Autopilot never sends anything on its own: it prepares work (an invoice, a query answer, an SAE draft), and a named person approves each item.
Who uses it: eleven roles, each with its own view
Vigía has eleven roles. Each sees a different projection of the same record, with the minimum necessary data. Clinical staff are scoped by the delegation log: a study is in their view once the PI has initialed their line for it. Monitors are scoped to the studies they are assigned to, and inspectors to named studies until a set last day; neither can see that other studies exist.
| Role | What their day looks like |
|---|---|
| Coordinator (CRC) | Today shows pre-flight holds for today's and tomorrow's visits, then the visit workspace: a step rail in protocol order, plausibility feedback as numbers are typed, "Fill from a source," and the close checklist. |
| Principal investigator | A tablet sign-off queue ranked ready, review or held: visits, lab reviews and eligibility checklists, with what changed since last opened. One re-authentication signs a batch. Also stopping-rule decisions, SAE awareness, deviations and amendments. |
| Sub-investigator | Same conduct and sign-off tools, within the tasks the PI delegated. |
| Pharmacist | Dispensing against the assigned kit, kit and IRT gates, storage locations with daily temperature readings, and excursions that quarantine kits. The role is limited to investigational product work: only steps they are delegated for, no screen failures, withdrawals or concomitant medications, and no direct identifiers. |
| Finance | The money workspace: unbilled work, invoice drafts, remittances, short-pays. Finance sees no clinical values, only what billing needs. |
| Regulatory | The binder status board by document type (current, expiring, needs signature, missing), IRB renewals, amendments due, and per-person credentials. |
| Recruiter | A pre-screening pipeline from new lead to randomized, with per-source return. No clinical content. Identifiers can be revealed only for participants still in screening. |
| Site director | Everything above in aggregate: portfolio board, next actions per study, access review, site settings, the switch-over import, and the connections to outside systems. Directors do not conduct or sign visits. |
| Monitor | Study-scoped, read-only record view with source-data verification and per-field queries. |
| Auditor | Read-only, site-wide view of the record and the audit trail, with export. |
| Inspector (sponsor auditor or regulator) | Read-only access to the named studies and their audit trail, with export, until the last day of access. |
Protocol intake: from a document to a study build
The Protocol compiler turns a protocol into a working study before the CTA is signed. It accepts pasted text, .txt, .md and .docx through a rules parser, and PDFs through the model. The output is a complete build:
- the visit schedule with study days and windows
- procedures and timepoints, including post-dose steps
- eligibility criteria as a checklist
- prohibited medication classes
- stopping rules and washout rules
- a budget map linking billable procedures to CTA lines
- a check for problems that will cause trouble later: overlapping windows, unpriced visits
On the bundled sample protocol (BRW-230 CLEARSKIN-PN, Brightwater Biologics, Phase 3, prurigo nodularis) the compiler produces 9 visits (SCR, BL, W2, W4, W8, W12, W16, W24, FU) and 16 procedures (PK at two timepoints), with a 28-day screening window, then windows of 0, ±3, ±5 and ±7 days, fasting at SCR, BL, W12 and W24, 9 eligibility criteria (4 inclusion, 5 exclusion) and 3 prohibited medication classes.
A person confirms every value. Each extracted field carries where it came from in the document (a page, or a section of the schedule of assessments), a value not in the document is left empty rather than guessed, and deterministic cross-checks run on top (overlapping windows, visits the study does not have). The guided flow is read, confirm each value against its source, budget, sponsor and team, create. A batch queue can read several protocols in turn and, when a protocol number already exists as a study, prepare an amendment instead.
Margin before signature. The compiler also returns a margin-per-coordinator-hour verdict, computed from the site's own settings: courier cost per lab shipment, EDC minutes per visit, and coordinator minutes and direct cost per procedure. Vigía ships none of these values. Until the site enters them, the verdict says what is missing rather than inventing a number.
Amendments re-compile the same way. An amendment that changes the schedule, eligibility, prohibited medications or stopping rules creates a new study-definition version. The PI reviews a plain-words comparison before signing; visits not yet started are re-instantiated from the new version and keep their booking; closed visits are never re-judged by rules that changed later; and the amendment card lists delegated staff who still need training on the new version.
