Consent Governance · Arxova

Verifiable, Patient-Owned Research Consent: How Arxova's Consent Governance Works

Every clinical study runs on consent, yet most consent records are fragile. A signed PDF sits on a file server, and years later — when an auditor or IRB asks for proof that a specific participant agreed to a specific version of a protocol on a specific date — teams scramble.

Arxova's Consent Governance closes that gap. It captures research consent as a tamper-evident record the moment it's given, keeps a retrievable copy of the exact document the participant signed, and lets either one be verified long after a study wraps. Teams integrate it through the Consent SDK and API; the governance is the product, the SDK is how you connect it to a flow you already run.

It is in production today, running on the same encrypted infrastructure that already protects patient records inside the Arxova platform. If your team runs studies and needs consent records that hold up under scrutiny, this is built for you.

Illustration of a tamper-evident consent receipt anchored on-chain

Key Takeaways

  • Each consent generates a cryptographic receipt, recorded on-chain, that carries no names, emails, or personal data — only a document hash and a study identifier.
  • The signed document is encrypted and stored separately, retrievable on demand and checkable against its receipt to confirm nothing has changed.
  • Withdrawal is recorded the same way consent is: timestamped and independently verifiable at any future point.
  • Participants never touch a wallet or handle crypto — everything is provisioned behind the login they already use.

What Consent Governance Proves

Most e-consent tools can show a log entry that says "consent given." Far fewer can prove, years later, what the participant agreed to and that it hasn't been altered since. Arxova is built to prove three things independently of any single database, vendor, or staff member.

That consent happened. When someone consents, the system writes a cryptographic receipt to the blockchain. That receipt holds only opaque references — a document hash and a study identifier — enough to confirm a specific consent event at a specific time, and nothing that reveals who the participant is. The record carries no privacy risk even if the ledger is public, and anyone holding the receipt can confirm the event without trusting an administrator's word for it.

What was signed. Separately, the exact document the participant read and signed is encrypted and stored. When an IRB review, sponsor inspection, or regulatory request comes up, the original is retrieved and checked against the on-chain hash. If they match, you have proof the document is byte-for-byte what the participant saw. If a mid-trial amendment changed the consent language, each version has its own receipt, so there is no ambiguity about which version applied to which participant.

When it was withdrawn. Consent isn't permanent, and the record reflects that. A withdrawal is logged on-chain and timestamped, so the answer to "was this participant enrolled and consenting on this date?" is a verifiable sequence of events — consent, then withdrawal if it happened — not a buried email thread or a spreadsheet edit history.

The signed consent document encrypted and verifiable against its on-chain hash

How It Works

The mechanics stay in the background, so participants and site staff never deal with blockchain concepts directly.

  1. The participant consents inside your existing flow. No wallet setup, no crypto onboarding — a wallet is provisioned invisibly behind the login they already use.
  2. A receipt is recorded, and the transaction cost is sponsored. The participant pays nothing and never sees a gas fee or an approval prompt.
  3. The signed document is sealed. It's encrypted, stored, and linked to the receipt through its hash, with decryption keys held by the patient via Lit Protocol.
  4. Verify or retrieve at any time. Confirm the record's integrity, or pull the original document for an audit, an IRB request, or a sponsor inspection.

Because the participant-facing experience barely changes from a standard e-consent flow, adoption doesn't require retraining staff or asking participants to learn new tools.

Built on Infrastructure Already in Production

This is not a standalone pilot. It runs on the same stack that powers Arxova's patient platform, where wearable data, lab results, and medical records live in an encrypted vault the patient controls — the same client-side encryption, decentralized storage, and on-chain verification, applied to research consent. The security architecture keeps every access event auditable without exposing the underlying records. Practically, that means the technology behind these consent records is already handling sensitive health data for real patients today, rather than being built from scratch.

Who It's For

Consent Governance is aimed at organizations that need consent records to survive scrutiny long after a study ends:

  • CROs running multi-site trials that need consistent, auditable consent across sites with different staff and workflows.
  • Study sponsors who must show regulators that consent was properly obtained and never altered.
  • Academic and medical research groups under IRB oversight, where audit trails matter for both ethics review and publication integrity.
  • Site networks managing consent across multiple locations that need a single, reliable source of truth.

This reflects how Arxova approaches research more broadly: patient-owned and patient-consented, partnering with institutions where participants enroll under IRB-approved consent, and supporting real-world data collection without ever selling participant data or acting as a data broker.

Research teams — CROs, sponsors, and IRB-governed groups — Consent Governance is built for

Where It Stands Today

The infrastructure is live on Solana mainnet and already handling production consent workflows tied to patient health data. Arxova is onboarding a small group of early partners to shape the integration around real study requirements — early partners have direct input into how it fits their existing workflows. If you're rethinking how participant consent gets captured, proven, and audited across multiple sites, this is the stage to get involved.

FAQ

Does the on-chain receipt expose any participant information?

No. Receipts hold only opaque references — a hash and a study identifier — never a name, email, or other identifying detail.

Do participants need a crypto wallet?

No. A wallet is provisioned automatically behind their existing login. They never see wallet setup, gas fees, or blockchain confirmations.

Can we retrieve the original signed document years after a study ends?

Yes. The encrypted document is stored and retrievable on demand, and its hash can be checked against the receipt to confirm it hasn't changed since the day it was signed.

What happens when a participant withdraws?

The withdrawal is recorded the same way as the original consent: on-chain, timestamped, and independently verifiable.

Is this live, or still in development?

It's live on Solana mainnet and running in production for patient health data. Arxova is currently onboarding early partners to integrate it into specific study workflows.

Conclusion

Research consent shouldn't depend on trusting that a file wasn't quietly edited or that a database log is complete. Arxova's Consent Governance gives CROs, sponsors, and research institutions a way to prove consent happened, prove what was signed, and prove when it was withdrawn — without exposing participant data in the process, and on infrastructure already protecting real patient records today.

If your team is rethinking how consent gets captured, proven, and audited, reach out to learn about early access and see how the integration could fit your existing study workflows.

Request access

Tell us about your organization and what you're trying to solve. We'll reply within a few business days.

Arxova provides consent and audit infrastructure. It is not a research organization and does not conduct research or provide regulatory, legal, or IRB approval. Consent receipts contain no participant identifying information; consent documents are encrypted at rest. Integration terms and compliance scope are discussed directly with prospective partners.