HiveALCOA turns every clinical trial event into an FDA-grade receipt. It's ALCOA+ compliant, signed twice, and still valid the day a regulator asks.
Clinical trials will cost over $200B worldwide in 2026. Veeva Vault, Medidata Rave, Pfizer, Roche, and Novartis already run eTMF, EDC, and validation systems. None of them give you a signature that still holds up at a 15-year FDA inspection in 2041, once today's Ed25519 signatures are breakable. AgentGuard sits underneath them. Every protocol amendment, every consent capture, every adverse event report, every CRO data transfer, and every database lock gets captured as a receipt signed twice (Ed25519 plus ML-DSA-65) and anchored to Base 8453. It's built to meet ALCOA+ from the ground up.
High-volume or negotiated terms? Talk to Steve
What this is worth on a single Phase III oncology trial
AgentGuard reads events from any eTMF, EDC, CTMS, IRT, ePRO, or CRO data-transfer pipeline you already have. Every state change becomes a receipt signed twice, with a pointer back to the event before it, and the full ALCOA+ attribute set written into named fields. Here are the numbers a Head of Data Integrity, a VP of Regulatory Affairs, or a CRO QA Director can bring to the steering committee.
A sponsor running ten active Phase II/III programs with about 50,000 evaluable subjects pays around $0.0192 per event. Compare that to a single Form 483 data integrity finding, which already costs an eight-figure fix and a six-month delay to approval. The math speaks for itself.
This is built for sponsor data integrity teams, regulatory affairs, CRO QA leads, and FDA inspection readiness officers. AgentGuard does not replace Veeva Vault or Medidata Rave. It runs underneath them as a receipt layer. Every state change becomes ALCOA+ evidence the FDA can check for itself under 21 CFR Part 11, without having to take the sponsor's word for it.
A receipt rail, not an EDC
EDC vendors hold the case report form data and check it against the protocol. eTMF vendors hold the trial master file documents. CTMS vendors hold the operational state. AgentGuard does none of that. It produces the signed ALCOA+ receipt that proves a recorded clinical trial event happened the way the sponsor says it did. That covers the protocol amendment that authorized it, every consent, screening, dosing, adverse event report, ePRO capture, and CRO transfer that touched it, all the way to the database lock and FDA submission. Keeping that separate is the whole point.
Every sponsor, CRO, and academic medical center produces the same kind of evidence, just under different vendor names. That evidence doesn't depend on any one platform, which is what makes it hold up to an FDA inspector under 21 CFR Part 11, to an EMA inspector under Annex 11, or to an MHRA inspector with no internet access in 2041.
How a Form 483 finding gets stopped in a 2031 FDA inspection
Here's a specific example, walked through step by step. A 2026 Phase III oncology trial enrolls patient #847 at a community oncology site. Five years later, in 2031, the FDA shows up for a pre-approval inspection. The inspector picks one subject at random and asks the sponsor to prove this patient consented to the v3.2 protocol amendment that was active on the day of consent. Now the clock is the only thing that matters.
agentguard_consent_attest fires with the patient DID, IRB version hash, AI agent DID, and the site investigator DID. Dual signatures applied. Anchor on Base 8453.chain_length threads to the screening event.chain_verify. AgentGuard returns the consent receipt and the full chain back to the protocol amendment receipt. ML-DSA-65 still checks out in 2031 against the issuer's archived public key. The ALCOA+ envelope shows Attributable (patient, investigator, and AI agent DID), Contemporaneous (the Base 8453 anchor block timestamp matches the day of consent), Original (no rewrite history on the chain), Accurate (IRB version hash matches v3.2), Complete (all 9 attributes present), Consistent (schema version locked), Enduring (the post-quantum signature still checks out), and Available (endpoint live).Live verification: what an inspector sees
The envelope is CBOR-canonical, and it checks out offline against the issuer's published public keys. No call to Hive is needed to verify it. The panel below is the same one every FDA, EMA, MHRA, or PMDA inspector sees, with the full ALCOA+ attribute grid written out as named fields.
k1:8c2a…kq:b71d…That panel is everything an FDA inspector or a 21 CFR Part 11 compliance officer needs. No demo, no login. The evidence proves itself, and it still works fifteen years from now on a laptop with no internet.
