Audit-ready by design. Not after the fact.
One data model, one audit trail, CDSCO-aligned end-to-end. Designed for Indian GCP and aligned to ICH E6(R3) for international filings.
How the platform meets each standard
CDSCO Schedule Y, end-to-end
Study templates, the audit trail and electronic signatures follow Indian GCP and align to CDSCO New Drugs and Clinical Trials Rules, 2019. CTRI registration support is in build.
Part 11–style e-signatures
Every signature carries meaning, attribution and a reason for change. Architected to Indian GCP, ICH E6(R3) and 21 CFR Part 11, so an international filing does not need a second system.
Validation, run with an external auditor
The platform is architected to GAMP 5, with electronic signatures, audit trails and record-integrity controls built in rather than added later. The formal computer system validation exercise runs with an external auditor, and we tell you plainly what it covers and what it does not yet cover.
Security by default
Encryption in transit and at rest, granular role-based access, SSO/SAML and least-privilege permissions. Reviewed on a schedule, not when someone asks.
Data residency
Your data is processed in alignment with the DPDP Act 2023, encrypted in transit and at rest, with every access logged for audit. Need isolation? Enterprise customers can take a dedicated single-tenant environment or regional failover, and the full subprocessor list is published in our Data Processing Agreement.
Standards, end to end
CDSCO Schedule Y · ICMR National Ethical Guidelines (2017) · Indian GCP · DPDP Act 2023 · ICH E6(R3) · ICH E2A and E2B(R3) for safety · CDISC ODM / SDTM · MedDRA / WHODrug · HL7 FHIR for integration.
The trail is the record.
Every entry carries who, when, what changed and what it changed from. It is written as the work happens rather than assembled afterwards, which is the difference between a log and evidence.
The detail a reviewer asks for.
Written for the person who has to sign off on us. Where something is still in build, the row says so.
Records and signatures
- Audit trail
- Every create, change and delete is written with the actor, the timestamp, the previous value and the new one. Entries are append-only and queryable; nothing in the application can edit or remove one.
- Electronic signatures
- Signatures carry meaning, attribution and a reason for change, and are bound to the record they sign. Architected to 21 CFR Part 11 and ICH E6(R3).
- Freeze, lock and unlock
- Data can be frozen or locked at form, subject or study level. Unlock is a request with an approver and a recorded reason, not an administrative toggle.
Access
- Role-based access
- Roles and their permissions are configurable rather than fixed, at organisation, study and site level, because no two CROs use the same titles. Field-level restriction is not there yet.
- Authentication
- Email and password with session controls today; SSO and SAML for enterprise agreements.
- Least privilege
- Permissions are granted per study rather than globally, so access to one sponsor's study does not imply access to another's.
Data
- Encryption
- Encrypted in transit and at rest by the underlying cloud infrastructure.
- Residency
- Processed in alignment with the DPDP Act 2023. Enterprise customers can take a dedicated single-tenant environment or regional failover.
- Backup and recovery
- Automated backups with point-in-time recovery. Restore procedure is documented and exercised, not assumed.
- Export and exit
- The full study exports on request, audit trail included, in CDISC ODM and SDTM-aligned form. Leaving does not require our cooperation beyond running the export.
- Subprocessors
- Listed in the Data Processing Agreement, with identity, location and purpose for each.
Study lifecycle
- Environments
- A study moves draft → UAT → live, with configuration promoted between them. A separate development environment and an independent QC stage, with test subject data isolated from production, is the next piece of architecture in build.
- Study validation
- Proving your configuration behaves to your specification is distinct from validating our platform. Today that testing happens in UAT; a dedicated QC stage with retained, retrievable evidence is in build.
- Amendments
- Study configuration is versioned and deploys without a rebuild. A full change-control workflow — request, approval, effective date and documented impact on enrolled subjects — is in build alongside the environment separation above.
Bring your QA, regulatory, and ethics-committee teams to the demo.
We walk through the audit trail, electronic signatures, validation approach, CTRI registration support, and DPDP-aligned data handling in detail — the elements that determine the outcome of an Indian-GCP inspection.
