Trust · posture

What we claim, and what we can prove

A vendor’s compliance badges are not your compliance. This page states our position on each standard the way you would read a result against a specification.

  • UK/EU hosted
  • AES-256 at rest
  • 10-year retention
Statuses per Trust CentreSheet 4
Standards

Standard, requirement, status

Status definitions: self-attested means documented controls with no third-party audit completed. In progress means controls are partially or fully in place and validation has not completed. Nothing here is third-party validated yet, and we will change these rows the day that changes.

StandardWhat it requiresOur status
21 CFR Part 11Electronic records and electronic signaturesSelf-attested
GDPRLawful processing, minimisation, right to erasureSelf-attested
ISO 13485Quality management for medical devicesControls in place, validation in progress
ISO 9001General quality management frameworkControls in place, validation in progress
EU GMPGood Manufacturing Practice for medicinal productsControls in place, validation in progress
Ethics and supply chainAnti-bribery, modern slavery and supplier conduct commitmentsPolicy published, self-attested
Cookies PolicyConsent for non-essential cookies and a published cookie inventoryPolicy published, self-attested
Notes
  1. Self-attested means we conform to the standard’s requirements with documented controls. No third-party audit has completed. We publish this rather than badge it, because you are the one who has to defend the choice.
  2. Nothing on this site claims certification. A vendor who tells you their software is "ISO 13485 certified" is describing their own company, not your compliance.
  3. Tenant data is hosted in the UK/EU. Encryption is AES-256 at rest and TLS 1.2 or higher in transit. Default record retention is 10 years post decommission.
  4. The full sub-processor list, data-flow routing and DPA links are published in the Trust Centre and updated before any new sub-processor is onboarded.
Security

Controls, as specifications

ControlSpecificationStatus
Encryption at restAES-256 via managed KMSIn place
Encryption in transitTLS 1.2 or higher on every public endpointIn place
Data residencyTenant data hosted in the UK/EUIn place
Audit trailAppend-only, tenant-isolated, per 21 CFR Part 11 §11.10(e)In place
Signature integritySoft-invalidation with reason; never hard-deletedIn place
Retention10 years post decommission, configurable upwardIn place
Data exportFull export in open formats on request and on exitIn place
Dependency scanningAudit gates on every pull request; critical CVEs block mergeIn place
Third-party auditIndependent attestation of the aboveNot yet
Public status pageIncident history and uptimePlanned

Where a row says not yet or planned, that is the honest state. We would rather you find it here than discover it during qualification.

A quality control laboratory bench at night, instruments dark and idle

Qualification. Your auditor will ask us the same questions you do. We keep the answers packaged.

Validation

What we hand your qualification process

Under ISO 13485 §7.4 and EU GMP Chapter 7 you have to qualify us as a supplier of a GxP-critical service. That work is real, and it is usually where a software purchase stalls. We keep it packaged rather than improvised.

Validation package

IQ/OQ/PQ for the platform, a validation summary, and 21 CFR Part 11 / EU Annex 11 documentation.

Supplier qualification pack

Pre-completed questionnaire, quality manual, SDLC description, security and business-continuity documentation, insurance certificates.

Supplier audits

Accepted by arrangement.

Data return

A defined retention-and-return window agreed in the Quality Agreement.

Notes
  1. This page is a summary. The authoritative version, including the full sub-processor table with data flows and DPA links, is published in the Trust Centre and updated before any new sub-processor is onboarded.
  2. Data-subject requests and GDPR queries go to dpo@innoqualis.com. General compliance questions go to compliance@innoqualis.com.
  3. No public-facing incidents to date. Incidents affecting customer data, availability or compliance posture will be published within 72 hours of resolution.

We use analytics cookies (page views, clicks, scroll and mouse movement) to understand how visitors use this site. Nothing is tracked until you accept. See our Cookie Notice for what each cookie is for.