Done
8
In product / docs
Partial
9
Scaffold — harden for production
External
5
Org / license / gateway
Important reality check
There is no FDA/EMA stamp that “approves” a safety database product. Buyers validate the system in their environment (CSV / GAMP 5 / CSA). We reduce that burden with product controls and a reusable validation package.
Do not claim “GVP validated” or “Part 11 certified” until customer IQ/OQ/PQ is executed and approved — and org certifications (ISO/SOC) are separately obtained.
21 CFR Part 11 / Annex 11
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| E-signature on lock / submit / unlock | Done | Password re-challenge + meaning of signature; CaptureESign writes audit | — |
| Clinical audit trail with actor | Done | Migration 000021 triggers + db.actorTracer → audit_log.actor | — |
| Role-based access control | Done | app_user roles + protected API routes; Console for admin lists | — |
Data integrity (ALCOA+)
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| Database-enforced case lock | Done | enforce_case_unlocked() triggers (migration 000023) | — |
| Case version snapshots | Done | case_version on lock/submit/transmit + manual snapshot | — |
Privacy / PHI
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| Optional PHI field encryption helpers | Partial | pgcrypto initials_enc / birth_date_enc + POST …/phi/encrypt | Production key management, SSO/OIDC, field-level RBAC reviews |
ICH E2B(R3)
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| ICSR export with richer section coverage | Partial | build.go stub: C/D/E/F/G elements, message types, nullFlavors | Official ICH HL7 agency XSD pack |
| Schema-gated E2B validate / transmit | Partial | Embedded icsr_r3_min.xsd + POST /e2b/validate | Replace with official HL7 ICSR XSD |
| ACK/NACK reconciliation | Done | Transmission ACK fields; Nack → action_item; Interchange UI | — |
| Initial / follow-up / amendment / nullification | Done | e2b_message_type on case + Regulatory Reports selector | — |
Agency gateways
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| Live AS2 / SFTP to FDA ESG / EMA EV / PvPI | External | Destination stubs + local payload staging only | Partner certificates + gateway onboarding |
Dictionaries
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| MedDRA search / encode / recode impact | Partial | Active release registry, coding UI, recode jobs | Licensed MSSO MedDRA packs |
| WHO-DD search / apply / recode | Partial | who_drug sample + product apply + recode stamps | Licensed UMC WHODrug packs |
| Device / IMDRF sample dictionary | Partial | device_dictionary samples + Dictionaries → Device tab | Licensed IMDRF / UDI packs; eMDR path |
Reporting clocks
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| Standard 90-day guideline + expedited HA clocks | Done | GUIDELINE_90 + FDA/MHRA/etc. report_rule; worklist due date | — |
Periodic / signal
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| PBRER / signal modules | Partial | Periodic generate + signal PRR/ROR; not full MAH engines | Period-locked datasets from case versions |
CSV / GAMP 5 package
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| URS + IQ/OQ/PQ + DR templates | Partial | docs/validation/* — templates; customer must execute in their env | Traceability matrix + executed PQ with design partner |
| GAMP category + CSA criticality map | Partial | Documented in CERTIFICATION-AND-VALIDATION-REALITY.md | Module-by-module CSA risk register |
Org security certifications
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| ISO 27001 | External | Not a product feature — organizational audit | Engage certification body after ISMS is live |
| SOC 2 Type II | External | Not a product feature — organizational audit | SaaS control evidence + Type II period |
| HIPAA alignment / BAA | External | No official HHS certificate; buyer diligence + BAA if US PHI | Risk analysis, BAAs, independent assessment |
Identity
| Capability | Status | Evidence in Safety DB | Next step |
|---|---|---|---|
| Enterprise SSO / OIDC | External | Local username/password auth today | Wire Okta / Entra / Auth0 |
Org certification roadmap
ISO 27001, SOC 2, and HIPAA credibility are organizational — not product features. All steps below are External and currently Not started. Do not market them until evidence exists.
Recommended order
- 1. Security basics and written policies (Foundation)
- 2. SOC 2 Type II — often first ask for US / pharma SaaS procurement
- 3. ISO 27001 — strong for EU / global buyers; heavy reuse of SOC work
- 4. HIPAA alignment + BAAs — only if US PHI is in scope; no government seal
| Framework | Step | Phase | Owner | Detail |
|---|---|---|---|---|
| Foundation | Security basics (MFA, encryption, logging, backups, access reviews) | Not startedExternal | Security / IT | Shared prerequisite for SOC 2 / ISO / HIPAA. Product already has audit/RBAC; org must run operational controls. |
| Foundation | Policies: ISMS / information security handbook | Not startedExternal | Security / Quality | Acceptable use, access control, incident response, vendor management, change control, BCP/DR. |
| SOC 2 | Define Trust Services Criteria + system boundary | Not startedExternal | Security | Usually Security first; add Availability / Confidentiality as buyers require. Map hosting + Safety DB. |
| SOC 2 | Engage CPA firm; Type I then Type II observation period | Not startedExternal | Leadership / Security | Type I = design at a point in time; Type II = operating effectiveness over 3–12 months. Deliverable is a report under NDA, not a wall certificate. |
| ISO 27001 | Operate ISMS with risk register + Statement of Applicability | Not startedExternal | Security | Reuse SOC control evidence where possible. Run the management system before the certification audit. |
| ISO 27001 | Accredited Stage 1 + Stage 2 certification audit | Not startedExternal | Leadership / Security | Certificate typically valid 3 years with annual surveillance audits. |
| HIPAA | HIPAA risk analysis + policies (if US PHI in scope) | Not startedExternal | Privacy / Security | There is no official HHS/OCR “HIPAA certificate.” Credibility = risk analysis, safeguards, and evidence. |
| HIPAA | BAAs with customers and subprocessors | Not startedExternal | Legal / Privacy | Required when acting as a business associate. Align cloud provider BAAs (AWS/Azure) with your posture. |
| HIPAA | Independent HIPAA assessment (optional HITRUST / SOC mapping) | Not startedExternal | Security | Buyers often accept a third-party assessment or HIPAA controls mapped inside SOC 2. |
Note: HIPAA has no official HHS certificate. Buyers look for risk analysis, BAAs, and (often) a third-party assessment or SOC mapping.
Buyer diligence questions
- Current ISO 27001 / SOC 2 certificates and expiry dates (if any)
- Sample CSV / Part 11 evidence pack (URS, IQ/OQ, audit sample, access matrix)
- Hosting region(s), subprocessors, and data residency options
- Who holds MedDRA and WHO-DD licenses — vendor or customer
- E2B gateway references (test ACK evidence for FDA ESG / EMA EV)
- Backup/restore drill results and RPO/RTO commitments
- Change-control SOP for configuration vs code releases
- Inspection support model and customer references
Validation artifacts live under docs/validation/ and docs/gvp-csv-checklist.md.