Early access · Compliance plan

The quality system you can hand to an inspector

Documents, training, deviations, CAPA and internal audits in one record. Signed under 21 CFR Part 11, on an audit trail nobody can edit.

  • Built to ISO 13485
  • 21 CFR Part 11
  • EU GMP
  • UK/EU hosted
The Compliance plan, as sold today7 of 7 included
DocumentsVersioning, review, approval, effectivityIncluded
TrainingMatrices, assignment, quizzes, requalificationIncluded
DeviationsLogging, risk, investigation, dispositionIncluded
CAPAActions, owners, effectiveness reviewIncluded
Internal auditsProgramme, checklists, findings, closureIncluded
E-signatures21 CFR Part 11, soft-invalidationIncluded
Audit trailAppend-only, tenant-isolatedIncluded
Compliance plan£1,250/month · 12-month term30-day trial · no cardUK/EU hosted
The problem

Audits are not failed on the quality of your work

They are failed on whether you can prove it. The work gets done. The evidence just is not kept in a form anyone can inspect.

Fragmented

SOPs in SharePoint, approvals in email, training in a spreadsheet.

Unversioned

Nobody is sure which revision is current until someone notices it was not.

Unprovable

The record exists. The trail of who changed what, when, and on whose authority does not.

Rebuilt each audit

Weeks spent reconstructing evidence that should have been a by-product of the work.

A long row of identical archive binders on steel shelving, receding into shadow

The status quo. Ten years of retention obligation, held in a room nobody can query.

How it holds together

One record, and everything it triggers

Not separate products bolted together. This is the chain an inspector follows.

  1. Deviation raised

    DEV-014

    Logged, numbered, risk-assessed and owned in the system, not in an inbox.

  2. Investigation

    DEV-014 / RCA

    Root cause recorded against the deviation. Every edit attributed and timestamped.

  3. CAPA

    CAPA-007

    Raised from the investigation with named owners and due dates, linked to source.

  4. Effectiveness verified

    CAPA-007 / EFF

    The CAPA cannot close until this is done. It is the evidence auditors ask for.

The same chain runs from an audit finding. Every step attributed, timestamped, append-only.

Modules

The five modules in the Compliance plan

Each ships complete. None is a placeholder for a later release.

Document Control

ISO 13485 §4.2

Enforced revision history, approval workflows and effective dates. Only the current approved version circulates; every superseded one stays retrievable.

Training Management

ISO 13485 §6.2

Role-based matrices, assignment straight from a controlled document, quizzes, and requalification tracked per person.

Deviation Management

EU GMP Ch. 1

Logged, risk-assessed, investigated and dispositioned, with a controlled path into CAPA when the investigation warrants one.

CAPA

21 CFR 820.100

Owned action items, due dates, and an effectiveness review that must complete before closure.

Internal Audits

ISO 13485 §8.2.4

Programme planning, checklists, findings and closure evidence. Findings raise CAPAs directly; external auditors get scoped access.

Glass vials on a stainless conveyor inside an aseptic filling isolator

Where it matters. Every record in the system exists because something physical depended on it.

Pricing

What it costs, published

Everyone else in this market makes you book a call. Here is the number.

Compliance

Available now

The entry plan, and the whole product today.

£1,250/month

on a 12-month term (£15,000/year)

£1,330/month on a 6-month term

Seats
5 QA + 15 trainees
Documents
Unlimited
  • Dashboard, My Tasks and Calendar
  • Document control
  • Training management
  • Deviation management
  • CAPA
  • Internal audits
  • 21 CFR Part 11 electronic signatures
  • Immutable audit trail
  • Read-only AI help assistant
  • Extra trainee seats at £15/seat/month
Request early access

Growth

Not on sale yet

The supplier-facing and equipment side. Named so you can plan; not on sale yet.

Seats
12 QA + 40 trainees
Documents
Unlimited
  • Everything in Compliance
  • Change control
  • Equipment and calibration
  • Supplier management
  • SCARs
  • Complaints
  • Regulatory checks
  • AI Compliance Officer actions

Enterprise

Not on sale yet

Analytics, SSO and custom frameworks, with an MSA, DPA and SLA.

Seats
Unlimited
Documents
Unlimited
  • Everything in Growth
  • Analytics
  • Document templates
  • Validation package generators
  • SSO
  • Custom regulatory frameworks
Notes
  1. There is deliberately no monthly plan. The 30-day free trial is how you evaluate, and it takes no card.
  2. Terms are prepaid 6 or 12 months and renew automatically unless cancelled with written notice before renewal.
Compliance posture

Where we actually stand

A result against a stated specification. You are the one who has to defend this to a notified body, so here it is unvarnished.

StandardWhat it requiresOur status
21 CFR Part 11Electronic records and electronic signaturesSelf-attested
GDPRLawful processing, minimisation, right to erasureSelf-attested
ISO 13485Quality management for medical devicesControls in place, validation in progress
ISO 9001General quality management frameworkControls in place, validation in progress
EU GMPGood Manufacturing Practice for medicinal productsControls in place, validation in progress
Ethics and supply chainAnti-bribery, modern slavery and supplier conduct commitmentsPolicy published, self-attested
Cookies PolicyConsent for non-essential cookies and a published cookie inventoryPolicy published, self-attested
Notes
  1. Self-attested means we conform to the standard’s requirements with documented controls. No third-party audit has completed. We publish this rather than badge it, because you are the one who has to defend the choice.
  2. Nothing on this site claims certification. A vendor who tells you their software is "ISO 13485 certified" is describing their own company, not your compliance.
Questions

The questions a quality lead actually asks

Are you certified to ISO 13485?

No, and no software vendor’s certificate would make you compliant anyway. Our controls are in place and third-party validation is in progress; 21 CFR Part 11 and GDPR are self-attested today. The Trust Centre states the position for each standard, and we would rather you read it before you buy than after.

What do I get for supplier qualification?

A supplier-qualification pack: a pre-completed supplier questionnaire, our quality manual and SDLC description, security and business-continuity documentation, and insurance certificates. We also accept supplier audits by arrangement.

Do you provide validation documentation?

Yes. An IQ/OQ/PQ package for the platform, a validation summary, and 21 CFR Part 11 / EU Annex 11 documentation, delivered as a one-off onboarding package. It is quoted separately because it is genuine recurring work on our side and a mandatory artefact on yours.

Where is our data held, and can we get it back?

Tenant data is hosted in the UK/EU, encrypted with AES-256 at rest and TLS 1.2 or higher in transit. A full export in open formats is available on request at any time and on exit. Default retention is 10 years post decommission.

Early access

Put your name to it

We are taking a small number of first customers so onboarding is done properly.

We use this to contact you about access. No newsletter, no third parties.

We use analytics cookies (page views, clicks, scroll and mouse movement) to understand how visitors use this site. Nothing is tracked until you accept. See our Cookie Notice for what each cookie is for.