Compliance

Don't take our word for it. Verify it.

Every claim on this page maps to something your quality or compliance team can test in a trial account, whether your examiner is the FDA, FINRA, the SEC, or your own internal audit group. That is the difference between a compliance badge and a compliant product.

21 CFR Part 11, mapped clause by clause.

Here is where each requirement lives in the product, in the same order your auditor will ask about it.

RequirementWhat the regulation asksHow SignerNest answers
§11.10(a) Systems must be validated for accuracy and reliability. An IQ and OQ validation pack ships with every release, alongside a change summary for periodic review.
§11.10(b) Accurate and complete copies in human-readable and electronic form. Every envelope exports as a certified PDF plus machine-readable JSON, with the full evidence chain embedded.
§11.10(d) System access limited to authorized individuals. SSO and SAML, MFA, and role-based permissions. Access changes are themselves audit events.
§11.10(e) Computer-generated, time-stamped audit trails. Every event is recorded automatically, time-stamped in UTC, and hash-chained. No one can edit the trail, including us.
§11.50 Signed records must show the signer, date and time, and meaning. Printed name, timestamp, and signature meaning render on the record itself and in every copy.
§11.70 Signatures must be linked to their records and impossible to excise or copy. Each signature is cryptographically bound to the record hash. Moving it to another document is mathematically impossible.
§11.100 Each electronic signature must be unique to one individual. Identity is verified before an account signs anything, and credentials are never shared or reissued to another person.
§11.200 Signatures require at least two identification components. Signers re-authenticate at the moment of signing, every time, with their IdP credentials plus a second factor.
§11.300 Controls for identification codes and passwords. Credential lifecycle, aging, and loss management run through your identity provider, or SignerNest's built-in controls.
21 CFR Part 11
EU Annex 11
GAMP 5 aligned
ESIGN and UETA
eIDAS
SEC 17a-4 ready
HIPAA ready

One platform, every rulebook.

Part 11 is the strictest e-signature standard in the world, so we built to it first. The same controls carry your obligations in every other regulated industry.

Pharma and biotech

21 CFR Part 11 · EU Annex 11 · GAMP 5

Signature meanings, batch record approvals, and validation documentation for GxP processes, from the lab bench to release.

Banking and finance

SEC 17a-4 · FINRA 4511 · SOX 302 and 404

Immutable, time-stamped records that satisfy books-and-records retention, plus attestation trails your external auditors can rely on.

Clinical research

ICH GCP · 21 CFR Part 11 · HIPAA

Investigator signatures, delegation logs, and consent records with evidence your sponsor and IRB can inspect at any time.

Insurance

ESIGN and UETA · State e-sign laws · NAIC guidance

Enforceable policyholder signatures with consent capture, identity evidence, and a defensible record if a claim ends up in court.

Healthcare and medical devices

HIPAA · 21 CFR 820 · EU MDR

Encrypted handling for PHI, design history file approvals, and supplier agreements that stand up in an FDA or notified body audit.

Energy and utilities

NERC CIP · FERC · State PUC rules

Authorization records, switching orders, and compliance attestations with proof of who approved what, and exactly when.

A trail no one can quietly rewrite.

Every event links to the one before it through a SHA-256 hash chain. Change a single byte anywhere in the history and the chain breaks, visibly, for everyone. That protection covers your own admins, and it covers us.

  • Immutable by design. No edit path exists, at any permission level.
  • Exportable as certified PDF and JSON, chain included.
  • Verifiable offline. Auditors can check the chain without SignerNest.
Walk through a real trail in a demo
Envelope created m.chen · Quality Operations #000000 → #a41f9c2e
Template Rev 03 applied system · effective 02 Aug 2026 #a41f9c2e → #5be07731
Recipient authenticated a.okafor · SSO + MFA #5be07731 → #77b0d3f1
Signature applied · Approved a.okafor · re-authenticated #77b0d3f1 → #c9e452a7
Chain sealed and archived system · retention: 12 years #c9e452a7 → verified ✓

Security your infosec team will actually enjoy reviewing.

Short answers to the questionnaire, before they ask.

Encrypted everywhere

AES-256 at rest, TLS 1.3 in transit, and envelope-level keys. Documents are never readable by anyone outside your account, including our own engineers.

Your data stays where you put it

Choose your data region at signup. Records never leave it, backups included, and residency is documented for your data protection assessments.

Retention you control

Set retention and legal hold per document type, from one year to forever. When a record must be destroyed, the destruction itself is an audit event.

Built to stay up

Redundant infrastructure across availability zones, continuous backups, and a published status page. Your signing deadlines do not wait for ours.

Put us in front of your quality team.

The hardest room to win is the one we built this for. Bring your QA lead to the demo and let them try to break the audit trail.