ALCOA+ AGENTGUARD · Live since 2026-05-08

HiveALCOA turns every clinical trial event into an FDA-grade receipt. It's ALCOA+ compliant, signed twice, and still valid the day a regulator asks.

Clinical trials will cost over $200B worldwide in 2026. Veeva Vault, Medidata Rave, Pfizer, Roche, and Novartis already run eTMF, EDC, and validation systems. None of them give you a signature that still holds up at a 15-year FDA inspection in 2041, once today's Ed25519 signatures are breakable. AgentGuard sits underneath them. Every protocol amendment, every consent capture, every adverse event report, every CRO data transfer, and every database lock gets captured as a receipt signed twice (Ed25519 plus ML-DSA-65) and anchored to Base 8453. It's built to meet ALCOA+ from the ground up.

High-volume or negotiated terms? Talk to Steve

protocolconsentscreeningenrollmentdosingadverse_eventePRO_captureCRO_transferquery_closedatabase_locksubmission

What this is worth on a single Phase III oncology trial

AgentGuard reads events from any eTMF, EDC, CTMS, IRT, ePRO, or CRO data-transfer pipeline you already have. Every state change becomes a receipt signed twice, with a pointer back to the event before it, and the full ALCOA+ attribute set written into named fields. Here are the numbers a Head of Data Integrity, a VP of Regulatory Affairs, or a CRO QA Director can bring to the steering committee.

Global trial spend
$200B+
Global clinical-trial spend in 2026 per industry tracking from the IQVIA Institute. The receipt rail underneath that spend is the unit that survives a 2041 inspection.
FDA retention
15 yr
21 CFR 312.62 requires investigators to keep trial records for two years after marketing approval. In practice that's 15 or more years from the first dose. Ed25519 alone won't last that long. ML-DSA-65 will.
Cost to FDA approval
$2.6B
Average capitalized cost to bring a new drug to FDA approval per the Tufts Center for the Study of Drug Development. A receipt-anchored data integrity layer is rounding error against that number and the only thing standing between it and a CRL.
Single Form 483 cost
$10M+
Average sponsor cost of a single Form 483 finding when remediation, re-monitoring, re-submission, and approval delay are priced in. AgentGuard prevents the data-integrity findings that drive the bulk of 483s in clinical trials.
PQ horizon
2041
This is the year a 2026 ML-DSA-65 (NIST FIPS 204) signature still checks out on a laptop with no internet, in front of an FDA inspector pulling records from a closed-out trial. Ed25519 alone can't make that promise.
ALCOA+ coverage
9 of 9
All nine ALCOA+ attributes (Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, and Available) are written as named fields in every receipt, following the FDA data integrity guidance and EMA Annex 11.

A sponsor running ten active Phase II/III programs with about 50,000 evaluable subjects pays around $0.0192 per event. Compare that to a single Form 483 data integrity finding, which already costs an eight-figure fix and a six-month delay to approval. The math speaks for itself.

For sponsor data integrity, regulatory affairs, CRO QA, and FDA inspection-readiness

This is built for sponsor data integrity teams, regulatory affairs, CRO QA leads, and FDA inspection readiness officers. AgentGuard does not replace Veeva Vault or Medidata Rave. It runs underneath them as a receipt layer. Every state change becomes ALCOA+ evidence the FDA can check for itself under 21 CFR Part 11, without having to take the sponsor's word for it.

A receipt rail, not an EDC

EDC vendors hold the case report form data and check it against the protocol. eTMF vendors hold the trial master file documents. CTMS vendors hold the operational state. AgentGuard does none of that. It produces the signed ALCOA+ receipt that proves a recorded clinical trial event happened the way the sponsor says it did. That covers the protocol amendment that authorized it, every consent, screening, dosing, adverse event report, ePRO capture, and CRO transfer that touched it, all the way to the database lock and FDA submission. Keeping that separate is the whole point.

