Pharma and biotech
21 CFR Part 11 · EU Annex 11 · GAMP 5
Signature meanings, batch record approvals, and validation documentation for GxP processes, from the lab bench to release.
Compliance
Every claim on this page maps to something your quality or compliance team can test in a trial account, whether your examiner is the FDA, FINRA, the SEC, or your own internal audit group. That is the difference between a compliance badge and a compliant product.
Here is where each requirement lives in the product, in the same order your auditor will ask about it.
Part 11 is the strictest e-signature standard in the world, so we built to it first. The same controls carry your obligations in every other regulated industry.
21 CFR Part 11 · EU Annex 11 · GAMP 5
Signature meanings, batch record approvals, and validation documentation for GxP processes, from the lab bench to release.
SEC 17a-4 · FINRA 4511 · SOX 302 and 404
Immutable, time-stamped records that satisfy books-and-records retention, plus attestation trails your external auditors can rely on.
ICH GCP · 21 CFR Part 11 · HIPAA
Investigator signatures, delegation logs, and consent records with evidence your sponsor and IRB can inspect at any time.
ESIGN and UETA · State e-sign laws · NAIC guidance
Enforceable policyholder signatures with consent capture, identity evidence, and a defensible record if a claim ends up in court.
HIPAA · 21 CFR 820 · EU MDR
Encrypted handling for PHI, design history file approvals, and supplier agreements that stand up in an FDA or notified body audit.
NERC CIP · FERC · State PUC rules
Authorization records, switching orders, and compliance attestations with proof of who approved what, and exactly when.
Every event links to the one before it through a SHA-256 hash chain. Change a single byte anywhere in the history and the chain breaks, visibly, for everyone. That protection covers your own admins, and it covers us.
Short answers to the questionnaire, before they ask.
AES-256 at rest, TLS 1.3 in transit, and envelope-level keys. Documents are never readable by anyone outside your account, including our own engineers.
Choose your data region at signup. Records never leave it, backups included, and residency is documented for your data protection assessments.
Set retention and legal hold per document type, from one year to forever. When a record must be destroyed, the destruction itself is an audit event.
Redundant infrastructure across availability zones, continuous backups, and a published status page. Your signing deadlines do not wait for ours.
The hardest room to win is the one we built this for. Bring your QA lead to the demo and let them try to break the audit trail.