Skip to content

Compliance by design

Compliance isn't a checkbox. It's the architecture. Every design decision in MESvantage was made with ISO 13485 and FDA 21 CFR Part 11 in mind from the first line of code.

FDA

21 CFR Part 11

The FDA's electronic records and electronic signatures regulation requires that any software used in regulated manufacturing maintains trustworthy, reliable, and generally equivalent records to paper.

In March 2026 we completed an IQ/OQ/PQ exercise for MESvantage at our founding customer's site: 226 / 226 test cases executed and passed, against a requirements traceability matrix in which 175 / 175 requirements were traced. We are assembling that package — protocols, scripts, the traceability matrix and the executed reports — for release under NDA. Until it is assembled we will not pretend otherwise; the current status of each artefact is on our evidence page. This is a point-in-time qualification of that configuration. We operate a release classification and per-release GxP impact assessment that determines what gets regression-tested, but we have not yet published that statement — so until we do, treat our answer on it as unverified. That, and everything else we do not have, is set out on what we don't do yet.

  • Immutable audit trail on every record change
  • Electronic signatures with identity verification
  • Role-based access controls with least-privilege enforcement
  • Closed system with access limited to authorised users
  • System-generated, computer-readable audit trails
  • Date/time stamping on all record modifications
  • Sequence of events with operator identification
  • Validation documentation package (IQ/OQ/PQ)
Quality

ISO 13485

ISO 13485 is the quality management standard for medical device manufacturers. MESvantage's quality module directly supports the traceability, DHR, and process control requirements auditors look for.

  • Digital Device History Record (DHR)
  • Full component and process traceability
  • Incoming inspection with accept/reject workflow
  • First Article Inspection (FAI) records
  • Non-conformance tracking and CAPA linkage
  • Customer-facing quality portal
  • Training records linked to operator access
  • Process control with SPC alerting
Architecture

Siloed SaaS

Each MESvantage customer receives a fully isolated deployment: their own compute, their own database, their own Redis cache, their own backups.

Isolation is not a regulatory requirement, and we will not claim it is. It is a practical one: your environment can be inspected and evidenced without reference to any other customer's system, which keeps your audit scope simple and your data unambiguously yours.

Siloed SaaS is a compliance feature, not a technical compromise.

  • Dedicated compute instance per customer
  • Isolated PostgreSQL database
  • Separate Redis cache
  • Independent automated backups
  • Independent security patching
  • Audit scope limited to your own environment
  • No cross-customer data access (by design)
  • Infrastructure provisioned from code

Talk to us about your compliance requirements

Book a Demo