LAYER 3
Sponsor and CRO operations: Veeva Vault eTMF, Medidata Rave EDC, Oracle InForm, IQVIA, Parexel, ICON, Labcorp, Pfizer, Roche, Novartis, Merck, AstraZeneca. This covers protocol design, site management, monitoring, statistical programming, and submission.
LAYER 2
AgentGuard receipt rail. Lifecycle receipts signed twice, for protocol, consent, screening, enrollment, dosing, adverse_event, ePRO_capture, CRO_transfer, query_close, database_lock, and submission. Built to line up with ALCOA+, 21 CFR Part 11, ICH E6(R3) GCP, ICH E2B(R3), CDISC SDTM / ADaM, HL7 FHIR R5, and EU AI Act Article 26.
LAYER 1
Base 8453 anchoring · Ed25519 (RFC 8032) + ML-DSA-65 (NIST FIPS 204) · USDC settlement via x402 · CBOR-canonical envelopes.

Every sponsor, CRO, and academic medical center produces the same kind of evidence, just under different vendor names. That evidence doesn't depend on any one platform, which is what makes it hold up to an FDA inspector under 21 CFR Part 11, to an EMA inspector under Annex 11, or to an MHRA inspector with no internet access in 2041.

How a Form 483 finding gets stopped in a 2031 FDA inspection

Here's a specific example, walked through step by step. A 2026 Phase III oncology trial enrolls patient #847 at a community oncology site. Five years later, in 2031, the FDA shows up for a pre-approval inspection. The inspector picks one subject at random and asks the sponsor to prove this patient consented to the v3.2 protocol amendment that was active on the day of consent. Now the clock is the only thing that matters.

01
2026 enrollment. A 2026 Phase III oncology trial enrolls patient #847 at a community oncology site. The site is using an AI-assisted eligibility-screening agent integrated into the EDC.
02
Consent captured by AI agent at the site. The agent walks the patient through the v3.2 protocol consent form. Patient signs the e-consent. agentguard_consent_attest fires with the patient DID, IRB version hash, AI agent DID, and the site investigator DID. Dual signatures applied. Anchor on Base 8453.
03
AgentGuard records the consent_attest. Receipt binds patient DID + IRB version hash (v3.2) + IRB approval date + AI agent DID + investigator DID + protocol_amendment_effective_date. ALCOA+ envelope is fully populated. chain_length threads to the screening event.
04
2031 FDA inspection. Inspector picks subject #847 at random and asks the sponsor to prove the patient consented to the v3.2 protocol on the day of consent. The sponsor opens AgentGuard.
05
Inspector pulls chain_verify. AgentGuard returns the consent receipt and the full chain back to the protocol amendment receipt. ML-DSA-65 still checks out in 2031 against the issuer's archived public key. The ALCOA+ envelope shows Attributable (patient, investigator, and AI agent DID), Contemporaneous (the Base 8453 anchor block timestamp matches the day of consent), Original (no rewrite history on the chain), Accurate (IRB version hash matches v3.2), Complete (all 9 attributes present), Consistent (schema version locked), Enduring (the post-quantum signature still checks out), and Available (endpoint live).
06
Form 483 averted. The inspector accepts the receipt as primary evidence under 21 CFR Part 11. No data integrity finding, no Form 483, no fix cycle, and over $10M in cost avoided. The same chain answers a future EMA inspection, MHRA inspection, or product liability discovery with no need to re-collect anything. The receipt is the evidence.

Live verification: what an inspector sees

The envelope is CBOR-canonical, and it checks out offline against the issuer's published public keys. No call to Hive is needed to verify it. The panel below is the same one every FDA, EMA, MHRA, or PMDA inspector sees, with the full ALCOA+ attribute grid written out as named fields.

