Arrives validation-ready.
21 CFR Part 11 · EU Annex 11 · GAMP 5 · ALCOA+. GxP compliance is built into Praescia at the architectural level — it is not a checklist bolted on after the fact. We lower your CSV burden. We don’t add to it.
The three invariants
Every claim in this Validation Center reinforces three architectural invariants. Break any one, and we break the brand.
Insight-only
Validation-ready by design
Explainable by construction
GxP compliance status
| Framework | Status | Notes |
|---|---|---|
| 21 CFR Part 11 (FDA Electronic Records) | Architecture complete | Audit trail, e-signature manifests, and access control implemented. IQ/OQ/PQ deployment-gated per site. |
| EU Annex 11 | Architecture complete | Equivalent controls to Part 11. Validated per-site upon deployment. |
| GAMP 5 / CSA | Validation package skeleton complete | URS → GxP-risk classification → verification traceability. 7/8 requirements verified in-repo; IQ/OQ/PQ deployment-gated. |
| ALCOA+ | Enforced at every I/O boundary | Data integrity gate at publish: malformed or unattributable records are refused (fail-closed) and the rejection is audited. |
| SOC 2 Type I | Planned | Targeted pre-commercial. Available under NDA. |
| ISO 27001 | Roadmap | Follows SOC 2. Contact us for current posture. |
The GxP compliance shell
The compliance shell wraps the AtlasInside publish boundary as CompliantAtlasInside — a drop-in that the coupled pipeline publishes through with zero pipeline changes.
21 CFR Part 11 / EU Annex 11 controls
- Audit trail (
audit.py): Append-only, hash-chained, tamper-evident. Every advisory, disposition, and configuration change is recorded with timestamp, user identity, and action. Non-repudiable. - Electronic signatures (
signature.py): E-sig manifests include signer identity, timestamp, meaning of signature, and hash-link to the signed record (Subpart C). Deviation advisories are queued for QA electronic-signature disposition. - Access control (
identity.py): Role-based, fail-closed. Default-deny. Least-privilege enforced by role, not by policy document.
ALCOA+ data integrity
Fail-closed at the I/O boundary. Records that violate ALCOA+ (not Attributable, not Legible, not Contemporaneous, not Original, not Accurate) are refused at publish. The refusal is itself audited. No silent data corruption.
- Attributable: Every data point carries its originating source, instrument, user, and timestamp.
- Legible: Human-readable audit entries alongside machine-readable records.
- Contemporaneous: Timestamps are asserted at the point of data acquisition, not retrospectively.
- Original: Raw data is preserved alongside derived values. Chain of custody is hash-linked.
- Accurate: Contradictions between sources are flagged, not silently resolved.
GAMP 5 / CSA validation package
The validation package skeleton is shipped with the product — not built separately per customer engagement:
- User Requirements Specification (URS)
- GxP-risk classification (Category 3 Computer System per GAMP 5)
- Verification traceability matrix (URS → test evidence)
- 7 of 8 requirements verified in-repository; IQ/OQ/PQ executed at deployment per site
- Change-control log integrated with the audit trail
Why insight-only is the regulatory moat
Praescia is positioned as decision support, not a GMP closed-loop controller. This is an architectural choice with profound regulatory consequences:
- Out of GMP closed-loop-control validation scope. A system that advises the operator does not require the same validation depth as a system that actuates the process. This significantly lowers the customer’s validation burden.
- FDA-tailwind. The FDA actively encourages PAT, continuous manufacturing, and real-time release (ICH Q8/Q9/Q10, the PAT guidance). Praescia is designed to support these frameworks, not conflict with them.
- Explainable advisories are auditable. An opaque black-box recommendation cannot be defended in a deviation investigation. Praescia’s named-driver advisories can.
Security posture
Encryption
Network isolation
Access control
- Authentication
- SAML 2.0 / OIDC / LDAP — integrates with your existing IAM provider
- Provisioning
- SCIM 2.0 for automated user lifecycle management
- Roles
- Process engineer / QA reviewer / Site admin / Read-only auditor — fail-closed by default
- MFA
- Required for all advisory disposition actions
Atlas Inside network data handling
The “Atlas Inside” network layer enables cross-site benchmarking and fleet intelligence. It operates without ever accessing raw batch data from other customers.
Federate derived patterns, not raw process data. Only typed derived structure (deviation transition labels, golden-trajectory residuals, outcome bands) moves across the network. Raw historian values, batch identifiers, and product identities never leave the customer’s environment. Enforced architecturally, not by policy.
- Differential privacy
- ε=1.0, δ=10−6, k-anonymity floor 25 (standard configuration)
- Prohibited content types
- Raw historian values, batch product identifiers, lot numbers, customer identifiers, patient identifiers
- Permitted content types
- Typed derived residuals, transition onset labels, outcome bands, golden-trajectory features
- Opt-out
- Network participation is per-site and per-line. Opt out at any time; benchmarking features are disabled for opted-out assets.
Documents available under NDA
- GAMP 5 validation package skeleton (URS, risk assessment, verification traceability matrix)
- Security architecture overview
- Data flow diagram (customer site → compliance shell → network layer)
- SOC 2 Type I report (when available)
- Penetration test executive summary (when available)
Responsible disclosure
To report a security vulnerability: richard@accelerate-ip.co. PGP key available on request. We commit to acknowledging reports within 48 hours and providing a timeline within 7 days.