Standards: what AgentGuard adds
Every existing clinical trial standard answers a different question. AgentGuard doesn't replace any of them. It adds the signature that makes each one stand up after the fact, even against quantum computers in 2041.
| Standard | Coverage | What AgentGuard adds |
|---|---|---|
| 21 CFR Part 11 | FDA electronic records and electronic signatures | Cryptographic non-repudiation per record, not per system login |
| ALCOA+ (FDA + EMA + MHRA) | Data integrity attributes: Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available | All 9 attributes written as named fields in the receipt |
| ICH E6(R3) GCP | Good Clinical Practice: sponsor, investigator, IRB, and monitoring obligations | Per-event consent and amendment receipts with an effective-date clock start |
| ICH E2B(R3) | Adverse event reporting transmission standard | Built-in receipt for SUSAR / SAE / IRB notification |
| 21 CFR 312.62 | Investigator records retention: two years post-approval, in practice 15 or more years | 15-year durability through the ML-DSA-65 anchor on Base 8453 |
| CDISC SDTM / ADaM | FDA submission data tabulation and analysis dataset standards | Receipt-anchored audit trail per dataset, per domain, per row hash |
| HL7 FHIR R5 | Healthcare data exchange resources, including clinical-trial extensions | Native FHIR Provenance + AuditEvent mapping for every receipt |
| EU AI Act Article 26 | High-risk AI system obligations, including AI in medical devices | Decision-level provenance for AI-assisted enrollment, eligibility, and AE coding |
3-step integration path
https://receipts.thehiveryiq.com/v1/alcoa-agentguard/<event>_attest, where <event> is one of protocol, consent, enrollment, dosing, adverse_event, data_transfer, or database_lock (for example consent_attest). That's one sidecar per environment. No protocol amendments, no SDV changes, no monitor-visit changes.receipt_id in the eTMF as a 21 CFR Part 11 audit record. That works with Veeva Vault, Florence eBinders, MasterControl, or any eTMF that already accepts a Part 11 audit field. The receipt id travels with the source event, and your source schema doesn't change.https://receipts.thehiveryiq.com/v1/alcoa-agentguard/chain_verify?trial_id=… FDA inspectors, EMA inspectors, MHRA inspectors, sponsor QA, and CRO QA all run this same call. Both signatures check out offline against the issuer's published public keys, so ALCOA+ obligations get answered from the same chain with no need to re-collect anything.The 11 MCP tools
| Tool | Purpose |
|---|---|
agentguard_protocol_attest | Attest a protocol or protocol-amendment event with sponsor DID and IRB version hash. |
agentguard_consent_attest | Attest an e-consent event with subject DID, investigator DID, and IRB version hash. |
agentguard_enrollment_attest | Attest enrollment / randomization with eligibility-class hash and AI agent DID if applicable. |
agentguard_dosing_attest | Attest a dosing event with kit id, lot id, and administration timestamp. |
agentguard_adverse_event_attest | Attest a SAE / SUSAR / AE per ICH E2B(R3) with MedDRA preferred-term binding. |
agentguard_data_transfer_attest | Attest a CRO to sponsor data transfer with payload hash and recipient DID. |
agentguard_database_lock_attest | Attest a database-lock event with the full SDTM dataset hash set. |
agentguard_chain_verify | Verify the full lifecycle chain for a trial or subject, from protocol through submission. |
agentguard_alcoa_audit | Return the 9-attribute ALCOA+ audit grid for any receipt. |
agentguard_pricing | Read live pricing surface. |
agentguard_health | Health probe. |
All eleven tools are live in production. Contact us for MCP integration credentials and the full well-known manifest.
The trial event envelope
Every agentguard_*_attest call returns an envelope with the receipt id, trial id, event kind, subject (USUBJID plus DID), investigator DID, AI agent DID where it applies, protocol version, IRB version hash, the full nine-field ALCOA+ attribute grid, the prior attestation id, the Base 8453 anchor txid, and two signatures (Ed25519 and ML-DSA-65). The signatures cover every field, so any attempt to tamper with it breaks verification.
The envelope is CBOR-canonical, and you can verify it offline against the issuer's published public keys. ML-DSA-65 (NIST FIPS 204, the government's post-quantum signature standard) is the post-quantum signature. Ed25519 (RFC 8032) gives you classical assurance on top. Both have to check out for the receipt to be valid. Receipts stay valid through key rotation using a signed key history, so a 2026 consent still holds up in a 2041 FDA inspection.
What this is not
Setting the right expectations is part of the product. AgentGuard is narrow on purpose.
The horizontal ALCOA+ receipt rail underneath the entire clinical-trial data graph. Sponsors, CROs, sites, IRBs, eTMF, EDC, CTMS, IRT, ePRO, and AI-assisted clinical-operations agents all run cleaner with a dual-signed receipt under each lifecycle transition.
