Skip to content

Built for GxP

Part 11 controls, and the mechanism behind each

Mergiva is built for GxP and designed to align with 21 CFR Part 11 and EU GMP Annex 11. Each control below names the mechanism that does the work.

21 CFR Part 11 sets the conditions under which the FDA treats electronic records and signatures as trustworthy as paper ones. EU GMP Annex 11 covers the same ground for computerised systems used in GMP work in Europe. Software cannot meet either on its own. An installation meets them after your team validates it and runs it under your procedures.

What software can do is give each control a mechanism you can inspect, test and cite. The cards below name that mechanism for each control, with the detail an assessor asks about first.

  • §11.10(e) · Audit trail

    Tamper-evident ledger

    Each entry carries the SHA-256 of the one before it, chained per deal. Database triggers reject update, delete and truncate. A verify routine names the first broken entry. An entry always names the person who really acted, and the public API can only read the ledger.

    Good to know

    130 of 147 state-changing routes write to it, and each of the other 17 carries a written reason why it is not a regulated record.

  • §11.50, §11.200 · Signatures

    Electronic signatures

    Who, when, what and the meaning of the signature are set on the server, never taken from the caller. Each signer logs in again; the token comes from your Keycloak and expires within 300 seconds.

    Good to know

    Waves and the gated stage changes are e-signed. Exception decisions are recorded with a written reason in the audit trail.

  • Segregation of duties

    Two distinct signers

    Two signatures from two different people, each identity taken from their own re-authentication. The creator of a wave cannot approve it. Enforced in the service and by a unique index in the database.

    Good to know

    Sixteen built-in roles. By design, changing a control goes through your change control.

  • §11.10(d) · Access control

    Roles and deal teams

    Sixteen roles in four tiers. By default, a user can open a deal only while on its deal team. Row-level security in the database keeps every query inside its own tenant, and the application’s database role cannot bypass it.

    Good to know

    Revocation takes effect at the gateway at once. Data services honour it within the token’s remaining life, at most five minutes. Removing someone from a deal team ends their access to that deal on their next request.

  • §11.10(c) · Records

    Retention and legal hold

    Object lock in compliance mode on Amazon S3 and MinIO, and each store’s own retention controls on Azure and Google Cloud, with a fifteen-year default. Per-file legal hold. Storage that cannot honour a policy is refused.

    Good to know

    Retention applies to the migrated copy in object storage, not to the source estate.

  • System validation

    Executed with your QA

    You receive the Part 11 and Annex 11 evidence maps, the control inventory, runbooks and the test artefacts your QA team needs to validate against your own infrastructure.

    Good to know

    Validation is executed with your QA team, on your infrastructure, using the evidence pack below.

EU GMP Annex 11 adds periodic audit-trail review and lifecycle documentation over the same ground. Compliance belongs to your validated installation, and these mechanisms are what your QA team validates.

The evidence layer

A ledger you can re-verify

Every entry records who acted, what they did, to which resource and from which address. Where they apply, it also records the state before and after, the reason and the e-signature.

  1. Entry 1

    prev hash = genesis

    checksum over the entry

  2. Entry 2

    prev hash = entry 1

    checksum includes it

  3. Entry 3

    prev hash = entry 2

    checksum includes it

  4. Entry n

    prev hash = entry n−1

    alter any earlier row and every later checksum breaks

verifyChain

Recomputes every checksum in order and returns INTACT, or TAMPERED with the first broken entry named.

130 / 147

State-changing routes that write to the ledger

88.4% on 26 September 2026. Each of the other 17 carries a written reason why it is not a regulated record.

Append-only

Enforced by the database

Update, delete and truncate are rejected by database triggers, and a verify routine names the first broken entry.

Zero

Unaudited routes allowed

A state-changing route that writes nothing to the ledger, without a written exemption, fails the build.

A hardened PostgreSQL ledger, with a second copy queued to object-lock storage off the database host. Coverage figures are from 26 September 2026.

Records

Retention and legal hold

Object lock in compliance mode on Amazon S3 and MinIO has no privileged override, which is the point of a long retention obligation. On Azure and Google Cloud, Mergiva uses each store’s own retention controls.

  • Policies default to fifteen years, and one step applies them to a wave’s verified files.
  • A legal hold is set per file, with a reason and an accountable user.
  • Each storage adapter reports how strong its immutability is, and a policy the storage cannot honour is refused.
  • Retention covers the migrated copy in object storage.

Validation

Validation is work we do with you

Validation is an executed qualification in your environment, signed by your people. This is what your QA team receives to start, and we execute the validation with you.

Evidence maps

Requirement-by-requirement maps for 21 CFR Part 11 and clause-by-clause for EU GMP Annex 11.

Control inventory

Each control and the mechanism that implements it.

Test artefacts

The unit, integration and end-to-end runs behind each control, and the committed transfer proof.

Runbooks

Operating procedures for incidents, backup and restore.

Start with one deal.

Judge us on the ledger, not the demo.

Talk to us
  1. 1

    Name the pair

    Tell us the two systems you need to connect. We produce that pair’s evidence before the pilot starts.

  2. 2

    Scan one estate

    Run a Data Estate Scan in your own cluster. You get the PDF report and a classification your QA team can inspect.

  3. 3

    Plan validation together

    Evidence maps, the control inventory and test artefacts, executed with your QA team on your infrastructure.

  4. 4

    Run the first wave

    Two signatures, a verified transfer and a compliance report you can hand to an assessor.

Or write to contact@mergiva-ai.com.