Test environment — data here is not for production use
MedData
Kuwait-first · Clinical research platform

Trusted data. Better research.

A bilingual EDC and clinical research platform built for Kuwait and the Gulf — designed for high-quality data, designed to be auditable end-to-end.

Get startedSign inSee it in action

Built for research teams in Kuwait and the Gulf

Sample record · Demographics
P-0001 · KDR-2026
Complete
Full name
Ahmed Al-Sabah
Age at diagnosis
51
Sex
Male
Symptoms
PolyuriaPolydipsia
Patient has signed the informed consent form on file.
Patient has signed the informed consent form on file.
Audit historyMarked complete by Eyad · 2 minutes ago
01

Design

Author forms visually, publish immutable versions.

02

Capture

Type-aware data entry with full audit history.

03

Export

Encrypted datasets you can hand to a reviewer.

Everything your study needs

Design forms, capture data, audit changes, and export clean datasets — all in one place. No plugins, no add-ons.

Bilingual EN + AR, with first-class RTL

Every label, choice, help text, and notification is bilingual. Arabic layout is structural, not bolted on.

Design instruments with 14 field types

Text, numeric, date/time, email, phone, choice types, descriptive text, and calculated. Type-aware validation at design and entry.

Immutable version snapshots

Publishing freezes the form definition. A record created against v1 still renders the v1 form — even after you ship v2.

Data entry with P-NNNN codes

Auto-generated, unique, per study. The form travels with the record, so the data always knows what it was captured on.

Lifecycle: draft → complete → locked → archived

Every status transition is recorded. Changes to completed records require a reason and show up in the audit trail.

Append-only audit history

Who, what, when, and why. Field-level diffs. No record can change without leaving a trace.

Encrypted, time-limited exports

CSV or JSON, AES-256-GCM at rest, signed download URLs, SHA-256 integrity check. Sensitive fields can be filtered out at request time.

MFA for privileged roles

TOTP-based two-factor authentication. Sessions are server-side, cookies are signed, scrypt password hashing.

Your infrastructure, your data

Cloud-agnostic Docker. PostgreSQL for production, SQLite for dev. Self-host on your own servers, or deploy to any cloud.

Security & compliance

Sensitive data. Sensible controls.

Every password is scrypt-hashed. Every session is server-stored. Every identifier field is tagged at design time. Every download is HMAC-signed. Every export is encrypted at rest and verified on every fetch.

  • scrypt password hashing
  • TOTP for two-factor auth
  • AES-256-GCM export encryption
  • HMAC-signed download URLs
  • SHA-256 integrity on every download
  • Audit trail for every change
# Audit event
{
"actor": "eyad@meddata.example",
"action": "export.download",
"target": "KDR-2026/P-0001..P-0011",
"format": "csv",
"size": 2626,
"sha256": "eab89658825a6a58…",
"expires": "2026-08-13T10:42:07Z"
}

Coming next

We're building the platform in vertical slices. M0 is the foundation; M1 brings roles and operational hardening.

  • Field-level rules & calculated fields (M0.6)
  • Roles, capabilities, and per-role identifier policy (M0.7)
  • Operational controls, retention, and disaster recovery (M0.8)
  • Public read API for authorized integrations (M1)

Ready to capture better data?

Create a workspace in under a minute. No credit card, no sales call.

Create your workspace