Pricing
| Tier | Unit | Annual band | Fit |
|---|---|---|---|
| Per event | $0.0192 / event | metered, no commitment | Self-serve, any trial scale. Pay per ALCOA+ receipt issued. |
| Volume commit (optional) | from $5,000 / mo | monthly bundle | Bundle events at $0.0192 / event. Overage at the same rate. |
Per-event pricing at $0.0192 / event fits any trial scale, from adaptive Phase I pilots to global Phase III programs. Volume-commit accounts bundle events at the same rate with monthly invoicing. You settle in USDC on Base 8453 through x402. Treasury address 0x15184Bf50B3d3F52b60434f8942b7D52F2eB436E exists. Receipts settle in seconds. Invoicing is monthly, net-30 by default.
Field map
AgentGuard signs every clinical trial lifecycle change twice, and it drops cleanly into existing CDISC SDTM, HL7 FHIR R5, Veeva Vault API, and Medidata Rave API pipelines. Each call accepts the correlation fields below. The envelope travels through standard JSON / CBOR transports using the Hive Receipt primitive.
| Source field | Source standard | Maps to AgentGuard receipt field |
|---|---|---|
USUBJID | CDISC SDTM DM domain | receipt.subject.usubji_d + receipt.subject.did |
STUDYID | CDISC SDTM TS domain | receipt.trial_id |
IECAT | CDISC SDTM IE domain | receipt.eligibility_class |
AEDECOD | CDISC SDTM AE domain | receipt.event.meddra_pt |
EXTRT + EXDOSE + EXSTDTC | CDISC SDTM EX domain | receipt.dosing.{kit_id, dose, administered_at} |
Provenance.recorded | HL7 FHIR R5 Provenance | receipt.alcoa.contemporaneous_anchor_ts |
AuditEvent.agent.who | HL7 FHIR R5 AuditEvent | receipt.alcoa.attributable_did |
Consent.policyRule | HL7 FHIR R5 Consent | receipt.irb_version_hash |
vault__v.api.binder.id | Veeva Vault Clinical API | receipt.etmf_binder_id |
rave.api.subject.audit_uuid | Medidata Rave Web Services | receipt.edc_audit_uuid |
inform.api.transaction_id | Oracle InForm RWS | receipt.edc_audit_uuid |
prior_attestation_id | AgentGuard chain primitive | receipt.prior_attestation_id |
Pair this with HiveComply when SOC 2, HIPAA, GxP, or EU AI Act audits are in scope. HiveComply reads AgentGuard receipts natively. Pair it with Atticus when a product liability or DOJ False Claims Act case turns into litigation.
A real conversation, not a demo black hole
If you are a Head of Data Integrity, VP of Regulatory Affairs, CRO QA Director, or FDA Inspection-Readiness Officer who has already done the math on the cost of a single Form 483 finding and the 15-year retention horizon, the fastest path is a direct note. No qualification gate, no SDR. Steve reads them.
High-volume or negotiated terms? Talk to Steve
Questions buyers actually ask
What does AgentGuard attest?
Every clinical trial state, including protocol, consent, screening, enrollment, dosing, adverse_event, ePRO_capture, CRO_transfer, query_close, database_lock, and submission, gets a receipt signed twice (Ed25519 plus ML-DSA-65) that's ready for a post-quantum world and that an FDA inspector can check offline.
What is ALCOA+ compliance?
ALCOA+ is the FDA's data integrity standard: Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, and Available. AgentGuard receipts are built so every attestation meets all nine attributes from the start.
Does AgentGuard replace Veeva Vault or Medidata Rave?
No. AgentGuard is the post-quantum durability layer underneath Veeva Vault, Medidata Rave, and Oracle InForm. Your existing eTMF and EDC workflows keep running as they are. Every state change also gets a receipt signed twice.
Is AgentGuard 21 CFR Part 11 ready?
Yes. 21 CFR Part 11 requires electronic records and signatures to be trustworthy, reliable, and as good as paper records. AgentGuard receipts, signed twice with Ed25519 and ML-DSA-65, are built to meet that standard with a clear, enforced chain of custody.
How long are signatures valid?
ML-DSA-65 (NIST FIPS 204) is the post-quantum signature. Ed25519 (RFC 8032) gives you classical assurance on top. Both have to check out for the receipt to be valid. Receipts stay checkable for as long as the regulation requires you to keep the trial record.
What does AgentGuard cost?
Per-event pricing for ALCOA+-grade clinical trial receipts. Annual contract pricing for sponsors and CROs. Settlement is in USDC on Base 8453 via x402.
Hive runs the receipt rail underneath the broader A2A · agent-to-agent commerce category.