Back to homeCompliance & Evidence
Transparency page

Compliance & Evidence

This page is maintained by Advanced Life Sciences to answer common security, quality and compliance questions about the Pharma Intelligence platform. It now separates real product evidence, internal process statements and items that are not yet available as formal evidence.

This page is not a certification or evidence vault. It describes what can be verified in the product today and what still requires enterprise qualification. It does not represent an independent audit opinion, regulatory approval, SOC 2 report, ISO certificate or generated PDF evidence package.

Real evidence today

Live application modules, audit views, validation workflows, risk fields and HTTPS delivery can be reviewed directly in the product.

Requires qualification

Customer-specific validation packs, SLA terms, regional deployment boundaries and onboarding documents must be confirmed during procurement.

Not available yet

SOC 2 Type II, ISO 27001 certification, HIPAA attestation and public penetration-test reports are not currently published evidence.

Platform architecture

Statements about what can be verified from the live product today versus what still requires enterprise scoping.

  • Modular architecture across seven functional pillars

    In place today

    Compliance, Validation, Assets, Training, CAPA, Change Control and Suppliers are implemented as independent modules in the shipped product.

    Evidence: Live product evidence: the authenticated platform contains these modules and their user workflows.
  • Traffic served over TLS (HTTPS)

    In place today

    The public site and authenticated application are served exclusively over HTTPS.

    Evidence: Browser-verifiable evidence: the public domain and app surfaces are served with HTTPS.
  • Regional deployment (US / EU / LATAM)

    Planned / roadmap

    The platform is designed to support region-bound deployments. Region isolation for a specific customer is scoped during enterprise onboarding.

    Evidence: No public evidence package is available yet. This is scoped per enterprise deployment.

Regulatory alignment

Regulatory statements describe the intent of the design. They are not certifications by an independent auditor and should not be read as such.

  • Designed for 21 CFR Part 11 and EU Annex 11 controls

    In place today

    Access control, electronic records, audit trail and electronic signature workflows are built with these regulations as the reference framework.

    Evidence: Product evidence exists for access control, records and audit-trail workflows. A formal clause-by-clause validation package is not publicly issued.
  • ALCOA+ data integrity by design

    In place today

    Records are captured with attribution (user, timestamp), stored with a database-level audit trail and made available for review.

    Evidence: Product evidence: audit views show who changed what, when it changed and the before / after record context.
  • GAMP 5 aligned software lifecycle

    In place today

    Development, change control and release processes reference GAMP 5 category guidance.

    Evidence: Process evidence only. No external GAMP 5 certification or auditor-issued statement is currently available.
  • ICH Q9 risk-based approach

    In place today

    Risk classification is embedded in validation, supplier and change control workflows.

    Evidence: Product evidence: risk fields, criticality and scoring are visible in the relevant application modules.

Security frameworks

Security work is aligned to well-known frameworks. No statement on this page should be read as an independent certification or audit outcome.

  • Controls mapped to SOC 2, ISO 27001 and HIPAA

    Planned / roadmap

    The internal control set is mapped against these frameworks. Pharma Intelligence does not currently hold a SOC 2 Type II report, ISO 27001 certificate or HIPAA attestation.

    Evidence: No third-party attestation is available at this time. This should not be presented as certified evidence.
  • SOC 2 Type II report

    Planned / roadmap

    A formal SOC 2 Type II audit is on the enterprise roadmap. Timeline is shared during enterprise procurement discussions.

    Evidence: Not available yet.
  • Penetration test

    Available on request

    Executive summaries of the most recent security testing exercises can be shared with qualified prospects.

    Evidence: Security review can be discussed during procurement. No public penetration-test report is published on the site.

Operations

Operational statements describe how the service is run in practice. Specific numeric commitments (SLA, RTO, RPO) are formalised in the Master Services Agreement, not on marketing pages.

  • Availability targets and SLA

    Available on request

    Uptime targets, credits and reporting cadence are defined per enterprise contract. No universal uptime percentage is published on marketing surfaces.

    Evidence: Contract evidence only. SLA terms must be issued in the customer agreement, not generated by this page.
  • Backup and recovery

    Available on request

    Backup frequency, retention and recovery objectives are documented and provided during enterprise onboarding.

    Evidence: Enterprise onboarding evidence. A public BCP / DR report is not currently available.
  • Incident response

    In place today

    Security incidents are triaged and handled by the engineering team. Notification obligations are governed by the applicable enterprise contract.

    Evidence: Operational process statement. Contract-specific notification obligations are confirmed during onboarding.

Shared responsibility

Compliance in regulated pharma is a shared responsibility. Advanced Life Sciences operates and maintains the Pharma Intelligence platform and its underlying controls. The customer is responsible for configuring the platform in line with their own Quality Management System, running their qualification / validation activities for the intended use, defining internal SOPs, managing user access within their organisation and keeping their own regulatory records.

Requesting evidence

Use this form to request a compliance review and identify which evidence topics matter to your team. It does not automatically generate real evidence documents. If a requested item is not currently available, the compliance team will say so clearly instead of sending placeholder material.

Schedule enterprise demo

Last reviewed: July 2026 · Maintained by Advanced Life Sciences