Trust & validation

How we earn the trust of a QA lead

You should be able to assess QENTRA the same way you would assess any GxP supplier. This page says what we deliver, what is already designed in, and what is still in progress.

Designed in part of the Beta 1 specification   In progress delivered at Beta 1 launch (planned Q1 2027)

Validation: we validate, you verify

QENTRA is configurable SaaS (GAMP 5, category 4). We follow a risk-based approach in line with GAMP 5 (2nd edition) and FDA's Computer Software Assurance guidance: we validate the standard system once per release, and you reuse our evidence and only verify your own intended use.

QENTRA does
Validation plan, requirements, risk assessment, IQ/OQ execution, traceability and validation report for every release.
You do
A short, risk-based PQ/UAT of your own workflows, using a pre-filled template. Typically 1–2 days.
Every release
Release notes, known issues and an impact assessment telling you whether you need to re-test.

The validation package In progress

Included in every plan from Beta 1 launch. No separate fee.

Validation planScope, approach, roles and acceptance criteria
User requirements (URS)What the system is intended to do
Functional / configuration specificationHow QENTRA meets the URS
Functional risk assessmentWhich functions are GxP-critical and tested hardest
Part 11 / Annex 11 assessmentRequirement by requirement: how QENTRA supports it
Architecture & security descriptionHosting, encryption, backup and access
IQ and OQ protocols with executed evidenceIncluding negative tests of critical functions
Traceability matrixRequirement → risk → test → result
Validation summary reportDeviations during testing and release conclusion
For youPre-filled PQ/UAT template, step-by-step validation guide, quality agreement, supplier questionnaire, SLA

Built-in controls Designed in

Audit trailWho, what, when and why for every change to a regulated record. Cannot be edited or switched off by users.
Electronic signaturesName, date, time and meaning of the signature, linked to the record. Designed to support 21 CFR Part 11 and EU GMP Annex 11.
Role-based accessPersonal logins only, with roles per company and module.
Controlled workflowsStatus gates for documents, deviations and CAPA, with QA approval at defined steps.
External reviewersQPs, consultants and CDMOs review and sign inside the record with limited, audited access.
ExportRecords and audit trail can be exported for inspections, partners and exit.

Your data

Data processing agreementStandard for every customer, under GDPR.
HostingCloud hosting that meets EU data protection requirements. Provider and region are documented in the architecture description before Beta 1. In progress
No default vendor accessQENTRA staff have no standing access to your records. Emergency (break-glass) access is exceptional and logged.
Backup and restoreRegular backups with documented and tested restore. In progress
Tenant separationEach customer's data is logically separated from other customers.
Your data stays yoursFull export when you leave. No lock-in.

QENTRA as a supplier In progress

Our own quality system covers software development life cycle, change control and release, testing, bugs and CAPA, supplier management, backup and disaster recovery, information security and periodic review. You can audit it, or assess us remotely with our completed supplier questionnaire.

Questions from your QA or IT team?

We are happy to go through validation, hosting or data protection in detail.