Document Control
Enforced revision history, approval workflows and effective dates. Only the current approved version circulates; every superseded one stays retrievable.
Documents, training, deviations, CAPA and internal audits in one record. Signed under 21 CFR Part 11, on an audit trail nobody can edit.
They are failed on whether you can prove it. The work gets done. The evidence just is not kept in a form anyone can inspect.
SOPs in SharePoint, approvals in email, training in a spreadsheet.
Nobody is sure which revision is current until someone notices it was not.
The record exists. The trail of who changed what, when, and on whose authority does not.
Weeks spent reconstructing evidence that should have been a by-product of the work.

The status quo. Ten years of retention obligation, held in a room nobody can query.
Not separate products bolted together. This is the chain an inspector follows.
Logged, numbered, risk-assessed and owned in the system, not in an inbox.
Root cause recorded against the deviation. Every edit attributed and timestamped.
Raised from the investigation with named owners and due dates, linked to source.
The CAPA cannot close until this is done. It is the evidence auditors ask for.
The same chain runs from an audit finding. Every step attributed, timestamped, append-only.
Each ships complete. None is a placeholder for a later release.
Enforced revision history, approval workflows and effective dates. Only the current approved version circulates; every superseded one stays retrievable.
Role-based matrices, assignment straight from a controlled document, quizzes, and requalification tracked per person.
Logged, risk-assessed, investigated and dispositioned, with a controlled path into CAPA when the investigation warrants one.
Owned action items, due dates, and an effectiveness review that must complete before closure.
Programme planning, checklists, findings and closure evidence. Findings raise CAPAs directly; external auditors get scoped access.

Where it matters. Every record in the system exists because something physical depended on it.
Everyone else in this market makes you book a call. Here is the number.
The entry plan, and the whole product today.
on a 12-month term (£15,000/year)
£1,330/month on a 6-month term
The supplier-facing and equipment side. Named so you can plan; not on sale yet.
Analytics, SSO and custom frameworks, with an MSA, DPA and SLA.
A result against a stated specification. You are the one who has to defend this to a notified body, so here it is unvarnished.
| Standard | What it requires | Our status |
|---|---|---|
| 21 CFR Part 11 | Electronic records and electronic signatures | Self-attested |
| GDPR | Lawful processing, minimisation, right to erasure | Self-attested |
| ISO 13485 | Quality management for medical devices | Controls in place, validation in progress |
| ISO 9001 | General quality management framework | Controls in place, validation in progress |
| EU GMP | Good Manufacturing Practice for medicinal products | Controls in place, validation in progress |
| Ethics and supply chain | Anti-bribery, modern slavery and supplier conduct commitments | Policy published, self-attested |
| Cookies Policy | Consent for non-essential cookies and a published cookie inventory | Policy published, self-attested |
No, and no software vendor’s certificate would make you compliant anyway. Our controls are in place and third-party validation is in progress; 21 CFR Part 11 and GDPR are self-attested today. The Trust Centre states the position for each standard, and we would rather you read it before you buy than after.
A supplier-qualification pack: a pre-completed supplier questionnaire, our quality manual and SDLC description, security and business-continuity documentation, and insurance certificates. We also accept supplier audits by arrangement.
Yes. An IQ/OQ/PQ package for the platform, a validation summary, and 21 CFR Part 11 / EU Annex 11 documentation, delivered as a one-off onboarding package. It is quoted separately because it is genuine recurring work on our side and a mandatory artefact on yours.
Tenant data is hosted in the UK/EU, encrypted with AES-256 at rest and TLS 1.2 or higher in transit. A full export in open formats is available on request at any time and on exit. Default retention is 10 years post decommission.
We are taking a small number of first customers so onboarding is done properly.
We use analytics cookies (page views, clicks, scroll and mouse movement) to understand how visitors use this site. Nothing is tracked until you accept. See our Cookie Notice for what each cookie is for.