Data security & technology
How we protect regulatory data, and what we can put in front of your vendor qualification team.
Label content is commercially sensitive and, once approved, legally binding. Everything below is written for the person on your side who has to sign off on a new vendor before regulatory affairs is allowed to use it.
Application security
Who can get in, and what the system remembers
Authentication
For data security, multi-factor authentication is enforced.
Access control
Role-based permissions scoped by product, division and portfolio.
Signing accounts
Accounts used to apply an electronic signature are unique to one person. Shared logins are prevented structurally rather than by policy.
Audit logging
Records actor, timestamp, type of action taken and label version. Every difference between versions is recorded. The trail cannot be switched off.
Data protection
Where your data lives, and what happens to it
Hosting and residency
All customer data is stored on Amazon EC2 instances.
Encryption
Encrypted at rest and in transit via TLS.
Tenancy
Our application operates on a secure multi-tenant architecture. Customer data is strictly isolated at the database layer using unique, tenant-specific identifiers to ensure that no cross-tenant data access is possible.
Backups and recovery
We take data integrity seriously. Our infrastructure is engineered to prevent data loss, minimize downtime, and ensure your business operations run smoothly and without interruption.
Our platform utilizes a high-availability architecture that continuously replicates data in real time to a secondary database for rapid failover capabilities. To ensure peak performance, secure and encrypted hot backups are taken nightly from this replica instance and stored offsite in AWS without impacting the live production application.
Data ownership and exit
Your label content is yours. It leaves with you.
Subprocessors
The only time someone other than you touches your data is when you submit a complex document that our automated processes cannot fully translate. At that time a direct employee of RegFrontier will fix the flagged sections to comply with FDA SPL standard.
Incident notification
If customer data is affected, we will inform you within 48 hours of our identification of the issue.
Testing cadence, patch SLAs, monitoring coverage, change control, personnel screening and the rest of the security questionnaire are answered in full under NDA rather than summarised here.
21 CFR Part 11 and validation
We claim the controls, not the compliance
FDA does not certify, approve or validate software against Part 11. There is no registry and no certificate. Compliance is a property of a regulated company using a system for a defined purpose, established through that company's own validation. Any vendor claiming blanket Part 11 compliance is telling you something that isn't available to them.
RegFrontier is built to support Part 11. We implement the technical controls the regulation requires of an electronic records system, and we supply the documentation you need to validate the platform for your intended use — so your validation team is reviewing evidence rather than assembling it.
| Clause | Requirement | What RegFrontier does |
|---|---|---|
| 11.10(a) | System validation | Supplies the validation evidence package — requirements, qualification records and a summary report |
| 11.10(b) | Accurate, complete copies in readable and electronic form | Exports any label and its history in both human-readable and electronic form |
| 11.10(c) | Records protected and retrievable across the retention period | Keeps every version retrievable for the full retention period, including across schema changes |
| 11.10(d) | Access limited to authorised individuals | Enforces role-based access, scoped by product, division and portfolio |
| 11.10(e) | Secure, computer-generated, time-stamped audit trail that does not obscure prior values | Records actor, timestamp, type of action taken and label version. Every difference between versions is recorded. The trail cannot be switched off |
| 11.10(f) | Operational system checks enforcing sequencing | Enforces the required order of steps through the workflow |
| 11.10(g) | Authority checks on who may act | Checks authority before permitting an action or a signature |
| 11.50 | Signature manifestation — printed name, date and time, meaning | Displays printed name, date and time, and the meaning of the signature on the record |
| 11.70 | Signatures bound to their record, not excisable | Binds each signature to the specific label version signed, and prevents it being detached |
| 11.300 | Unique identification and password controls | Issues signing accounts unique to one person and prevents shared logins structurally, not by policy |
Four Part 11 requirements are procedural obligations of the regulated company and cannot be delivered by any software vendor: training records for system users (11.10(i)), a written accountability policy for electronic signatures (11.10(j)), verifying an individual's identity before issuing a signature (11.100(b)), and the certification letter to FDA (11.100(c)). We name them rather than letting a compliance claim imply our controls cover them.
Certifications and standards
What we hold, and what we don't
| Standard | Validation | Status |
|---|---|---|
| SOC 2 Type II | Third-party audit | We anticipate getting this started in 2027. AWS maintains SOC 2 Type II for the underlying platform; that attestation covers AWS's controls, not our application. |
| ISO 27001 | Third-party audit | We anticipate getting this started in 2027. AWS holds ISO 27001 for the infrastructure layer. |
| FDA 21 CFR Part 11 | Not certifiable by anyone | Technical controls implemented; validation documentation provided. FDA does not certify software — see the clause-by-clause mapping below. |