Security and compliance
GxPValidate provides the technical controls that 21 CFR Part 11 and EU GMP Annex 11 expect of a computerised system. This page describes what the software does; validating it for your intended use, and the procedures around it, remain your responsibility.
Part 11 and Annex 11 controls
| Control | What GxPValidate does |
|---|---|
| Signature manifestation 11.50 | Every signature records the printed name, its meaning (authored, reviewed, approved, executed), a UTC timestamp and the record version. |
| Signature/record linking 11.70 | Each signature stores a SHA-256 hash and the canonical text of what was signed. It counts only while that hash still matches the record. |
| Re-authentication 11.200, Annex 11 §13.3 | Every signature re-authenticates the signer by passkey, password or SSO step-up (OIDC), even moments after sign-in. The method is stored on the signature. |
| Audit trail 11.10(e), Annex 11 §9 | Every change is recorded with the user, the time and a mandatory reason for change, with field-level differences. |
| Authority and sequence checks 11.10(f), (g) | Roles per system. An author cannot review or approve their own document, review comes before approval, and the person who raised a deviation cannot close it. |
| Record protection 11.10(c) | Locks are enforced on the data model, not only the screens: approved documents cannot be edited (a change means a new version and new signatures), and executions, evidence and signatures are write-once. |
| Session control Annex 11 §12 | Sessions end after an idle period each organization sets (30 minutes by default). |
| Evidence integrity | Every evidence file is stored with its SHA-256 hash. Automated-run evidence is checked against the test run’s manifest, and any mismatch fails the run. |
Tenant isolation in the database
Every record belongs to one organization, and PostgreSQL row-level security policies limit each request to its own organization’s rows. With no organization set, a query returns nothing. The application connects as a database role that cannot bypass these policies.
Single sign-on
Each organization can connect its own OIDC or SAML identity provider and enforce it, turning off password sign-in. SSO admits only existing users and invited people; client secrets and certificates are stored encrypted.
AI assistants cannot sign
Assistants connected over MCP act as the signed-in user with that user’s roles and locks. During an MCP request the system refuses to create any signature or move a document to review or approval, and every assistant edit is marked in the audit trail.
Accounts and transport
Passwords are at least 12 characters and stored as salted hashes. Traffic is HTTPS only, with HSTS and secure, HTTP-only session cookies. Card payments are handled by Stripe; card numbers never reach GxPValidate.
Hosting and data location
If you have requirements for where your data is stored, for supplier assessment or for an audit of GxPValidate itself, contact us before you start. We will answer specifically rather than point you to a badge.