agentguard_chain_verify · trial_id = NCT0X-2026-ONC-PIII · subject = 847 VERIFIED
// CBOR-canonical clinical-trial consent_attest envelope, JSON-rendered { "receipt_id": "01J5K-AG-CONSENT-847C2A", "trial_id": "NCT0X-2026-ONC-PIII", "event_kind": "consent_attest", "subject": { "usubji_d": "NCT0X-2026-ONC-PIII-847", "did": "did:hive:subject:0xa19c…7d41" }, "investigator_did": "did:hive:investigator:0x88f3…c104", "ai_agent_did": "did:hive:agent:eligibility:0x4e21…b8c0", "protocol_version": "v3.2", "irb_version_hash": "sha256:9b2f7c…a14d", "alcoa": { "attributable_did": "did:hive:subject:0xa19c…7d41", "legible_format": "cbor-canonical/json-rendered", "contemporaneous_anchor_ts": "2026-05-08T14:11:42Z", "original_payload_hash": "sha256:71d3ea…ff04", "accurate_validation": "irb_version_hash == v3.2", "complete_required_fields": 9, "consistent_schema": "agentguard.consent.v1", "enduring_signature": "ml-dsa-65 + ed25519", "available_endpoint": "https://receipts.thehiveryiq.com/v1/alcoa-agentguard/chain_verify" }, "prior_attestation_id": "01J5K-AG-PROTOCOL-v3.2", "chain_length": 3, "anchor_chain": "base-8453", "anchor_txid": "0xb7e1…9c40", "sig_ed25519": "4c7d…e211", // RFC 8032 "sig_mldsa65": "f9a1…3d04" // NIST FIPS 204 }
[ok] Ed25519 signature valid · issuer key fingerprint k1:8c2a…
[ok] ML-DSA-65 signature valid · issuer key fingerprint kq:b71d…
[ok] Chain matches · protocol to consent verified offline · ALCOA+ 9 / 9 attributes present
[ok] VERIFIED · OFFLINE · ALCOA+ COMPLETE · 21 CFR Part 11 evidentiary record

That panel is everything an FDA inspector or a 21 CFR Part 11 compliance officer needs. No demo, no login. The evidence proves itself, and it still works fifteen years from now on a laptop with no internet.

Standards: what AgentGuard adds

Every existing clinical trial standard answers a different question. AgentGuard doesn't replace any of them. It adds the signature that makes each one stand up after the fact, even against quantum computers in 2041.

StandardCoverageWhat AgentGuard adds
21 CFR Part 11FDA electronic records and electronic signaturesCryptographic non-repudiation per record, not per system login
ALCOA+ (FDA + EMA + MHRA)Data integrity attributes: Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, AvailableAll 9 attributes written as named fields in the receipt
ICH E6(R3) GCPGood Clinical Practice: sponsor, investigator, IRB, and monitoring obligationsPer-event consent and amendment receipts with an effective-date clock start
ICH E2B(R3)Adverse event reporting transmission standardBuilt-in receipt for SUSAR / SAE / IRB notification
21 CFR 312.62Investigator records retention: two years post-approval, in practice 15 or more years15-year durability through the ML-DSA-65 anchor on Base 8453
CDISC SDTM / ADaMFDA submission data tabulation and analysis dataset standardsReceipt-anchored audit trail per dataset, per domain, per row hash
HL7 FHIR R5Healthcare data exchange resources, including clinical-trial extensionsNative FHIR Provenance + AuditEvent mapping for every receipt
EU AI Act Article 26High-risk AI system obligations, including AI in medical devicesDecision-level provenance for AI-assisted enrollment, eligibility, and AE coding

3-step integration path

01
Send the webhook. Point your Veeva Vault, Medidata Rave, or Oracle InForm webhook to https://receipts.thehiveryiq.com/v1/alcoa-agentguard/<event>_attest, where <event> is one of protocol, consent, enrollment, dosing, adverse_event, data_transfer, or database_lock (for example consent_attest). That's one sidecar per environment. No protocol amendments, no SDV changes, no monitor-visit changes.
02
Store the returned receipt_id in the eTMF as a 21 CFR Part 11 audit record. That works with Veeva Vault, Florence eBinders, MasterControl, or any eTMF that already accepts a Part 11 audit field. The receipt id travels with the source event, and your source schema doesn't change.
03
Verify any time via https://receipts.thehiveryiq.com/v1/alcoa-agentguard/chain_verify?trial_id=… FDA inspectors, EMA inspectors, MHRA inspectors, sponsor QA, and CRO QA all run this same call. Both signatures check out offline against the issuer's published public keys, so ALCOA+ obligations get answered from the same chain with no need to re-collect anything.

