Skip to content
GxPValidate
Menu

Security and compliance

GxPValidate provides the technical controls that 21 CFR Part 11 and EU GMP Annex 11 expect of a computerised system. This page describes what the software does; validating it for your intended use, and the procedures around it, remain your responsibility.

Part 11 and Annex 11 controls

How each control is implemented
ControlWhat GxPValidate does
Signature manifestation
11.50
Every signature records the printed name, its meaning (authored, reviewed, approved, executed), a UTC timestamp and the record version.
Signature/record linking
11.70
Each signature stores a SHA-256 hash and the canonical text of what was signed. It counts only while that hash still matches the record.
Re-authentication
11.200, Annex 11 §13.3
Every signature re-authenticates the signer by passkey, password or SSO step-up (OIDC), even moments after sign-in. The method is stored on the signature.
Audit trail
11.10(e), Annex 11 §9
Every change is recorded with the user, the time and a mandatory reason for change, with field-level differences.
Authority and sequence checks
11.10(f), (g)
Roles per system. An author cannot review or approve their own document, review comes before approval, and the person who raised a deviation cannot close it.
Record protection
11.10(c)
Locks are enforced on the data model, not only the screens: approved documents cannot be edited (a change means a new version and new signatures), and executions, evidence and signatures are write-once.
Session control
Annex 11 §12
Sessions end after an idle period each organization sets (30 minutes by default).
Evidence integrityEvery evidence file is stored with its SHA-256 hash. Automated-run evidence is checked against the test run’s manifest, and any mismatch fails the run.

Read more in Help: electronic signatures

Tenant isolation in the database

Every record belongs to one organization, and PostgreSQL row-level security policies limit each request to its own organization’s rows. With no organization set, a query returns nothing. The application connects as a database role that cannot bypass these policies.

Single sign-on

Each organization can connect its own OIDC or SAML identity provider and enforce it, turning off password sign-in. SSO admits only existing users and invited people; client secrets and certificates are stored encrypted.

AI assistants cannot sign

Assistants connected over MCP act as the signed-in user with that user’s roles and locks. During an MCP request the system refuses to create any signature or move a document to review or approval, and every assistant edit is marked in the audit trail.

Accounts and transport

Passwords are at least 12 characters and stored as salted hashes. Traffic is HTTPS only, with HSTS and secure, HTTP-only session cookies. Card payments are handled by Stripe; card numbers never reach GxPValidate.

Hosting and data location

If you have requirements for where your data is stored, for supplier assessment or for an audit of GxPValidate itself, contact us before you start. We will answer specifically rather than point you to a badge.