Your data, protected end to end.
Written for the Qualified Person and the validation team: where your signed records live, who can reach them, and how the platform is validated. The platform is pre-release, so each item below is committed for go-live, and details that depend on your contract are marked as such.
Your QMS keeps the original record
The regulated record stays exactly where it already lives. The Quality Bridge carries the shared, attributable trail of the approval alongside it.
Security architecture
Built to align with ISO 27001 principles.
Designed for validation
A GAMP 5 Category 4 configured product with a clean split of responsibilities, stated below.
Designed as a GAMP 5 Category 4 configured product.
That sets a clean division of labour between you and us. Validation of the system for its intended use stays with the regulated company; we supply everything a Category 4 supplier is expected to supply.
References: GAMP 5 (second edition) Category 4 · EU GMP Annex 11, Computerised Systems · ALCOA+ principles for data integrity.
- User requirements specification
- Testing sign-off
- Acceptance and release for use
- SOPs and work instructions for your intended use
- Functional and configuration specifications
- Configuration test evidence
- Product user documentation
- A documented change-management process
Stated item by item.
What we commit to, item by item, and what each means for your data. The platform is pre-release, so every item is marked By go-live: committed for the first production release. The full detail is in the supplier quality pack.
| Item | State | Detail |
|---|---|---|
| Hosting provider and region | By go-live | Hosted in the European Union. No customer data leaves the EU. |
| Encryption in transit and at rest | By go-live | TLS 1.2 or higher for every connection; data and documents encrypted at rest. |
| Role-based access control | By go-live | Every action is permitted by role and by company. A user sees only their own company's workspaces and threads. |
| Multi-factor authentication | By go-live | Available to every user; enforceable by the licence holder for its own users and for invited partner users. |
| Single sign-on (SAML) | By go-live | SAML 2.0 single sign-on for customers who run their own identity provider. |
| Audit-trail retention period | By go-live | Audit trails are kept for the life of the workspace and beyond its closure, for the period set in your quality agreement. |
| Backup and restore | By go-live | Daily encrypted backups; restore procedure tested on a fixed schedule. |
| Penetration testing | By go-live | Independent penetration test at least annually and after any material change; summary available in the supplier quality pack. |
| Sub-processor list | By go-live | Published and kept current; customers are notified before any change. |
| Data export on exit | By go-live | Every workspace, document, thread and audit trail exportable in open formats on request, at no charge, at the end of the contract. |
| Incident notification | By go-live | Customers notified without undue delay and within 72 hours of a confirmed personal-data breach, as the GDPR requires. |
For your quality and validation teams, on request.
QMS summary, specification and test approach, security posture, and change management, in one pack for quality and validation teams.