Platform · Compliance plan

Every module, and the records it produces

The Compliance plan in full. For each module: what it does, and what it hands an auditor when they ask.

  • 5 modules
  • Unlimited documents
  • 4 roles
The scope sold today
ISO 13485 §4.2 · 21 CFR 820.40

Document Control

Controlled documents move through enforced states. Only the current approved revision is in circulation, superseded revisions stay retrievable, and the history records every content edit, change request and approval transition.

What it does
  • Lifecycle statesDraft, review, approved, effective, obsolete, with enforced transitions
  • Version controlNew versions route through approval rather than going live directly
  • Approval workflowsConfigurable per document type
  • Periodic reviewScheduled with owner notification
  • Training on effectivityBecoming effective can assign training automatically
Records it produces
  • The current approved revision of any document
  • Complete revision history with approver and date
  • Change requests and their outcomes
  • Who is trained on which revision
ISO 13485 §6.2 · EU GMP Ch. 2

Training Management

Training is tied to the documents and roles that require it, so the matrix stays true as documents change rather than being rebuilt by hand before an audit.

What it does
  • Training matrixRoles mapped to required documents
  • AssignmentTriggered by document effectivity or assigned directly
  • QuizzesPass thresholds with recorded attempts
  • RequalificationRecurring cycles per role or document
  • Trainee seatsRead-and-train access without a full QA seat
Records it produces
  • Completion signed by the trainee, with date
  • Competency evidence retained against the person
  • Outstanding training by role or document
  • Requalification due dates
EU GMP Ch. 1 · ICH Q10

Deviation Management

Deviations are numbered per workspace, risk-assessed at logging, investigated with structured root cause analysis, and dispositioned. Where the investigation warrants it, a CAPA is raised with the linkage preserved.

What it does
  • Sequential numberingDEV-001 onward, scoped to your workspace
  • Risk assessmentClassified at the point of logging
  • Root cause analysisStructured rather than free text
  • Escalation to CAPALinked, without rekeying the investigation
Records it produces
  • The deviation, its risk class and its disposition
  • Investigation and root cause
  • Any CAPA it raised, and that CAPA’s outcome
  • Full attributed timeline
21 CFR 820.100 · ISO 13485 §8.5

CAPA

Corrective and preventive actions carry owned action items and due dates, and cannot close until an effectiveness review is complete. That review is the artefact auditors ask for and the one most commonly missing.

What it does
  • Action itemsNamed owners and due dates
  • Effectiveness reviewRequired before closure
  • Dependency mapAcross every linked record
  • Source linkageBack to the deviation, finding or complaint
Records it produces
  • The CAPA, its actions and their owners
  • Effectiveness review and its verdict
  • What raised it and what it resolved
ISO 13485 §8.2.4 · 21 CFR 820.22

Internal Audits

The audit programme, its plans, checklists and findings, through to closure evidence. External auditors can be given scoped, time-limited access rather than a copy of your quality system.

What it does
  • Audit programmeAnnual schedule with planned audits
  • ChecklistsExecuted against the plan
  • FindingsClassified, assigned and tracked to closure
  • Findings raise CAPAsWith linkage preserved
  • External auditor accessScoped and time-limited
Records it produces
  • The audit programme and its execution
  • Findings, owners and closure evidence
  • CAPAs raised from findings
An empty cleanroom gowning airlock corridor with a sealed interlock door

Controlled access. Four roles, tenant-isolated. An external auditor sees only what you scope to them.

Across every module

What holds regardless of which module you are in

ControlSpecificationStatus
Electronic signatures21 CFR Part 11, with meaning statementsIncluded
Signature invalidationSoft-invalidation with reason; never hard-deletedIncluded
Audit trailAppend-only, attributed, timestampedIncluded
Tenant isolationEvery query scoped; cross-tenant access impossible by constructionIncluded
AuthenticationPasswordless one-time code by emailIncluded
RolesAdmin, QA Team, User, Auditor — all tenant-scopedIncluded
Data exportFull export in open formats, on request and on exitIncluded
Retention10 years post decommission by defaultIncluded
Summary

The five modules at a glance

Document Control

ISO 13485 §4.2

Enforced revision history, approval workflows and effective dates. Only the current approved version circulates; every superseded one stays retrievable.

Training Management

ISO 13485 §6.2

Role-based matrices, assignment straight from a controlled document, quizzes, and requalification tracked per person.

Deviation Management

EU GMP Ch. 1

Logged, risk-assessed, investigated and dispositioned, with a controlled path into CAPA when the investigation warrants one.

CAPA

21 CFR 820.100

Owned action items, due dates, and an effectiveness review that must complete before closure.

Internal Audits

ISO 13485 §8.2.4

Programme planning, checklists, findings and closure evidence. Findings raise CAPAs directly; external auditors get scoped access.

Early access

Put your name to it

Tell us who you are and we will be in touch before the trial opens.

We use this to contact you about access. No newsletter, no third parties.

We use analytics cookies (page views, clicks, scroll and mouse movement) to understand how visitors use this site. Nothing is tracked until you accept. See our Cookie Notice for what each cookie is for.