Append-only ledger
Every state change — a published SOP, a closed CAPA, an inspection answer, an incident transition — is written once and never edited.
Audit Trail
Each event is appended to a ledger as canonical JSON — actor, action, content hash, UTC timestamp, and the hash of the previous event. Tamper with one row and every subsequent hash breaks.
21 CFR Part 11-shaped · EU GMP Annex 11 · ALCOA+ data integrity
Every state change — a published SOP, a closed CAPA, an inspection answer, an incident transition — is written once and never edited.
Each entry carries the hash of the previous one. Altering any historical row breaks every hash after it, visibly.
E-signatures include a hash of the exact bytes signed, with re-authentication and typed signature meanings.
PDFs and evidence packs embed the chain head. The artifact your auditor holds carries its own proof.
Auditors re-derive the chain on their own machine. The trail verifies or it doesn't — there is no "trust us" step.
Full workspace exports with chain proof are available if you leave. We don't hold your audit trail hostage.
Every action writes a canonical-JSON event with actor, action, subject hash, and UTC timestamp.
Each event includes the previous event's hash, forming a tamper-evident chain.
Anyone with the export can re-derive the chain independently and confirm nothing changed.
What this satisfies
"Shape" means we mirror the regulation's evidence, signature, and audit-trail requirements in our data model. See Trust & Security for the current certification state.
“Our auditor re-derived the chain on his own laptop and stopped asking for screenshots. That was the shortest evidence review we've ever had.”
Forge better processes
Bring SOPs, checklists, audits, incidents, and CAPAs into one connected system for safer, clearer, and more consistent operations.
No credit card required · Built for teams that run on process