Validation you can sign, because the gaps can’t hide.
GxPValidate runs a computerised-system validation from the Validation Plan to the Validation Summary Report. Testing effort follows risk (GAMP 5, FDA CSA), the traceability matrix builds itself from your records, and the summary report can’t be signed while anything is missing.
One validation, LIMS 2.1
-
VP Approved
Validation Plan
Approved by QA
-
SRA Approved
System Risk Assessment
System risk: High, GAMP 4
-
URS Approved
User Requirements
38 requirements, 11 at Tier 1
-
FS Approved
Functional Specification
52 requirements, all traced
-
DS Approved
Design Specification
17 requirements, all traced
-
TP Approved
Test Protocol
64 test cases
-
EXE Passed
Executions
63 of 64 passed in Prod
-
DEV Closed
Deviations
1 raised, closed by QA
-
VSR Validation Summary Report
Signing blocked: 2 open gapsuncovered-requirementURS-014 Audit trail export has no test.executor-not-independentTC-022 (Tier 1) was run by its own author.
Assurance proportionate to risk
Answer two questions for each requirement: is it GxP-critical, and is the impact direct or indirect? The tier and the testing it needs appear as you answer, and the traceability matrix holds you to it. Low-risk functions get exploratory testing with a session record instead of a 40-step script.
How tiers are assigned| Tier | What it needs |
|---|---|
| 1 High | Pre-approved scripted tests, negative paths, objective evidence, an executor independent of the author. |
| 2 Medium | Pre-approved scripted tests (automated preferred), pass/fail record, independent review. |
| 3 Not high | Unscripted, exploratory testing with a session record. |
Signatures that notice change
Every signature re-authenticates the signer by password, SSO or passkey, and binds a SHA-256 hash of exactly what was signed. Edit the record afterwards and the signature stops counting.
Automated tests, run where they matter
Run your pytest suite from one Docker image per commit in Test and in Prod, review the log and evidence, then sign to record the results. Every evidence file is checked against its hash.
Assistants draft, people sign
Connect an AI assistant over MCP to write requirements and test cases in draft. It works under your account and your locks, and it can never sign, submit or approve.
An audit trail with reasons
Every edit asks why. The audit trail shows who changed what, when, and the field-level difference, for every record in the validation.
Validate your next system here.
30 days free. No card needed to start.