The Quality Guardian: 51 cited rules at the point of care
The Guardian evaluates a visit (saved records plus the drafts being typed) and returns findings. Each finding names its rule and cites its source, for example 21 CFR 50.20 for consent before procedures, 21 CFR 312.53(c) and the Form FDA 1572 for delegation, ICH E6(R3) 2.3.2 for protocol training, or ALCOA+ for entry quality.
Every finding has one of four modes:
| Mode | Meaning | Example |
|---|---|---|
| Gate | The act must not happen yet | Dosing before a pregnancy test is resulted; a procedure by someone not delegated; a tripped stopping rule |
| Input | The entry is incomplete and must be completed | A required answer is missing; a timed reading has no actual time |
| Confirm | The entry is implausible and must be confirmed | A value outside what is physiologically plausible |
| Fact | Worth knowing, never blocking | A visit outside its protocol window; an IRB approval about to lapse |
The rule that defines the product: block the act, never the record. If a gated step already happened, Vigía records it with a reason, opens a deviation, and routes it to the PI. Safety capture (adverse events, medications) is never gated by process rules. The only preconditions for writing at all are an authorized, trained account.
What the 51 rules cover. Consent (current IRB-approved ICF version, obtained before any procedure, fully documented, signed copy on file, in a language the participant understands, parental permission and assent for a minor, own consent at the age of majority, an impartial witness when the participant cannot read, a study partner before informant-based assessments, and only what a withdrawn participant still agrees to). Study status (IRB approval current and not about to lapse, study not suspended, terminated or on clinical hold). Delegation and training (delegated for the task, trained on the current protocol version, GCP current, trained on the eSource system, rater certified, investigator licensed, investigator CV current). Visit timing (inside window, booked on an open clinic day, Day 1 inside the screening interval). Investigational product (randomized before study drug, dispensed before administered, the IRT-assigned and valid kit, compliance 80 to 120 percent, no drug after discontinuation, no prohibited concomitant medication, no tripped stopping rule, pregnancy test resulted before dosing). Sequence (pre-dose assessments and PK before the dose, post-dose after it). Labs (fasting status matches the schedule, kit in date, PK processed within the study's limit (60 minutes unless it sets another), timed samples inside their window). Eligibility (every criterion recorded and met, investigator confirmation before randomization). Safety (AEs consistent with visit notes, clinically significant findings captured, SAEs reported within the study's expedited window, suicidality screen reviewed, safety MRI read). Entry quality (contemporaneous within 24 hours, attributable to its performer, required fields complete, values plausible and out-of-range values reviewed). Kit expiry, the medication log and the dosing decision are judged on the day the step was performed, not the day it was booked.
Typing feedback. As a number is typed, the field judges it against its own reference and plausible range, in words. The sample plausibility check turns 720 minutes to centrifuge into "did you mean 72?" (outside the plausible 0 to 600); 72 is then still flagged against the 60-minute limit.
Delegation is timed precisely. A delegation line cannot be created for someone without current GCP training, cannot start in the past, and authorizes nothing until the study's PI initials it. It is then in force from the later of its start date and the PI's initials, and ends the instant it is cut. The same initials open the person's view of the study. Pre-flight judges people on the booked day, so a visit tomorrow can be held today for a missing credential.
Time is honest. Entries carry the time the act was performed, not the entry time. More than 24 hours later requires a late-entry reason. A repeat reading is a new reading, never an overwrite, and a reading that meets a stopping rule opens an event that holds IP until an investigator signs a decision.
Eligibility as a signed checklist. One row per inclusion and exclusion criterion: met, not met or not applicable, with evidence. Where the criterion can be read from recorded data (age from date of birth, BMI, vitals, local labs, the medication log, the pregnancy test, consent on file) Vigía evaluates it and stores the source value. Marking "met" over a "not met" read from the data is a Guardian hold. The PI signs the checklist, and randomization and Day-1 dosing are gated on that signature.
Versioned judgment. Each visit is judged by the schedule, protocol training, prohibited medications and stopping rules of the study-definition version it follows, so an amendment never retroactively fails a closed visit.
The AI features: reading, filling and drafting, always with a person confirming
Vigía's AI work follows one pattern. It reads or drafts, cites where each value came from, and saves nothing until a person confirms each field. Every reading is shown beside its source: each value with its page or region, and a confirm tick per field.
