Data security & technology

How we protect regulatory data, and what we can put in front of your vendor qualification team.

Label content is commercially sensitive and, once approved, legally binding. Everything below is written for the person on your side who has to sign off on a new vendor before regulatory affairs is allowed to use it.

Application security

Who can get in, and what the system remembers

Authentication

For data security, multi-factor authentication is enforced.

Access control

Role-based permissions scoped by product, division and portfolio.

Signing accounts

Accounts used to apply an electronic signature are unique to one person. Shared logins are prevented structurally rather than by policy.

Audit logging

Records actor, timestamp, type of action taken and label version. Every difference between versions is recorded. The trail cannot be switched off.

Data protection

Where your data lives, and what happens to it

Hosting and residency

All customer data is stored on Amazon EC2 instances.

Encryption

Encrypted at rest and in transit via TLS.

Tenancy

Our application operates on a secure multi-tenant architecture. Customer data is strictly isolated at the database layer using unique, tenant-specific identifiers to ensure that no cross-tenant data access is possible.

Backups and recovery

We take data integrity seriously. Our infrastructure is engineered to prevent data loss, minimize downtime, and ensure your business operations run smoothly and without interruption.

Our platform utilizes a high-availability architecture that continuously replicates data in real time to a secondary database for rapid failover capabilities. To ensure peak performance, secure and encrypted hot backups are taken nightly from this replica instance and stored offsite in AWS without impacting the live production application.

Data ownership and exit

Your label content is yours. It leaves with you.

Subprocessors

The only time someone other than you touches your data is when you submit a complex document that our automated processes cannot fully translate. At that time a direct employee of RegFrontier will fix the flagged sections to comply with FDA SPL standard.

Incident notification

If customer data is affected, we will inform you within 48 hours of our identification of the issue.

Testing cadence, patch SLAs, monitoring coverage, change control, personnel screening and the rest of the security questionnaire are answered in full under NDA rather than summarised here.

21 CFR Part 11 and validation

We claim the controls, not the compliance

FDA does not certify, approve or validate software against Part 11. There is no registry and no certificate. Compliance is a property of a regulated company using a system for a defined purpose, established through that company's own validation. Any vendor claiming blanket Part 11 compliance is telling you something that isn't available to them.

RegFrontier is built to support Part 11. We implement the technical controls the regulation requires of an electronic records system, and we supply the documentation you need to validate the platform for your intended use — so your validation team is reviewing evidence rather than assembling it.

ClauseRequirementWhat RegFrontier does
11.10(a)System validationSupplies the validation evidence package — requirements, qualification records and a summary report
11.10(b)Accurate, complete copies in readable and electronic formExports any label and its history in both human-readable and electronic form
11.10(c)Records protected and retrievable across the retention periodKeeps every version retrievable for the full retention period, including across schema changes
11.10(d)Access limited to authorised individualsEnforces role-based access, scoped by product, division and portfolio
11.10(e)Secure, computer-generated, time-stamped audit trail that does not obscure prior valuesRecords actor, timestamp, type of action taken and label version. Every difference between versions is recorded. The trail cannot be switched off
11.10(f)Operational system checks enforcing sequencingEnforces the required order of steps through the workflow
11.10(g)Authority checks on who may actChecks authority before permitting an action or a signature
11.50Signature manifestation — printed name, date and time, meaningDisplays printed name, date and time, and the meaning of the signature on the record
11.70Signatures bound to their record, not excisableBinds each signature to the specific label version signed, and prevents it being detached
11.300Unique identification and password controlsIssues signing accounts unique to one person and prevents shared logins structurally, not by policy

Four Part 11 requirements are procedural obligations of the regulated company and cannot be delivered by any software vendor: training records for system users (11.10(i)), a written accountability policy for electronic signatures (11.10(j)), verifying an individual's identity before issuing a signature (11.100(b)), and the certification letter to FDA (11.100(c)). We name them rather than letting a compliance claim imply our controls cover them.

Certifications and standards

What we hold, and what we don't

StandardValidationStatus
SOC 2 Type IIThird-party auditWe anticipate getting this started in 2027. AWS maintains SOC 2 Type II for the underlying platform; that attestation covers AWS's controls, not our application.
ISO 27001Third-party auditWe anticipate getting this started in 2027. AWS holds ISO 27001 for the infrastructure layer.
FDA 21 CFR Part 11Not certifiable by anyoneTechnical controls implemented; validation documentation provided. FDA does not certify software — see the clause-by-clause mapping below.