A Quality System That Ships With Its Own Validation Evidence
Medical-device companies cannot adopt a cloud QMS until it has been validated — months of unbillable work most vendors push onto the customer. We built one that validates itself, inside the product, and signs the PDF at the end.
Industry
MedTech / Regulatory
Solution
Validated eQMS
Engagement
~14 Months, Ongoing
Services
AI & Enterprise Development

The Software You Cannot Use Until You Prove It Works
A medical-device company's quality system is not paperwork — it is the evidence that its device is safe, and it is what a regulator asks for. Most of it lives in Word documents, spreadsheets and a wiki, with version drift between them and audit preparation that takes weeks of manual reconciliation.
Moving that to the cloud has a catch that outsiders never see: under 21 CFR Part 11, the customer must first validate the software itself — install, operational and performance qualification — before they are allowed to keep records in it. Most vendors hand that back to the customer. It is months of work that produces no product.
The Problems We Set Out to Solve
The source is clear that these are drawn from the codebase, plan files and meeting notes rather than from a formal client brief — but they are the problems the architecture was built against, and they are specific.
Quality records scattered across documents, spreadsheets and a wiki, with version drift
Customers unable to adopt any cloud QMS without running IQ/OQ/PQ validation themselves
Regulatory data living outside the QMS — copy-pasted between portals, going stale
Design and risk artefacts authored by hand from blank templates, frequently incomplete
Investor material maintained separately, disconnected from the device data behind it
Validation as a Product Feature
The idea that shapes everything: if the customer must validate the software, then validating the software should be something the software does.
A Validation Sandbox Per Tenant
A cloned sandbox provisioned atomically, with the signer personas created automatically, so the customer executes install, operational and performance qualification inside the product — and gets a signed PDF pinned to a specific release at the end.
One Source of Truth for Quality
Document authoring with full versioning and templates, with every artefact carrying an audit trail — the version drift between the document, the spreadsheet and the wiki simply has nowhere to happen.
Regulatory Data Inside the Workflow
Device codes, European device nomenclature and notified-body data pulled in through purpose-built functions and surfaced directly inside device definition and gap analysis, instead of copy-pasted from a portal.
AI Where the Authoring Is Heaviest
Around seventy-five AI functions covering document generation, gap-step assessment, hazard generation, verification planning, predicate trails and vigilance forms — the parts previously typed from a blank page.
What the Platform Does
Document Studio
Full document authoring with versioning, templates and validation — the single place quality records are written.
Validation Sandbox
A per-tenant cloned sandbox with auto-provisioned signer personas, in-app IQ/OQ/PQ execution, and one-click signed-PDF generation pinned to a release.
CAPA
Corrective and preventive action lifecycle with electronic-signature approvals.
Non-Conformity
Capture, investigation and closure of non-conformities against the product they concern.
Change Control
Change request through impact analysis to approval, with the trail intact.
Design Risk & Hazards
Risk management to ISO 14971, with AI-assisted hazard generation from the device definition.
Technical File
A technical-file builder structured to the European regulation's annexes, assembled from the same data as everything else.
Device & BOM
Unique device identification, device families, bill of materials and components.
Gap Analysis
Multi-standard gap checklists with AI-assisted assessment of each step.
Audits & PMS
Internal and supplier audits, plus post-market surveillance plans, escalations and vigilance reports.
Verification & Validation
Verification and validation plans with evidence synced to the artefacts they prove.
Design Review
Formal design-review meetings with attendees, verdict and electronic signature.
Training & Competency
Training plans, a competency matrix, and AI-generated training quizzes.
Suppliers
Supplier registry, audits and evaluation documents.
Budget & NPV
Company and phase budgets with risk-adjusted net present value and what-if analysis.
Investor Surface
Investor share links and marketplace previews, driven by the same product data rather than a separate deck.
Super-Admin Console
Around twenty pages covering tenants, billing, plans, releases, templates, API keys, AI usage and the audit log.
Multi-Tenant, Audit-Grade, AI-Assisted
Frontend
Backend
Data & Access
AI & Compliance
Fourteen Months, Five Phases
- 1
Core QMS Modules
The document model, the quality lifecycle, and the modules a device company cannot operate without.
- 2
Multi-Tenancy & Super-Admin
Strict tenant isolation with a privileged bypass held in one place, plus the console that runs the platform.
- 3
AI-Assisted Authoring
The AI functions across document generation, hazard analysis, gap assessment and verification planning, with tiered key resolution so customers can bring their own.
- 4
Validation Framework
The launch sprint that made IQ/OQ/PQ a feature: per-tenant sandbox, auto-provisioned signers, in-app execution, signed PDFs pinned to a release.
- 5
Scale-Up
Per-tenant database split and customer onboarding, planned against a concrete roadmap rather than hoped for.
- 6
How We Worked
Weekly launch-sprint meetings and five-minute micro-syncs during the sprint, working bug to fix to staging to next bug, with named per-client branches for customer-specific work.
What Was Delivered
5
Live Customer Tenants
10+
Tools Replaced
168
Edge Functions
995
DB Migrations
Validation — install, operational and performance qualification — is executed inside the product, and the signed evidence is generated there too.
Five customer tenants run live on the platform, each isolated from the others at the database level.
More than ten separate tools are replaced by one system, with a single audit trail across all of them.
Regulatory data is pulled into the workflow rather than copy-pasted from a portal, so device classifications do not quietly go stale.
Frequently Asked Questions
Yes — that is the idea the whole system is built around. Instead of handing validation back to the customer, we made it a product feature: a cloned sandbox is provisioned per tenant with signer personas created automatically, the customer executes install, operational and performance qualification inside the product, and a signed PDF pinned to a specific release is generated at the end.
Services Behind This Build
Explore Other Case Studies
Building software that has to pass an audit?
We build systems where the access model, the audit trail and the validation evidence hold up under a regulator — not just under a demo.
Talk to a Delivery Expert