Reading documents. The model reads four kinds of document, each under a fixed JSON contract where every field carries its page and anything absent from the document is null:
- Protocols, which feed the compiler.
- Central-lab reports (type, dates, every result with value, unit, printed range and flag), which are attached to the visit.
- CTA budgets, which become the study budget.
- Outside medical records (a PDF or a photo), which fill the structured medical history.
Deterministic cross-checks run on every reading: overlapping visit windows, a flag that contradicts the printed range, an unflagged out-of-range value (on the sample report, potassium 5.9 against a 3.5 to 5.1 range, with no flag printed), a collection date that is not the draw's, fees that do not add up to the stated total (the sample CTA states a total per participant $25 above what its visit fees add up to). The saving commands accept a reading only when every field was confirmed by a person and equals the value saved. The record keeps the document's SHA-256, the model, the page per field, which fields were corrected, and who confirmed.
Worksheet photos and dictation. A photo of a paper worksheet, a PDF worksheet, or a dictation transcript becomes a draft that lists only the visit's open fields, each with a confidence and the phrase or region it came from. On the sample worksheet the draft proposes seated 5 minutes, BP 126/80, pulse 70, temperature 36.7 °C, respiratory rate 15, weight 78.4 kg and height 171 cm, with confidences of 0.90 to 0.95. A draft saves nothing on its own.
Central-lab results by HL7 or CSV. Results arrive as HL7 v2 ORU^R01 messages or CSV files, by upload, through an HL7 MLLP listener, from a drop folder, or posted by a laboratory's interface engine with a machine credential (see Connections below). They are matched to the draw by kit or accession number and collection date, never by name. Anything that does not match waits in a reconciliation queue with a reason and, where one fits, a suggestion for a person to confirm. Matched results are filed as lab reports and enter the investigator's review queue.
Device files. ECG CSV or XML, vitals-monitor and scale exports in the formats Vigía defines fill the matching fields. Vendor formats need a mapping first.
Carry-forward. Stable answers (adult height, outside records, the medication review over the medication log, the kit out and its units) offer to carry forward in one tap. Vital signs, ECGs, labs, PK, scales, the pregnancy test, consent, eligibility, the exam, study drug and any timed or repeat reading are refused whatever a form says.
Provenance on every value. Each filled value shows a source chip (carried forward, lab feed, device file, model reading, import, computed). A value the person changes before saving becomes their entry, with the source's value kept. The system counts entries avoided only from these records.
Safety drafting. A bilingual AE lexicon watches visit notes for potential SAEs. A Spanish note such as "se cayó" can produce a drafted adverse event and start the SAE clock: the study's recorded expedited window from the site's awareness, 24 hours when the study records none. SAE reports are recorded in Vigía for the sponsor, with the clock shown by time left.
Autopilot. A rules engine, labeled as such on every item ("Prepared by Autopilot (rules)"), prepares work for approval: window rescues, invoices for unbilled work, underpayment disputes, query answers drafted from source, AE drafts from notes, re-consent plans, kit prep, monitoring packets and pre-screen matches. It is a review inbox: each item shows its evidence and exactly what approving will write or send. Approve, edit or decline with one key each. Nothing it prepares leaves without a named approval.
Ask Vigía. A command bar answers questions over the asker's own view, cites the records it used, says whether rules or a model wrote the answer, and lists the tools that read them. Without a model it routes a question to a fixed intent (participant, eligibility, enrollment shortfall, sponsor pay lag, training gaps, windows, safety, money, readiness, staff, quality, binder, schedule). If nothing matches it says it cannot answer from rules and suggests three questions the role can ask. It never answers a different question.
What each model path sends. A statement of what is sent, on each path, is shown in the Trust center and under each PDF reading button. Model access goes through a gateway that requires a business associate agreement, logs calls by hash, and pseudonymizes Ask Vigía messages and tool results.
The rest of the site, module by module
Visits and scheduling. A clinic board by day or week, grouped by room or coordinator, shows window bars, pre-flight holds, closures and coordinator load. Dragging a visit to a new slot runs the Guardian's booking check first. Slots are proposed only with a coordinator who is delegated on that date and trained for every step they will perform; otherwise the booking drawer says who was considered and why not. The site closure calendar covers holidays by rule and dated closures. Consent-gated visit reminders use IRB-approved, PI-signed text and go out at most once; if a send's outcome is unknown after a crash or timeout, a person checks it and it is never re-sent automatically.
