Identity.
Enrolled once. Confirmed every time.
For a result to count, you have to know whose sample it is. Identity enrols everyone once (businesses in Pulse, people in Flow) then confirms the person afresh at every collection, and keeps the patient in control of the data a sample produces. The yes itself is a signed act, and signing is its own module; what lives here is the identity it rests on, and the standing record of who may see what.
The patient owns
their data.
The person who gives the sample owns the data it produces. They grant access to a laboratory, a clinician or a partner, and they can revoke it. Consent is recorded, scoped and auditable (not a checkbox buried in terms, but a standing record of who may see what, and on what basis). That is what makes remote collection something a patient can trust and a partner can defend.
Portable, patient-owned provenance tied to a real person, the layer that is hardest to copy.
Enrolled once.
Confirmed at every collection.
Two moments, one capability. Enrolment collects licence and documents, checks credentials and resolves jurisdiction eligibility (businesses in Pulse, people in Flow). Then, at every collection, a fresh liveness confirmation binds a specific human to a specific tube. That second moment is the one decentralised diagnostics never solved: transit tracking is solved and anyone can buy it, and this is the hard one.
The check is never repeated downstream (it is relied upon). A practice that adds a laboratory is not re-verified; a practitioner who changes employer takes their enrolment with them, licence, scope and all.
What Pulse asks, and why.
For a business, enrolment is verification rather than a form (because money will move on the operator&rsquo);s name. A laboratory or partner proves itself once, to the standard a licensed European payment institution requires, and everything after that is already trusted.
- The identity document of the legal representative: the person who signs is real: passport, identity card, or permit.
- The business registration extract (the entity exists as filed, under the name that will transact).
- The ultimate-beneficial-owner declaration (whoever holds more than a quarter of the company, named); when nobody does, one stakeholder designated in their place.
- An organisational chart, when a company owns the company (the ownership structure made legible, not inferred).
- The licence the work requires (for a laboratory, its accreditation); the proof the activity is permitted at all.
- The account that receives settlements (so money lands only where it should, from the first payment on).
The screening behind it (registers, sanctions lists, the checks anti-money-laundering law demands) is carried by the platform, so an operator proves these things once instead of separately to every counterparty. Nothing transacts on an unverified name.
The same story, on screen.
This is what the operator actually watches: the dossier’s items checking off one by one, the status flipping the moment review completes, and the account switching to transacting (no email thread, no asking whether it went through).
The person’s side of the same story.
One app, and three moments that take seconds each: agree and pay once (the price on screen before the yes) confirm it is really you when the sample is taken, and hold the consent you granted where you can see it, and revoke it.
One proofing event, two uses.
Consent is closer to Sign than to anything else: the yes is captured as a signed event against a proved identity (specific, visible to the patient, and withdrawable). The same holds for a report, a prescription, a contract. The standard rises with what is being signed, and recognition is jurisdictional, so signature routes per market and per document type rather than promising one signature everywhere. Signature is not a second enrolment; it is Identity’s other output: and what remains HERE is the standing record that consent produces: who may see what, on what basis, revocable by the person who gave it.
Three guarantees.
As trustworthy
as the clinic.
The clinic earns trust through presence: a known patient, a known phlebotomist, a sample that never leaves the chain. Remote collection has to earn the same trust without the room. Identity & consent supplies the missing assurances, who, with what permission, and a provenance you can verify.
Anti-substitution rigor: the sample is matched to a verified identity, so it cannot be quietly swapped for someone else’s.
Consent is captured and scoped, so the use of a result always maps to something the patient agreed to.
An unbroken chain of custody means the journey from doorstep to laboratory can be audited end to end.
GDPR-native, by design.
Data protection is not bolted on. Identity & consent is GDPR-native: the patient is the data subject and the one in control, consent is recorded and revocable, and access is governed by the permission the patient grants. European-owned and built to European rules, so trust and compliance hold in the same motion.
Whoever relies on the result.
Good to know.
Who owns the patient’s data?
The patient. The person who gives the sample owns the data it produces, grants access to the parties who need it, and can revoke that access. Consent is recorded, scoped and auditable.
How is a remote sample matched to the right person?
Every collection is matched to a verified identity at the moment of collection, so the sample is tied to a known person from the start, giving a home-collected sample the same identity rigor as one taken in clinic.
What is verifiable provenance?
An unbroken, auditable chain of custody from collection to laboratory accessioning, with the sample’s identity travelling alongside it. It lets a result be tied back to the right person and the right consent.
How does this support trial integrity?
By providing anti-substitution rigor: because each sample is matched to a verified person, it cannot be quietly swapped, which is essential for CROs and pharma running decentralised trials.
What is the difference between enrolment and confirmation?
Enrolment happens once (licence, documents, credentials, jurisdiction eligibility); businesses in Pulse and people in Flow. Confirmation happens at every collection: a fresh liveness check that binds the person in front of the kit to the sample being taken. Two moments, one capability (and the second is the one that multiplies).
What does a business need to enrol in Pulse?
Six things, once: the identity document of the legal representative, the business registration extract, the ultimate-beneficial-owner declaration (anyone above a quarter of ownership: or a designated stakeholder when nobody is), an organisational chart where a company owns the company, the licence the activity requires, and the account that receives settlements. The status then moves from submitted through review to verified (and nothing transacts before it does).
Do practitioners enrol too?
Yes: once, as themselves: licence, scope, and where they are permitted to work. At the draw they confirm the patient in front of them against an enrolment already made, in seconds. The enrolment travels with them if they change employer.
Is it GDPR-compliant?
It is GDPR-native. The patient is the data subject and the one in control, consent is recorded and revocable, and access is governed by the permission the patient grants.
Enrolled once.
Confirmed every time.
Identity here is two moments, one capability (and the second is the one decentralised diagnostics never solved).
- The business, enrolled onceEntity, accreditation, licence and settlement details, in Pulse.
- The person, enrolled onceThe patient, and every practitioner who collects, in Flow.
- A fresh confirmation at every collectionLiveness, against the enrolment already made (seconds, not a new check).
- The result, released against that same identityWhat makes it yours and nobody else’s.
Trust the sample.
Talk to us about verified identity, recorded consent and verifiable provenance for your programme.