Zero-knowledge acquisition for decentralized trials

Encrypted at the source.
Standards-native downstream.

mH² is the zero-knowledge data-acquisition and eConsent layer for decentralized trials — capturing wearable signals, digital endpoints and ePRO with a cryptographic provenance spine, on a standards-native path to openEHR, FHIR and CDISC.

Upstream Zero-knowledge capture
Decryption
boundary
Downstream Standards-native

…with a cryptographic provenance spine crossing the boundary.

Speaks
openEHRarchetypes · AQL
HL7 FHIRconsent · observation
CDISCODM → SDTM
ICH E6(R3)ALCOA++ provenance
The architecture

One invariant, four layers.

The hard, expensive part — trustworthy zero-knowledge acquisition — already exists. A semantic gateway then maps encrypted, endpoint-level data to the standards your downstream systems speak. And because a provenance spine links every value to its raw signal, algorithm version and consent, the data isn't only secure — it's fully traceable and reproducible.

L1 · AcquisitionAvailable

Zero-knowledge capture

Wearable signals, ePRO and per-modality consent, encrypted on-device. The server never sees plaintext.

L2 · EndpointsIn progress

Versioned digital endpoints

HRV, sleep, activity and more — derived by versioned, validation-tiered algorithms. Every transformation is traceable.

Decryption boundary · study key
L3 · InteroperabilityOn roadmap

Semantic gateway

openEHR archetypes (EHRbase / AQL) and HL7 FHIR resources. Raw waveforms stay referenced as encrypted blobs; consent travels as computable policy.

L4 · ExchangeOn roadmap

Trial & EHDS-ready bundles

CDISC ODM/SDTM export, and bundles designed to be ingested by EHDS Secure Processing Environments after decryption at the boundary.

The left rail is the provenance spine — each layer's output is versioned, hash-chained and traceable back to the raw signal.

Provenance record

Digital endpointRMSSD = 42 ms
↑ traces back to ↑
Algorithm versionhrv-rmssd@1.4.2
Raw signal · encrypted blobsha256:9f3a…c7
In force at captureconsent v3 · protocol v7

Not only secure — traceable. Every endpoint links to the exact raw signal, algorithm version and consent in force, hash-chained and tamper-evident. Reproducible by construction; ICH E6(R3) ALCOA++.

Standards mapping

DataopenEHRFHIR
Consentversioned, dynamicConsent archetypeConsent
ePROquestionnaire responsesCKM questionnaireQuestionnaireResponse
EndpointsHRV · sleep · gaitOBSERVATIONObservation
Raw waveformECG · IMU · PPGreference (URI)DocumentReference
Provenancesignal → endpointFEEDER_AUDITProvenance

Identifiers indicative — to be confirmed against the international CKM and current HL7 Europe EHDS FHIR IGs.

openEHR and FHIR are complementary, not either/or — persistence and semantics on one side, exchange on the other. Because both need plaintext, the gateway sits after a single, well-defined decryption boundary. We integrate with EDC and downstream trial systems rather than replacing them.

Discuss interoperability
Data capture

Quality starts at capture — on every device.

Digital endpoints are only as trustworthy as the signals beneath them. mH² collects through a native, offline-first app on the participant's own phone and wearables — engineered for real-world studies, not just the clinic.

Native iOS & Android app

One Flutter codebase, native performance. Data is encrypted on-device before anything leaves the phone.

Wearables & sensors

Apple HealthKit, Android Health Connect, BLE wearables and phone IMU — every stream tagged with QC metadata.

Offline-first by design

Records without connectivity and reconciles on reconnect. No lost data in low-signal, in-the-wild settings.

Signal types ECG HRV Accelerometer Gyroscope Sleep Activity Location Voice ePRO
Quality & assurance

Prove the data — don't just collect it.

mH² began with a hard problem in real-world, in-the-wild studies: data you can't fully trust and results you can't reproduce. Assurance is built in from the raw signal up — and it's live today.

Adherence & dropout monitoring Available

See disengagement before it becomes dropout.

Completion and retention are tracked continuously against each participant's protocol. Missing submissions, adherence dips and at-risk participants are surfaced early — while there's still time to intervene, not in the end-of-study post-mortem.

Available

Real-time data quality

A monitoring dashboard flags missing submissions, anomalies and protocol deviations as data arrives — not weeks later.

Available

Signal metrology

Per-stream loss, clock drift, sampling rate and QC flags travel with every signal as PHI-free metadata.

Available

Reproducible by export

Complete study configuration exports as JSON — replicate a setup exactly, share a protocol, or archive it for publication.

Aligned to the V3 framework for digital endpoints

V3 · V3+ aligned

Sensor-based endpoints are only as credible as their evidence. mH² is designed around the three pillars of V3 — Verification, Analytical Validation, Clinical Validation — the accepted framework for evaluating digital measures.

1Verification

Signal captured faithfully

Bench and reference-device checks, with per-stream metrology (loss, drift, rate, QC) carried as metadata on every capture.

2Analytical validation

Metric computed correctly

Endpoints derived by versioned, validation-tiered algorithms — each run tagged with the exact algorithm version that produced it.

3Clinical validation

Metric means what we claim

Each endpoint links to the clinical concept it represents, with the evidence tier recorded per study for review.

Why it holds up: because every endpoint links back to its algorithm version and raw signal through the provenance spine, each V3 claim is auditable end-to-end. V3+ extends the framework with user-centricity and scalability — evidence that a measure works for real participants at real-world scale. Continuous adherence and data-quality monitoring is how mH² keeps that evidence honest in the field.

Framework: Goldsack et al., npj Digital Medicine (2020)  ·  V3+: npj Digital Medicine (2024)