The visit workspace. A step rail in protocol order gives every step a state: not started, ready, held, done, needs confirmation, needs attestation, not done. Units are always in view. Enter moves to the next field and, on the last, records. A dedicated dosing moment handles pre-dose steps, IRT assignment against the kit dispensed, and times. Drafts live only in that browser tab until recorded and are wiped at sign-out, lock or expiry. Corrections happen in a side sheet with the reason required. A close checklist is built from the same blockers the close command accepts, so it cannot disagree with it.
Consent. Site-based eConsent: sections read to the end, a comprehension check with flagged topics resolved before signing, participant signature, staff e-signature, and a certified copy with a content hash. Consent forms are versioned per language, with amendments and re-consent determinations, LAR and assent, and study-partner consent. Handing a tablet to a participant ends the staff session on it (kiosk mode). Remote eConsent sends a single-use, expiring link by text or email; the participant proves date of birth plus a one-time code, and the link locks after five wrong attempts. A legally authorized representative, a study partner or an impartial witness each get their own link with their own check. The certified copy lists every signer, the identity check, the device's IP address and user agent, and the recorded call.
Regulatory binder (eReg). An essential-document catalog at site and study level with versions, expiry and person-linked credentials. A status board shows each document type as current, expiring, needs signature or missing. Documents are signed inside Vigía with a fixed meaning per type (Form FDA 1572 and protocol signature page by the PI, financial disclosure by the discloser, CV by its owner, note to file by its author). Signatures bind to the version and its file hash; a newer version voids the open request. Certified copies of paper originals are supported. A daily site check updates binder expiry, overdue acknowledgments and unfiled required documents.
Electronic signatures. Signing commands are a fixed list that require re-authentication. On a server this is a single-use grant a client cannot assert; with passkey signing turned on by the director, a fresh passkey assertion can serve. Each signature stores the signer, printed name and title at signing, a meaning fixed by the command, the method, and the hash of what was signed. A later change breaks the binding and the old signature stays in history. The investigator sign-off queue signs a batch of visits with one re-authentication, and the signature sheet says exactly what the signature means.
Investigational product. Dispensing and administration are two acts, with pharmacist, kit and IRT gates before the first and pre-dose gates before the second (a study can be set to one step). Kits can be frozen for destruction; destruction requires the monitor's reconciliation, the sponsor's authorization and a witness. Storage locations (refrigerator, freezer, room) hold the site's acceptable range, daily min and max readings entered by hand or from a logger CSV, and alerts for missed or out-of-range readings. An excursion quarantines every kit kept there during it; release is a signed command.
Safety. The SAE clock leads the Safety page: the study's recorded expedited window (24 hours by default) from site awareness, ordered by time left, with each adverse event's next step. Potential SAEs from notes wait for a decision. Safety reports and the PI's acknowledgment are tracked in the binder. Stopping-rule events hold IP until an investigator signs a decision.
Quality. Deviations and CAPA run as a three-stage flow (needs review, reviewed, closed). Data queries are tracked with their turnaround. Monitoring readiness counts what a monitor will find, and approving a monitoring packet files the coded readiness report in the binder with its SHA-256 for the assigned monitor to open.
Connections. A director sets up each connection to an outside system, tests it against a list of hosts the operator has allowed, stores its credential (encrypted, never shown again) and switches it on; changing a connection after its test asks for a new test, and each step is audited. There are five kinds: an HL7 v2 listener (MLLP) that a laboratory or hospital interface engine sends results to, an SFTP or network drop folder read for result files, a FHIR R4 server, an outbound webhook signed with HMAC-SHA256, and a registered API. Inbound results are matched and queued for a person to file, as above. The FHIR connection reads the server's capability statement; reading a participant's record from the EHR into a visit is not built, and a registered API moves no data until a connector for it is built. The MLLP listener binds to the local address unless the operator opens it, and only on ports the operator allows. A laboratory's interface engine can instead post results with a machine credential: one scope (delivering lab results), an optional address allow-list, a rate limit, an expiry, rotation and revocation. Finance, regulatory and auditors can see connections but not change them.
