Standard, requirement, status
Status definitions: self-attested means documented controls with no third-party audit completed. In progress means controls are partially or fully in place and validation has not completed. Nothing here is third-party validated yet, and we will change these rows the day that changes.
| Standard | What it requires | Our status |
|---|---|---|
| 21 CFR Part 11 | Electronic records and electronic signatures | Self-attested |
| GDPR | Lawful processing, minimisation, right to erasure | Self-attested |
| ISO 13485 | Quality management for medical devices | Controls in place, validation in progress |
| ISO 9001 | General quality management framework | Controls in place, validation in progress |
| EU GMP | Good Manufacturing Practice for medicinal products | Controls in place, validation in progress |
| Ethics and supply chain | Anti-bribery, modern slavery and supplier conduct commitments | Policy published, self-attested |
| Cookies Policy | Consent for non-essential cookies and a published cookie inventory | Policy published, self-attested |
- Self-attested means we conform to the standard’s requirements with documented controls. No third-party audit has completed. We publish this rather than badge it, because you are the one who has to defend the choice.
- Nothing on this site claims certification. A vendor who tells you their software is "ISO 13485 certified" is describing their own company, not your compliance.
- Tenant data is hosted in the UK/EU. Encryption is AES-256 at rest and TLS 1.2 or higher in transit. Default record retention is 10 years post decommission.
- The full sub-processor list, data-flow routing and DPA links are published in the Trust Centre and updated before any new sub-processor is onboarded.
Controls, as specifications
| Control | Specification | Status |
|---|---|---|
| Encryption at rest | AES-256 via managed KMS | In place |
| Encryption in transit | TLS 1.2 or higher on every public endpoint | In place |
| Data residency | Tenant data hosted in the UK/EU | In place |
| Audit trail | Append-only, tenant-isolated, per 21 CFR Part 11 §11.10(e) | In place |
| Signature integrity | Soft-invalidation with reason; never hard-deleted | In place |
| Retention | 10 years post decommission, configurable upward | In place |
| Data export | Full export in open formats on request and on exit | In place |
| Dependency scanning | Audit gates on every pull request; critical CVEs block merge | In place |
| Third-party audit | Independent attestation of the above | Not yet |
| Public status page | Incident history and uptime | Planned |
Where a row says not yet or planned, that is the honest state. We would rather you find it here than discover it during qualification.

Qualification. Your auditor will ask us the same questions you do. We keep the answers packaged.
What we hand your qualification process
Under ISO 13485 §7.4 and EU GMP Chapter 7 you have to qualify us as a supplier of a GxP-critical service. That work is real, and it is usually where a software purchase stalls. We keep it packaged rather than improvised.
Validation package
IQ/OQ/PQ for the platform, a validation summary, and 21 CFR Part 11 / EU Annex 11 documentation.
Supplier qualification pack
Pre-completed questionnaire, quality manual, SDLC description, security and business-continuity documentation, insurance certificates.
Supplier audits
Accepted by arrangement.
Data return
A defined retention-and-return window agreed in the Quality Agreement.
- This page is a summary. The authoritative version, including the full sub-processor table with data flows and DPA links, is published in the Trust Centre and updated before any new sub-processor is onboarded.
- Data-subject requests and GDPR queries go to dpo@innoqualis.com. General compliance questions go to compliance@innoqualis.com.
- No public-facing incidents to date. Incidents affecting customer data, availability or compliance posture will be published within 72 hours of resolution.