Vendor Qualification & Regulatory Alignment

Built for Regulated Environments

MedLii is engineered with technical controls aligned to global regulatory standards. We do not claim certification — instead, we support your vendor qualification process with the documentation, validation package, and technical capabilities your QA team needs.

Regulatory Standards We Align To

Our platform architecture is designed to support compliance with these global regulatory frameworks.

RegionRegulatory BodySoftware StandardData Privacy Law
United StatesUS FDA21 CFR Part 11HIPAA
European UnionEMAAnnex 11GDPR
GlobalICHICH-GCP E6(R3)GAMP 5 Framework

Note: Software vendors cannot buy or apply for these regulations. Compliance is achieved through internal system validation and auditing during vendor qualification.

Technical Compliance Built Into the Code

These capabilities are native to our architecture — they cannot be patched in later. Each is designed to meet specific regulatory requirements.

Secure Audit Trails

Computer-generated, time-stamped audit trails automatically record the date, time, and operator for every action that creates, modifies, or deletes data. Records cannot be overwritten or deleted.

21 CFR Part 11.10(e) / Annex 11 §9

Record Immutability

Electronic records are protected against overwrite and deletion. Soft-delete mechanisms preserve records with trackable reasons, ensuring data integrity throughout the record lifecycle.

21 CFR Part 11.10(c)

Electronic Signatures

Signatures are uniquely linked to individuals, displaying printed name, date, time, and the meaning of the signing action (e.g., review, approval, data entry). Signatures cannot be excised or transferred.

21 CFR Part 11.50 / 11.70

Role-Based Access Control

Distinct user tiers (Data Entry, Principal Investigator, Sponsor Auditor, Admin) strictly control system access. Permissions are enforced at the API level for every operation.

21 CFR Part 11.10(e) / ICH-GCP E6(R3)

Validation Package (GAMP 5 Framework)

We provide a formal validation package so your team can verify the software works exactly as intended under stress. This follows the GAMP 5 approach to computer system validation.

We document everything the software is supposed to do, aligned with your specific regulatory requirements and clinical trial workflows.

Deliverables:

Functional requirements document
Regulatory requirements mapping
Interface specifications
Security and access requirements

Vendor Qualification Process

We become compliant when we sell to you. Here's how we support your vendor qualification audit.

1

Security Questionnaire

We provide a completed security and compliance questionnaire (e.g., SIG, CAQ, proprietary) covering data handling, access controls, encryption, and incident response.

2

System Documentation

We supply architectural diagrams, data flow documents, SOPs, and validation documentation for your vendor qualification team to review.

3

Audit Trail Demonstration

We demonstrate the audit trail system, showing how every data mutation is recorded with user identity, timestamp, and before/after values.

4

Access Control Review

We walk through the RBAC model, showing how user tiers are enforced and how access can be restricted per study, site, or document.

5

On-Site or Remote Audit Support

We support your vendor qualification audit with technical sessions, environment access, and documentation as required by your QA team.

6

Continuous Monitoring

Post-qualification, we provide ongoing documentation of system changes, updates, and re-validation as the platform evolves.

System Architecture for Compliance

Our infrastructure is designed to meet the security and reliability requirements of regulated industries.

Secure Cloud Infrastructure

Encrypted data at rest and in transit. Regular security patching, intrusion detection, and disaster recovery with automated backups.

API-Level Enforcement

All access control and audit logging is enforced at the API layer. No client-side bypass is possible — every request is authenticated and authorized.

Tenant Isolation

Study-level and organization-level data isolation ensures that sponsors, CROs, and sites only access data they are authorized to see.

Frequently Asked Questions

Ready to qualify MedLii for your organization?

Contact us to receive our validation package, security documentation, and schedule a vendor qualification audit with your QA team.