Sponsor EDC. A per-study mapping to the sponsor's CRF (form and item OIDs, codelists, event OIDs) produces a transcription sheet in the sponsor's form order and a CDISC ODM 1.3.2 export. Closed visits are sent only when a person presses Send, approves a batch, or the study is explicitly set to send on close. The EDC's answer is reconciled item by item. A later source correction marks a sent visit stale, and the resend carries only the changed items. Unmapped values are never sent.
Recruitment. A web intake form for leads, enabled by the director, takes one new lead per submission with the exact permission wording. A pipeline board runs new, to call, contacted, pre-screened, consented, randomized or closed, matching leads to studies and showing per-source return with the leads behind every count.
Start-up. A checklist names what blocks activation: IRB approval from the filed letter, PI-initialed delegation, training, CTA budget and execution, site initiation visit, IP, sponsor site number. IRB expiry warnings feed Today.
Participant payments. Reloadable-card stipends move through drafts, approval by someone other than the drafter, a funding file, and a result file or manual confirmation by someone other than the uploader. Only the card's last four digits and a provider token are stored.
Reports and the switch-over. Eight standard reports and an ad-hoc builder over 17 datasets run on the role-scoped view with no direct identifiers; finance also has twelve financial reports (summary, receivables aging, unbilled and accrued revenue, revenue, profitability, cash, adjustments, holdback, participant payments, forecast, month-end close and standard-of-care billing). A switch-over import brings staff, training, delegation, participants, visit history, medications, AEs, queries, deviations, kits and open receivables from another system or paper, with column mapping, dry run, row-level errors, all-or-nothing commit and no double imports. Every imported record keeps its source reference, and the director signs the reconciliation.
Revenue integrity: finding and collecting what the site earned
Vigía ties money to the same record as the clinical work, so finished work cannot silently go unbilled. The Revenue page tracks earned versus billed versus paid, and the money workspace shows the invoice-to-cash pipeline in six stages: unbilled, draft, issued, tracking, remitted, reconciled. Each figure opens the records it counts.
Unbilled work. Finished work not yet invoiced is counted on the Revenue page and in the money workspace, and each figure opens the lines behind it. Autopilot prepares the invoices as drafts for finance to approve.
Budgets. CTA budgets are versioned: visit fees, invoiceables, holdback, stipend, payment terms, screen-failure fee and cap. Earned lines keep the budget version they were earned under. A budget can be read from the CTA PDF with the page cited for each fee. When fees do not add up to the stated total, the reading says so; the sample CTA's stated total is $25 above the sum of its visit fees.
Invoices. Sponsor and CRO records are billing parties; a study bills its CRO on the sponsor's behalf when one is set. The protocol's sponsor is matched to a record only by exact normalized name; otherwise a person chooses. The invoice document carries letterhead and remit-to, bill-to, sponsor site number, CTA reference and budget version, lines by participant number, visit, service date and fee code, holdback netted, terms and due date, as printable HTML and CSV. Numbers come from the site's own sequence and are assigned at issue. The issued document is frozen with its SHA-256. Corrections go through numbered credit notes. An invoice imported at switch-over keeps the previous system's number and is never re-issued or renumbered.
Remittances. A sponsor's remittance CSV is matched to earned lines through a saved column mapping, or applied by hand. Partial payments and unapplied cash are first-class. Only the rows a person confirmed are applied; the rest stay as unapplied cash. The app shows how sure each automatic match is and where unapplied cash would go.
Short-pays and underpayments. Two detectors run continuously: EDC-triggered fees still unpaid 20 days past the sponsor's pay lag (the median days to pay of that sponsor's recorded visit-fee payments, or the payment terms when no history exists), and invoices paid in part and past due with a later payment from the sponsor on record. On the demo site, the sponsor of study TDW-118 has left visit fees unpaid past its usual pay lag, and Autopilot drafts the dispute letter for approval.
Cash forecast. Money already earned is placed on a calendar by each sponsor's recorded pay lag. Margin per coordinator hour appears only from costs and times the site has entered in its settings.
Role separation. Finance sees money but no clinical values. Card payouts require that the approver is not the drafter and the confirmer is not the uploader.
