For IT and procurement
Validation and security
The answers your reviewers ask for, in progress included.
Compliance posture
Status and date, not badges; evidence under NDA.
| Control | Status | Evidence |
|---|---|---|
| 21 CFR Part 11 §11.50 e-signature | Enforced | Content hash, signer IP, user-agent, signature meaning |
| GxP audit trail | Enforced | Every state change with before/after, actor, IP |
| 21 CFR 314.81 Field Alert clock | Enforced | Auto 3-day clock on critical deviations |
| 21 CFR 803 Medical Device Reports | Enforced | Auto 5/15/30-day clocks on complaints |
| GDPR and EU data residency | Available | EU region, SCCs, right-to-erasure workflow |
| EU GMP Annex 11 | In progress | Documentation drafted, validation report Q3 2026 |
| SOC 2 | Type I complete | Type II audit Q3 2026, report Q1 2027 |
| ISO 27001 | In progress | Pre-certification audit Q4 2026 |
| HIPAA BAA | Conditional | Hybrid and private cloud from Q4 2026 |
Isolation and controls
- Tenant isolation at query build
- Every query is tenant-scoped at build; no path bypasses it.
- Storage isolation
- Per-tenant S3 prefix with IAM deny across tenants; row-level security in Postgres.
- Data residency
- US or EU region selected at contract; file storage follows the database.
- Encryption
- TLS in transit, SSE at rest, managed keys.
- AI boundary controls
- PII redacted pre-prompt, per-call permission checks, prompt-injection guards.
- Complete audit trail
- Universal collection capturing actor, IP, user-agent and before/after snapshots.
Request the evidence pack
Architecture, controls and validation documentation under NDA.