Compliant Architecture Built for Trust

From data provenance to full 21 CFR Part 11 compliance, Flywheel is your imaging system of record, with traceability and reproducibility for auditable submissions to regulatory bodies.

Our Commitment to Trust

We ensure that our procedures and systems meet the highest standards of security and privacy.

Visit our Trust Center

Ensure Proper Governance

Manage privileges with role-based permissions to allow for secure data and algorithm sharing with internal and external collaborators.

Stay Audit-Ready from the Start

For organizations looking to meet 21 CFR Part 11 compliance, add audit trails, digital signatures and approval workflows to your Flywheel instance.

Get Data Ready for FDA Submission

Prep your projects for approval with the ability to export datasets and time-stamped audit trails.  

Maintain Security and Data Privacy

Secure your projects to manage collaboration in compliance with IRB, HIPAA and GDPR. Use re-identification tools to identify and purge data if needed.

Leverage Federated Identity Service

Securely invite and authenticate external collaborators with federated integration with 4,000 leading research institutions around the world.

Track Full Data Provenance

Ensure research is reproducible with access and job logs, and file and data object history, plus file delete reason and metadata value change options.

A Security Architecture Based on Industry Best Practices

Validated Solutions

Flywheel offers a fully validated platform and features for fully traceable data management.

  • Audit Trails: Export full audit trail reports at the project level.
  • Access Controls: Leverage logical and role-based access controls following the “least privilege” and “need-to-know” principles to govern employee capabilities.
  • Application Security: Secure application development and monitoring practices ensure flaws and risks to company designed applications are identified early in the development process.
  • Software Development Lifecycle Governance (SDLC): Formal SDLC methodologies are established that govern the secure development, acquisition, and implementation of all application and enhancement projects. Secure SDLC procedures cover secure coding reviews and practices.

Secure Environment

Flywheel is secure by design, with ongoing testing and maintenance.

  • Third-Party Certifications and Penetration Testing: Third-party firms are engaged on an annual basis to perform security audits and testing of the Flywheel environment to demonstrate our commitments to security.
  • Encryption: Customer data is encrypted at-rest (storage and backups) and in transit over public networks to protect the communication and transmission of data between system components.
  • Technical Safeguards: Technical safeguards are in place to protect information systems and data from unauthorized access, use and disclosure of information.
  • Data Segregation: System components are configured to ensure all customer environments are appropriately segmented and isolated.

Comprehensive Policies and Procedures

Flywheel follows a robust set of security and compliance policies.

  • Awareness Training: A comprehensive security and awareness training program is required for all employees, consultants and contractors to ensure compliance with organizational security policies and procedures to protect in-scope information systems and data. All employees must train upon hire and on an annual basis thereafter.
  • Business Continuity and Disaster Recovery: Disaster recovery plans (including restoration of backups) have been developed and tested annually. Test results are reviewed and consequently, contingency plans are updated.
  • Continuous Monitoring and Improvement: The organization has established an ongoing information security improvement program to continuously assess our security posture, stay up-to-date with best practices, and identify new and evolving threats and vulnerabilities.
  • Incident Response: Formal Incident Response processes are defined and established which require incidents to be tracked, documented and resolved in accordance with the NIST incident response framework.

Risk Management Framework

Learn more about how Flywheel manages risk.

  • Risk Management Process: A comprehensive risk management process is in place to analyze, prioritize and treat all organizational risk to ensure risk is reduced to acceptable tolerances.
  • Threat Modeling: A formal structured approach to threat modeling allows engineering teams to identify, and mitigate the risks to company applications and systems and identify the risks and likelihood of threat and impact to each system.
  • Third-Party Supplier Management: A comprehensive formal supplier management process is implemented to ensure that all potential vendors and suppliers are evaluated for potential risk. Suppliers are subject to security review and assessments when onboarding and on an annual basis.

Success Story: Enabling Imaging Review in a Phase 3 Trial

Researchers conducting a complex Phase 3 clinical trial needed to assess the efficacy of a new treatment in participants with diabetic retinopathy. With Flywheel, dispersed clinical sites are uploading ophthalmic images into one, centralized location for comprehensive reader review and auditability.

Frequently Asked Questions

Find answers to your questions about the Flywheel platform.

Our validated solution comes with features like audit trails, project locking and e-signatures to help you ensure compliance with 21 CFR Part 11, along with security features for compliance with HIPAA, GDPR and other data security mandates.

The Flywheel medical imaging platform takes the imaging data you already have stored—across various departments, PACS, institutions, trial sites—and unites them in one place to enhance data discovery and actionability, adding the ability to curate, organize, annotate and analyze this data.

Flywheel can be deployed on AWS or Azure.

Within the Flywheel platform, Flywheel Gears are containerized algorithms that can be deployed in the platform to automate pre-processing tasks and workflows. In addition, Flywheel can connect with Jupyter Notebook and other platforms via open APIs and SDKs to support AI development, while the platform itself is built to create AI-ready datasets for AI model testing and validation. Learn more about Flywheel Gears here.

Eliminate Data Bottlenecks While Maintaining Compliance

With greater data access, built-in compliance options and human-in-the-loop reader workflows, Flywheel gives you more control — for faster go-to-market and data use beyond the trial.