Insights: numbers that show their method
Every Insights figure is computed from the records in the viewer's own view, carries the records it counts, and states its method. Finance sees money but not clinical sections; monitors see their studies without breakdowns by person.
Enrollment forecasts. A constant-rate Poisson model with a Gamma posterior gives a predictive 80 percent range per study. There is no forecast under 5 randomizations or 42 active days; the screen says there is not enough history. With an enrollment target date recorded, it shows the chance of finishing on time and the randomizations and screenings per week it would take.
Visit-window risk. A regularized logistic model is fitted on the site's finished visits as they stood the day each window opened, using window length, open clinic days, earlier late or missed visits, reminders, booking state and coordinator load. It is validated with a fixed-seed, subject-grouped, stratified 5-fold cross-validation, reporting AUC and Brier score against the base rate with a bootstrap interval. The screens show a risk form only if the cross-validated AUC is at least 0.6, the interval's lower end is above 0.5 and the Brier score beats the base rate. Otherwise the open visits appear as a neutral list ("Visits worth a look") with a plain statement that the score did not beat the base rate. On the demo site's synthetic history the model does not clear that bar, so it shows the neutral list.
Quality patterns. Rates per 100 procedures by study, procedure, person and week; deviation clusters; and patterns found by counting one- and two-attribute groups with at least 5 events, at least twice the site rate, and a Bonferroni-corrected chance below 1 percent.
Money and staff. Unbilled aging, skipped-fee trend, a cash forecast placed by sponsor pay lag, margin only from the site's settings, staff load, expiries and study carriage.
Provenance statistics. A count of entries people did not have to type, per visit type, from the provenance records.
Narrative. On a person's click, a model may write the week's story from numbered facts (F1, F2 and so on). Each sentence is checked for its citations and numbers, shown as model output, and never saved.
Portfolio view. The Studies board shows each study's next action, enrollment against target with the forecast, windows at risk, readiness score, open and overdue queries, IRB state, re-consent counts and start-up blockers. Every number opens its records.
Trust and security: the safeguards built in
Vigía is built around HIPAA's technical safeguards and Part 11 electronic signatures. The controls below are in the product; a Trust center page shows them, verifies the audit chain on demand, and surfaces privacy review and AI governance.
Access. Sessions with required TOTP multi-factor authentication, optional passkeys with user verification, throttled sign-in, a password policy with a common-password list, idle logoff and a lock screen. State-changing requests need a CSRF header; routes are rate limited; a strict content security policy applies. Accounts are invited with an identity-verification method and emailed enrollment links; deactivation kills sessions and grants.
Least privilege. Eleven roles plus study scope (RBAC and ABAC). Every client receives a minimum-necessary projection of the record. Identifiers are masked until revealed with a purpose chosen from a fixed list of eight and a written note of at least ten characters; each reveal is audited and limited to 20 per person per hour outside break-glass. Break-glass lifts study scope for 60 minutes and queues a privacy review by someone else.
Encryption. Fields classified as PHI are encrypted at the field level with AES-256-GCM under a per-tenant data key, wrapped by a local key or AWS KMS. Documents are stored encrypted and scanned for malware before they are stored or read; an infected file is refused and audited, and an unavailable scanner refuses the upload.
Audit trail. Every command appends to an append-only, hash-chained log (SHA-256): who, role, when, what entity, a summary, the reason and field-level diffs. The audit table refuses updates and deletes, and keyed seals over state and audit rows detect out-of-band edits, deletions and truncation. The Trust center verifies the chain on demand, and a tamper test shows the chain failing at the exact event that was altered. Reading the audit trail is itself accounted for.
Signatures. Re-authenticated, bound to the exact content signed, with a fixed meaning (see the e-signature module above). Passkey signing is off unless the site director turns it on.
Privacy in AI paths. Dictation and Ask Vigía messages are pseudonymized before they reach a model. The pseudonymizer is pattern-based: it knows this site's participants and common identifier shapes, and a name it does not know passes through. Reports and the report builder run on the role-scoped view without direct identifiers. A PDF cannot be pseudonymized in-process, so it is sent as the file under the business associate agreement; the Trust center states this plainly under each reading button.
