Trust and security

Your data, protected end to end.

Written for the Qualified Person and the validation team: where your signed records live, who can reach them, and how the platform is validated. The platform is pre-release, so each item below is committed for go-live, and details that depend on your contract are marked as such.

Your QMS keeps the original record

The regulated record stays exactly where it already lives. The Quality Bridge carries the shared, attributable trail of the approval alongside it.

Security architecture

Built to align with ISO 27001 principles.

Designed for validation

A GAMP 5 Category 4 configured product with a clean split of responsibilities, stated below.

Regulatory position

Designed as a GAMP 5 Category 4 configured product.

That sets a clean division of labour between you and us. Validation of the system for its intended use stays with the regulated company; we supply everything a Category 4 supplier is expected to supply.

References: GAMP 5 (second edition) Category 4 · EU GMP Annex 11, Computerised Systems · ALCOA+ principles for data integrity.

The customer owns
  • User requirements specification
  • Testing sign-off
  • Acceptance and release for use
  • SOPs and work instructions for your intended use
We own
  • Functional and configuration specifications
  • Configuration test evidence
  • Product user documentation
  • A documented change-management process
Security posture

Stated item by item.

What we commit to, item by item, and what each means for your data. The platform is pre-release, so every item is marked By go-live: committed for the first production release. The full detail is in the supplier quality pack.

ItemStateDetail
Hosting provider and regionBy go-liveHosted in the European Union. No customer data leaves the EU.
Encryption in transit and at restBy go-liveTLS 1.2 or higher for every connection; data and documents encrypted at rest.
Role-based access controlBy go-liveEvery action is permitted by role and by company. A user sees only their own company's workspaces and threads.
Multi-factor authenticationBy go-liveAvailable to every user; enforceable by the licence holder for its own users and for invited partner users.
Single sign-on (SAML)By go-liveSAML 2.0 single sign-on for customers who run their own identity provider.
Audit-trail retention periodBy go-liveAudit trails are kept for the life of the workspace and beyond its closure, for the period set in your quality agreement.
Backup and restoreBy go-liveDaily encrypted backups; restore procedure tested on a fixed schedule.
Penetration testingBy go-liveIndependent penetration test at least annually and after any material change; summary available in the supplier quality pack.
Sub-processor listBy go-livePublished and kept current; customers are notified before any change.
Data export on exitBy go-liveEvery workspace, document, thread and audit trail exportable in open formats on request, at no charge, at the end of the contract.
Incident notificationBy go-liveCustomers notified without undue delay and within 72 hours of a confirmed personal-data breach, as the GDPR requires.
Supplier quality pack

For your quality and validation teams, on request.

QMS summary, specification and test approach, security posture, and change management, in one pack for quality and validation teams.