Skip to content
The compliance layer

Built so the audit is the easy part.

One compliance core underpins both products, with the same signatures, the same trail, the same rules. Staying compliant is built into how the work happens, not bolted on after.

Built to adapt to your regulatory regime: 21 CFR Part 11 · ISO 17025 · ISO 13485 · ISO 9001 · GxP

SOC 2 Type II is in progress.

21 CFR Part 11

The clauses, covered.

§11.10(a)
Validation

System validation to ensure accuracy, reliability, and consistent performance.

§11.10(b)
Record copies

Accurate, complete copies of records in human-readable and electronic form.

§11.10(c)
Record retention

Protection of records throughout their retention period via immutable history.

§11.10(d)
Access control

System access limited to authorized individuals via roles and permissions.

§11.10(e)
Audit trail

Secure, computer-generated, time-stamped audit trails with reason-for-change.

§11.10(k)
Change control

Controls over documentation and change to system records and procedures.

§11.50
Signature manifestations

Signed records show signer, date/time, and the meaning of the signature.

§11.70
Signature linking

Signatures are bound to their records so they cannot be excised or copied.

Audit trail

Captured automatically. Tamper-evident by design.

Every change records who did it, what changed, and when, into a history that cannot be edited after the fact. No gaps, no “the system did it” rows, nothing to reconstruct on audit day.

Who, what, when, on every record that matters The full context of every change, captured for you Records are never silently deleted or overwritten A reason-for-change on every signed edit (§11.10(e))
vapor.dlbd.us/results/R-8842
Search samples, results, CAPAs…
JM

Audit trail · Result R-8842

immutable
PS
Priya Shah created14 Jun · 08:41
Result R-8842 · As 0.21 ppm
  1. 1
    Open any record
    Every record that matters carries a history that cannot be edited after the fact.
  2. 2
    Who, what, when
    Each change is attributed and time-stamped for you, with nothing to log by hand.
  3. 3
    The reason, on the record
    The §11.10(e) context an auditor asks for is already written before anyone asks.
Electronic signatures

Friction where it counts. Nowhere else.

Your authenticated session, permissions, and training sign the routine, high-frequency actions, audit-ready and with no password re-prompt. The password-and-reason step appears only for the rare, high-risk moments: closing a CAPA, approving a revision, unsigning anything.

Routine: no re-prompt

Signed by your authenticated session, permissions, and current training. Audit-ready, zero friction.

  • Result verification
  • Batch verification
  • Instrument data approval
High-risk: password + reason

Reserved for the rare, audit-bait moments. Reason-for-change recorded for §11.10(e), then the record locks.

  • Close a CAPA
  • Approve a document revision
  • Unsign a record
Configurable approvals

The approval matrix is yours to configure.

Different regulators want different chains. Set your own approval steps per organization (QA → Director → CEO) and change them yourself when the rules change. A new market is a setting you adjust, not a release you wait on.

QA Director CEO
Data isolation

One client never sees another.

Every record is sealed to its organization, so one client can never reach another one’s data. Run many labs on a single deployment with no risk of crossover.

Greenfield
isolated
Nordic
isolated
Apex
isolated

Bring your auditor.

See the audit trail, the signature manifest, and the approval chain in the live demo.