Operations. Encrypted backups and restore, a disaster-recovery drill that times backup and restore and re-verifies seals and the audit chain, data-key rotation and re-wrap, SBOM generation, and a daily site check at a site-local time (default 05:30).
Human-readable records. Participant records and study archives export in a readable form that states what they include, with each value's source, the source's time and who confirmed it (21 CFR 11.10(b)). Direct identifiers are not in the exports, and free text people typed passes through the same pseudonymizer. A study can also be exported as one structured JSON document with its history, signatures and audit trail.
How it is built
Vigía has three parts, and one rule holds across them: business logic lives once, in core.
| Part | What it is |
|---|---|
| Core | Pure TypeScript with no runtime dependencies, running in Node and in the browser. It holds the domain model, every command, the Quality Guardian, the engines, role and study permissions, the audit chain, PHI classification, e-signature binding and the synthetic demo site. |
| Server | A Fastify API around core. It handles sessions and multi-factor authentication, passkeys, field-level encryption, the append-only audit in SQLite, eConsent kiosk sessions, public routes for remote consent and web intake, the lab-result and device-file intake, the integrations (MLLP listeners, drop folders, FHIR, webhooks and machine credentials), malware scanning, the AI gateway, the mailer, the participant messaging port and the sponsor EDC port. It compiles to plain JavaScript for production. |
| Web | A React 18 client. In live mode it talks to the server; in demo mode it runs core in the browser on the synthetic site and applies the same role projection, so switching personas shows what each role really sees. |
State changes only through commands. The site is one state object (users, studies, participants, visits, procedure records, AEs, medications, IP kits, delegation, training, documents, queries, deviations, invoices, remittances, recruitment leads, captures and the audit trail). A command checks permission and study scope, validates the input and domain rules, mutates state, and appends to the audit chain. There are 274 commands, listed once in a command table; the server exposes one route per entry and a test keeps the two lists identical.
Sync. The client fetches its projection once, polls a cheap version endpoint, and applies deltas by record with id digests, re-fetching a collection only when its digest no longer matches. A change made elsewhere reaches a client at its next poll (every 60 seconds) or after its own command.
The interface. A design system called Lookout: a quiet slate ground in light and dark themes with one ink-blue accent, three type families (Schibsted Grotesk for display, Atkinson Hyperlegible Next for body, Atkinson Hyperlegible Mono for data), severity never shown by color alone, a provenance chip on every sourced value, drill-down from every figure, a command palette and keyboard map, and tablet ergonomics for the investigator sign-off queue. Every page has its own address after the # in the URL, so a link opens it directly, and a link to something outside a person's view shows one "not available to you" page for both missing and forbidden. In the standard build each page except Today loads when it is first opened; the single-file build published on the website carries the whole app in one page.
Operations. The server persists to SQLite through Node's built-in driver behind one small interface with a start-up self-test (write, read back, integrity check). A production site is created empty by a provisioning command, with its first director enrolling through an emailed link. The documentation set includes an architecture guide, a HIPAA control map, a validation package (URS, risk assessment, traceability matrix, IQ, OQ and PQ templates) and an SBOM.
Scope
What the product covers, and where its edges are.
- Integrations. EDC submission is built for Medidata Rave only; other EDCs go by ODM file or transcription. Card payouts go by funding file, with no card-program connection. SAE reports are recorded, not transmitted. Vendor instrument formats need a mapping to a format Vigía defines. Laboratory feeds arrive by an MLLP listener, a drop folder or a scoped machine credential; mutual TLS is not built, and a credential can deliver lab results only. The FHIR connection reads a server's capability statement and nothing more, and a registered API moves no data until a connector is built.
- Consent. There is no video inside Vigía; remote discussions are the staff member's own call, recorded by them. Remote signers prove possession of a recorded contact and, for representatives and study partners, a knowledge factor; they are not checked against an identity document.
- Participants. No participant portal beyond the remote eConsent page and the intake form. Reminders go by SMS only.
- Language. The staff interface is in English; participant-facing text is in Spanish and English.
- Platform. SQLite with one server process per database, so no high-availability storage. Clients learn of changes at their next poll. Dragging a visit on the schedule board needs a mouse; touch uses a Move dialog.
- Data. Demo mode contains no real PHI. The synthetic site is a deterministic 26-protocol site in San Juan.