Skip to content
GxPValidate
Menu

Validation you can sign, because the gaps can’t hide.

GxPValidate runs a computerised-system validation from the Validation Plan to the Validation Summary Report. Testing effort follows risk (GAMP 5, FDA CSA), the traceability matrix builds itself from your records, and the summary report can’t be signed while anything is missing.

One validation, LIMS 2.1

  1. VP Approved

    Validation Plan

    Approved by QA

  2. SRA Approved

    System Risk Assessment

    System risk: High, GAMP 4

  3. URS Approved

    User Requirements

    38 requirements, 11 at Tier 1

  4. FS Approved

    Functional Specification

    52 requirements, all traced

  5. DS Approved

    Design Specification

    17 requirements, all traced

  6. TP Approved

    Test Protocol

    64 test cases

  7. EXE Passed

    Executions

    63 of 64 passed in Prod

  8. DEV Closed

    Deviations

    1 raised, closed by QA

  9. VSR Validation Summary Report

    Signing blocked: 2 open gaps
    • uncovered-requirement URS-014 Audit trail export has no test.
    • executor-not-independent TC-022 (Tier 1) was run by its own author.

Assurance proportionate to risk

Answer two questions for each requirement: is it GxP-critical, and is the impact direct or indirect? The tier and the testing it needs appear as you answer, and the traceability matrix holds you to it. Low-risk functions get exploratory testing with a session record instead of a 40-step script.

How tiers are assigned
Requirement tiers and the assurance each needs
TierWhat it needs
1 HighPre-approved scripted tests, negative paths, objective evidence, an executor independent of the author.
2 MediumPre-approved scripted tests (automated preferred), pass/fail record, independent review.
3 Not highUnscripted, exploratory testing with a session record.

Signatures that notice change

Every signature re-authenticates the signer by password, SSO or passkey, and binds a SHA-256 hash of exactly what was signed. Edit the record afterwards and the signature stops counting.

Automated tests, run where they matter

Run your pytest suite from one Docker image per commit in Test and in Prod, review the log and evidence, then sign to record the results. Every evidence file is checked against its hash.

Assistants draft, people sign

Connect an AI assistant over MCP to write requirements and test cases in draft. It works under your account and your locks, and it can never sign, submit or approve.

An audit trail with reasons

Every edit asks why. The audit trail shows who changed what, when, and the field-level difference, for every record in the validation.

Validate your next system here.

30 days free. No card needed to start.

Start free trial