The 11 MCP tools

ToolPurpose
agentguard_protocol_attestAttest a protocol or protocol-amendment event with sponsor DID and IRB version hash.
agentguard_consent_attestAttest an e-consent event with subject DID, investigator DID, and IRB version hash.
agentguard_enrollment_attestAttest enrollment / randomization with eligibility-class hash and AI agent DID if applicable.
agentguard_dosing_attestAttest a dosing event with kit id, lot id, and administration timestamp.
agentguard_adverse_event_attestAttest a SAE / SUSAR / AE per ICH E2B(R3) with MedDRA preferred-term binding.
agentguard_data_transfer_attestAttest a CRO to sponsor data transfer with payload hash and recipient DID.
agentguard_database_lock_attestAttest a database-lock event with the full SDTM dataset hash set.
agentguard_chain_verifyVerify the full lifecycle chain for a trial or subject, from protocol through submission.
agentguard_alcoa_auditReturn the 9-attribute ALCOA+ audit grid for any receipt.
agentguard_pricingRead live pricing surface.
agentguard_healthHealth probe.

All eleven tools are live in production. Contact us for MCP integration credentials and the full well-known manifest.

The trial event envelope

Every agentguard_*_attest call returns an envelope with the receipt id, trial id, event kind, subject (USUBJID plus DID), investigator DID, AI agent DID where it applies, protocol version, IRB version hash, the full nine-field ALCOA+ attribute grid, the prior attestation id, the Base 8453 anchor txid, and two signatures (Ed25519 and ML-DSA-65). The signatures cover every field, so any attempt to tamper with it breaks verification.

The envelope is CBOR-canonical, and you can verify it offline against the issuer's published public keys. ML-DSA-65 (NIST FIPS 204, the government's post-quantum signature standard) is the post-quantum signature. Ed25519 (RFC 8032) gives you classical assurance on top. Both have to check out for the receipt to be valid. Receipts stay valid through key rotation using a signed key history, so a 2026 consent still holds up in a 2041 FDA inspection.

What this is not

Setting the right expectations is part of the product. AgentGuard is narrow on purpose.

NOT
An EDC. Case-report-form data and protocol validation belong to Medidata Rave, Oracle InForm, Veeva CDMS, Castor, and Clinical Conductor.
NOT
An eTMF. Trial master file documents and Part 11 e-signature workflow belong to Veeva Vault, Florence eBinders, and MasterControl.
NOT
A CTMS. Site management, enrollment forecasting, monitoring visit tracking, and budget reconciliation belong to Veeva CTMS, Medidata, and Oracle Siebel CTMS.
NOT
An IRB system. Ethics review, expedited review, and continuing review belong to Advarra, WCG, and academic IRB-of-record systems.
NOT
Medical advice. AgentGuard is data integrity infrastructure. Clinical decisions belong to the investigator and the medical monitor.
NOT
A regulatory filing service. eCTD assembly, gateway submission, and Module 2 / 5 authoring belong to the regulatory operations team.
IS

The horizontal ALCOA+ receipt rail underneath the entire clinical-trial data graph. Sponsors, CROs, sites, IRBs, eTMF, EDC, CTMS, IRT, ePRO, and AI-assisted clinical-operations agents all run cleaner with a dual-signed receipt under each lifecycle transition.

Pricing

TierUnitAnnual bandFit
Per event$0.0192 / eventmetered, no commitmentSelf-serve, any trial scale. Pay per ALCOA+ receipt issued.
Volume commit (optional)from $5,000 / momonthly bundleBundle events at $0.0192 / event. Overage at the same rate.

Per-event pricing at $0.0192 / event fits any trial scale, from adaptive Phase I pilots to global Phase III programs. Volume-commit accounts bundle events at the same rate with monthly invoicing. You settle in USDC on Base 8453 through x402. Treasury address 0x15184Bf50B3d3F52b60434f8942b7D52F2eB436E exists. Receipts settle in seconds. Invoicing is monthly, net-30 by default.

