Cross-institution analysis
Requires data to move. HIPAA, GDPR and institutional policy say it can't — or only after months of legal negotiation per study.
NOOSChain is a permissioned blockchain for clinical and pharma data collaboration. It gives sponsors, CROs, sites and regulators one tamper-evident history — while per-record access control keeps every record inside its authorised environment, and analytics run where the data lives.
Clinical and pharma data programs stall in the same places. Manual audit processes replace real verification. They are slow and error-prone — exactly where breach and error costs are highest.
Requires data to move. HIPAA, GDPR and institutional policy say it can't — or only after months of legal negotiation per study.
Audit trails live in the systems of whoever ran the step. The sponsor trusts the CRO. The CRO trusts the site. After the fact, nobody can independently verify anything.
Obligations pile manual attestation on top of manual attestation.
Is either over-sharing (the whole dataset) or a data-transfer project (copies everywhere, retention questions nobody can answer).
The audit trail isn't a document someone wrote. It's a history every party can independently verify.
Every access and computation is logged as a signed, deterministic transaction. The audit trail isn't a document someone wrote. It's a history every party can independently verify — with no manual audit required.
Replication policies determine where data may travel, where it must remain and which nodes may retain it — enforced at the infrastructure level, not in a SOP that depends on everyone reading it.
Records can be public, restricted to one owner, or shared with defined organisations and groups. Per-record and per-bucket encryption lets participants share what is necessary while preserving ownership, confidentiality and residency boundaries. The sponsor sees the trial data it sponsors; the site keeps everything else.
Verifiable chain state is separated from encrypted payloads. The network proves the event; only authorised parties read the content.
Approved scripts, containers and AI models travel to the data's home node. Run multi-site analysis without exporting a single patient-level record across the border.
The near-term value is in trial integrity, pharma traceability, and governed analytics on sensitive records — not record portability.
Every data point's custody — collection, transformation, lock, query, correction — is recorded as signed transactions across sponsor, CRO and site nodes. Inspectors don't reconstruct the trail; they verify it.
Custody and compliance events from manufacturing through distribution, with every major stakeholder operating a validating node. Regulatory audit becomes replay, not archaeology.
Noosware's own BETTER project (Horizon Europe) applies decentralized AI to secure, cross-border health data analysis, privacy-compliant by design. NOOSChain is the governance layer underneath: institutions run analysis jointly without centralising the data. Two of our own EU projects — MARS (manufacturing) and BETTER (health) — hit the same wall from opposite sides: independent organisations must collaborate on data and processes while keeping control, privacy, validation and accountability. That recurring wall is why NOOSChain exists.
Run validation workflows with a verifiable execution trail. The recorded execution status, artifacts and hashes are themselves the QA evidence.
The mechanism that makes governed analytics possible: package the workload as a signed script or container image. NOOSChain authorises it against specific buckets, routes it to eligible data-holding nodes, and executes it inside their local environments.
Publish a signed workload with an immutable script or container-image digest.
Approve its identity, buckets, purpose, runtime limits and output policy.
Select nodes that hold the required data and are permitted to execute it.
Query protected buckets inside the node's controlled execution environment.
Commit execution status, results, artifacts and provenance to the blockchain.
Authorising a workload does not authorise its creator to read the underlying data. Access is scoped to the signed workload, selected buckets, eligible nodes and its execution policy.
Read the guideProduce permitted statistics, features and derived datasets while source records stay protected. No model, no export — the gentlest possible entry point.
Compliance, quality and transformation workflows with a verifiable execution trail.
Run approved models against clinical records without exporting the underlying data.
Train or fine-tune inside authorised data environments with controlled artifact retention — federated-style programs where data cannot leave institutional walls.
NOOSChain is our product. We designed it, we run it in production across our own EU health-data projects, and we know what a compliance workload needs before you have to ask. Sponsors, CROs, sites, hospitals — bring us your data-collaboration problem and we'll scope the first workload with you: extraction or validation, what stays in each institution's walls, who sees what.
Book a meetingStart NOOSChain with Docker and inspect the node using the CLI and Web UI.
npm run docker:up
Extraction or validation, what stays in each institution's walls, who sees what — designed with us.
Book a meetingNoosware is an AI-and-infrastructure company whose work spans health data in practice, not just in slides: BETTER (Horizon Europe — decentralized AI for cross-border health data analysis), RAISE Suite (FAIR-by-design research data lifecycle). NOOSChain is the proprietary trust layer used across these projects. It is not a general-purpose blockchain; it supports use cases from enterprise to EU-driven initiatives that require more than experimentation.