The platform — for medical device professionals and manufacturers
Compliance built into the data model.
Qevatrix applications share one spine: tenancy, identity, permissions, audit trail and signature. That is why activating a second application takes minutes instead of a migration project.
Architecture
What every application inherits
Tenancy and isolation
Every organisation is a tenant with strictly isolated data. Row-level policies are enforced in the database, not just in the application layer, so a query cannot cross a tenant boundary.
One identity, every application
A person authenticates once and carries their roles into every activated application. Provisioning, deactivation and access review happen in one place.
Role and permission model
Roles are held in a dedicated authorization store, never on a user profile, and evaluated server-side. Privilege can be scoped by site, product family and record type.
Append-only audit trail
Every create, change, approval, signature and state transition is written to an immutable trail with actor, timestamp, previous value and reason. Records are superseded, never overwritten.
Electronic signatures
21 CFR Part 11 compliant signature capture with reauthentication, signature meaning, printed-name binding and non-repudiation on every regulated approval.
Controlled record lifecycle
Draft, review, approved, effective, superseded and obsolete states are modelled explicitly, with transitions gated by role, checklist completion and signature.
Security
Controls your auditor will ask about
We assume every record may end up in front of a notified body or an FDA investigator.
- Encryption in transit and at rest
- SSO via SAML and OIDC on enterprise plans
- Least-privilege service credentials, no shared logins
- Configurable retention and archival exports
- Region-pinned data residency on enterprise agreements
- Validation package with IQ/OQ protocols for every release line
Preparing for the FDA QMSR transition?
The same spine is why a move from 21 CFR Part 820 to ISO 13485:2016 alignment is a mapping exercise rather than a migration.
Read the FDA QMSR transition guideWant the technical detail?
We will share the architecture overview, validation approach and security documentation under NDA.