Field map

AgentGuard signs every clinical trial lifecycle change twice, and it drops cleanly into existing CDISC SDTM, HL7 FHIR R5, Veeva Vault API, and Medidata Rave API pipelines. Each call accepts the correlation fields below. The envelope travels through standard JSON / CBOR transports using the Hive Receipt primitive.

Source fieldSource standardMaps to AgentGuard receipt field
USUBJIDCDISC SDTM DM domainreceipt.subject.usubji_d + receipt.subject.did
STUDYIDCDISC SDTM TS domainreceipt.trial_id
IECATCDISC SDTM IE domainreceipt.eligibility_class
AEDECODCDISC SDTM AE domainreceipt.event.meddra_pt
EXTRT + EXDOSE + EXSTDTCCDISC SDTM EX domainreceipt.dosing.{kit_id, dose, administered_at}
Provenance.recordedHL7 FHIR R5 Provenancereceipt.alcoa.contemporaneous_anchor_ts
AuditEvent.agent.whoHL7 FHIR R5 AuditEventreceipt.alcoa.attributable_did
Consent.policyRuleHL7 FHIR R5 Consentreceipt.irb_version_hash
vault__v.api.binder.idVeeva Vault Clinical APIreceipt.etmf_binder_id
rave.api.subject.audit_uuidMedidata Rave Web Servicesreceipt.edc_audit_uuid
inform.api.transaction_idOracle InForm RWSreceipt.edc_audit_uuid
prior_attestation_idAgentGuard chain primitivereceipt.prior_attestation_id

Pair this with HiveComply when SOC 2, HIPAA, GxP, or EU AI Act audits are in scope. HiveComply reads AgentGuard receipts natively. Pair it with Atticus when a product liability or DOJ False Claims Act case turns into litigation.

A real conversation, not a demo black hole

If you are a Head of Data Integrity, VP of Regulatory Affairs, CRO QA Director, or FDA Inspection-Readiness Officer who has already done the math on the cost of a single Form 483 finding and the 15-year retention horizon, the fastest path is a direct note. No qualification gate, no SDR. Steve reads them.

High-volume or negotiated terms? Talk to Steve

Live since 2026-05-08 · 11 MCP tools · ALCOA+ / 21 CFR Part 11 / ICH E6(R3) / ICH E2B(R3) / CDISC / FHIR R5 / FIPS 204 compatible · Dual-signed (Ed25519 + ML-DSA-65) · Settles USDC on Base 8453
Frequently asked

Questions buyers actually ask

What does AgentGuard attest?

Every clinical trial state, including protocol, consent, screening, enrollment, dosing, adverse_event, ePRO_capture, CRO_transfer, query_close, database_lock, and submission, gets a receipt signed twice (Ed25519 plus ML-DSA-65) that's ready for a post-quantum world and that an FDA inspector can check offline.

What is ALCOA+ compliance?

ALCOA+ is the FDA's data integrity standard: Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, and Available. AgentGuard receipts are built so every attestation meets all nine attributes from the start.

Does AgentGuard replace Veeva Vault or Medidata Rave?

No. AgentGuard is the post-quantum durability layer underneath Veeva Vault, Medidata Rave, and Oracle InForm. Your existing eTMF and EDC workflows keep running as they are. Every state change also gets a receipt signed twice.

Is AgentGuard 21 CFR Part 11 ready?

Yes. 21 CFR Part 11 requires electronic records and signatures to be trustworthy, reliable, and as good as paper records. AgentGuard receipts, signed twice with Ed25519 and ML-DSA-65, are built to meet that standard with a clear, enforced chain of custody.

How long are signatures valid?

ML-DSA-65 (NIST FIPS 204) is the post-quantum signature. Ed25519 (RFC 8032) gives you classical assurance on top. Both have to check out for the receipt to be valid. Receipts stay checkable for as long as the regulation requires you to keep the trial record.

What does AgentGuard cost?

Per-event pricing for ALCOA+-grade clinical trial receipts. Annual contract pricing for sponsors and CROs. Settlement is in USDC on Base 8453 via x402.

Hive runs the receipt rail underneath the broader A2A · agent-to-agent commerce category.