The platform — for medical device professionals and manufacturers

Compliance built into the data model.

Qevatrix applications share one spine: tenancy, identity, permissions, audit trail and signature. That is why activating a second application takes minutes instead of a migration project.

Architecture

What every application inherits

01

Tenancy and isolation

Every organisation is a tenant with strictly isolated data. Row-level policies are enforced in the database, not just in the application layer, so a query cannot cross a tenant boundary.

02

One identity, every application

A person authenticates once and carries their roles into every activated application. Provisioning, deactivation and access review happen in one place.

03

Role and permission model

Roles are held in a dedicated authorization store, never on a user profile, and evaluated server-side. Privilege can be scoped by site, product family and record type.

04

Append-only audit trail

Every create, change, approval, signature and state transition is written to an immutable trail with actor, timestamp, previous value and reason. Records are superseded, never overwritten.

05

Electronic signatures

21 CFR Part 11 compliant signature capture with reauthentication, signature meaning, printed-name binding and non-repudiation on every regulated approval.

06

Controlled record lifecycle

Draft, review, approved, effective, superseded and obsolete states are modelled explicitly, with transitions gated by role, checklist completion and signature.

Security

Controls your auditor will ask about

We assume every record may end up in front of a notified body or an FDA investigator.

  • Encryption in transit and at rest
  • SSO via SAML and OIDC on enterprise plans
  • Least-privilege service credentials, no shared logins
  • Configurable retention and archival exports
  • Region-pinned data residency on enterprise agreements
  • Validation package with IQ/OQ protocols for every release line

Preparing for the FDA QMSR transition?

The same spine is why a move from 21 CFR Part 820 to ISO 13485:2016 alignment is a mapping exercise rather than a migration.

Read the FDA QMSR transition guide

Want the technical detail?

We will share the architecture overview, validation approach and security documentation under NDA.

Talk to our team