Built for GxP
Part 11 controls, and the mechanism behind each
Mergiva is built for GxP and designed to align with 21 CFR Part 11 and EU GMP Annex 11. Each control below names the mechanism that does the work.
21 CFR Part 11 sets the conditions under which the FDA treats electronic records and signatures as trustworthy as paper ones. EU GMP Annex 11 covers the same ground for computerised systems used in GMP work in Europe. Software cannot meet either on its own. An installation meets them after your team validates it and runs it under your procedures.
What software can do is give each control a mechanism you can inspect, test and cite. The cards below name that mechanism for each control, with the detail an assessor asks about first.
§11.10(e) · Audit trail
Tamper-evident ledger
Each entry carries the SHA-256 of the one before it, chained per deal. Database triggers reject update, delete and truncate. A verify routine names the first broken entry. An entry always names the person who really acted, and the public API can only read the ledger.
Good to know
130 of 147 state-changing routes write to it, and each of the other 17 carries a written reason why it is not a regulated record.
§11.50, §11.200 · Signatures
Electronic signatures
Who, when, what and the meaning of the signature are set on the server, never taken from the caller. Each signer logs in again; the token comes from your Keycloak and expires within 300 seconds.
Good to know
Waves and the gated stage changes are e-signed. Exception decisions are recorded with a written reason in the audit trail.
Segregation of duties
Two distinct signers
Two signatures from two different people, each identity taken from their own re-authentication. The creator of a wave cannot approve it. Enforced in the service and by a unique index in the database.
Good to know
Sixteen built-in roles. By design, changing a control goes through your change control.
§11.10(d) · Access control
Roles and deal teams
Sixteen roles in four tiers. By default, a user can open a deal only while on its deal team. Row-level security in the database keeps every query inside its own tenant, and the application’s database role cannot bypass it.
Good to know
Revocation takes effect at the gateway at once. Data services honour it within the token’s remaining life, at most five minutes. Removing someone from a deal team ends their access to that deal on their next request.
§11.10(c) · Records
Retention and legal hold
Object lock in compliance mode on Amazon S3 and MinIO, and each store’s own retention controls on Azure and Google Cloud, with a fifteen-year default. Per-file legal hold. Storage that cannot honour a policy is refused.
Good to know
Retention applies to the migrated copy in object storage, not to the source estate.
System validation
Executed with your QA
You receive the Part 11 and Annex 11 evidence maps, the control inventory, runbooks and the test artefacts your QA team needs to validate against your own infrastructure.
Good to know
Validation is executed with your QA team, on your infrastructure, using the evidence pack below.
EU GMP Annex 11 adds periodic audit-trail review and lifecycle documentation over the same ground. Compliance belongs to your validated installation, and these mechanisms are what your QA team validates.
The evidence layer
A ledger you can re-verify
Every entry records who acted, what they did, to which resource and from which address. Where they apply, it also records the state before and after, the reason and the e-signature.
Entry 1
prev hash = genesis
checksum over the entry
Entry 2
prev hash = entry 1
checksum includes it
Entry 3
prev hash = entry 2
checksum includes it
Entry n
prev hash = entry n−1
alter any earlier row and every later checksum breaks
verifyChain
Recomputes every checksum in order and returns INTACT, or TAMPERED with the first broken entry named.
130 / 147
State-changing routes that write to the ledger
88.4% on 26 September 2026. Each of the other 17 carries a written reason why it is not a regulated record.
Append-only
Enforced by the database
Update, delete and truncate are rejected by database triggers, and a verify routine names the first broken entry.
Zero
Unaudited routes allowed
A state-changing route that writes nothing to the ledger, without a written exemption, fails the build.
A hardened PostgreSQL ledger, with a second copy queued to object-lock storage off the database host. Coverage figures are from 26 September 2026.
Records
Retention and legal hold
Object lock in compliance mode on Amazon S3 and MinIO has no privileged override, which is the point of a long retention obligation. On Azure and Google Cloud, Mergiva uses each store’s own retention controls.
- Policies default to fifteen years, and one step applies them to a wave’s verified files.
- A legal hold is set per file, with a reason and an accountable user.
- Each storage adapter reports how strong its immutability is, and a policy the storage cannot honour is refused.
- Retention covers the migrated copy in object storage.
Validation
Validation is work we do with you
Validation is an executed qualification in your environment, signed by your people. This is what your QA team receives to start, and we execute the validation with you.
Evidence maps
Control inventory
Test artefacts
Runbooks
Start with one deal.
Judge us on the ledger, not the demo.
1
Name the pair
Tell us the two systems you need to connect. We produce that pair’s evidence before the pilot starts.
2
Scan one estate
Run a Data Estate Scan in your own cluster. You get the PDF report and a classification your QA team can inspect.
3
Plan validation together
Evidence maps, the control inventory and test artefacts, executed with your QA team on your infrastructure.
4
Run the first wave
Two signatures, a verified transfer and a compliance report you can hand to an assessor.
Or write to contact@mergiva-ai.com.