Trust & compliance
What Ravngard does to support EU GMP Annex 11 and 21 CFR Part 11, how we protect your data, and what we have not done yet.
Regulations and guidance we design for
- EU GMP Annex 11 — Computerised Systems (and the 2025 draft revision)
- 21 CFR Part 11 — Electronic Records; Electronic Signatures
- GAMP 5, 2nd edition — a risk-based approach to compliant GxP computerised systems
- PIC/S PI 041-1 — good practices for data management and integrity
- EU GMP Annex 15 — qualification and validation
- EU GMP Annex 22 (draft) — artificial intelligence
No software is compliant on its own. Compliance comes from a validated system used under your procedures. Ravngard provides the technical controls; you keep control of the procedures and the decisions.
How Ravngard supports Part 11 and Annex 11
| Requirement | What it asks | How Ravngard supports it |
|---|---|---|
| 11.10(a) · A11 §4 | Validation | Supplier validation pack, built-in self-test you can run after every update, release notes for every version. |
| 11.10(b) · A11 §8 | Accurate and complete copies | Printouts with signatures, Excel exports and a complete backup of all records. |
| 11.10(c) · A11 §7 | Protection and retention of records | Records stored in PostgreSQL, daily backups with regular restore tests, no hard delete of signed records. |
| 11.10(d) · A11 §12 | Limited system access | Personal accounts, role-based access, optional two-factor authentication (TOTP), automatic idle lock. |
| 11.10(e) · A11 §9 | Secure, computer-generated audit trail | Append-only audit trail with time stamps, user, old and new values and the reason for change; entries are hash-chained so any alteration is detected. |
| 11.10(f) · A11 §5 | Operational checks (sequence) | Approval routes enforce the order of steps; a document cannot be executed before it is approved. |
| 11.10(g) · A11 §12 | Authority checks | Only users with the right role and position in the route can sign each step. |
| 11.10(k) · A11 §10 | Document and change control | Frozen versions at every submit, approval and revision, with side-by-side compare and a differences report. |
| 11.50 · A11 §14 | Signature manifestation | Each signature shows the printed name, date and time and the meaning (authored, reviewed, approved, executed). |
| 11.70 · A11 §14 | Signature/record linking | Signatures are issued by the server and bound to the exact record version; they cannot be copied to another record. |
| 11.100 · 11.200 | Unique signatures, two components | Unique user ID plus password at every signing; signing re-checks the password even inside an open session. |
Security
- HTTPS everywhere with HSTS; strict Content-Security-Policy and other security headers.
- Passwords stored with Argon2id; optional TOTP two-factor authentication; secrets encrypted at rest (AES-GCM).
- Session cookies that are HTTP-only, secure and same-site; CSRF protection; rate limiting on sign-in.
- Each customer's data is separated in its own tenant.
- Only the web proxy is reachable from the internet; the application and database sit on an internal network.
Hosting and data protection
- The hosted service runs on servers in the European Union. A dedicated instance is available on request.
- Daily backups, copied off-site, with regular restore tests.
- We act as data processor under a GDPR data processing agreement (art. 28).
- Your records are yours: export them at any time; retention and hand-over are agreed in the contract.
Supplier validation pack
Available on request, to support your supplier assessment and your own validation:
- Functional specification and supplier risk assessment
- Test reports for each release, including the automated test results
- Release notes and known issues
- Quality agreement template and SOP templates for use of the system
Our quality system — honestly
Ravngard is a young company in formation. We are not ISO 9001 or ISO 27001 certified yet; both are planned. Until then we offer:
- Remote or on-site supplier audits, with full access to our development and test records
- A completed supplier questionnaire on request
- Development under a documented software lifecycle with version control, automated testing and release notes