Read-only by design. Verifiable by default.
Clinplex reads regulated records: SOPs, deviations, CAPAs, batch records, validation packages, submission modules. It never writes to your validated systems, never trains a model on your data, and deletes what you send on request from Clinplex-controlled storage. This page states what we implement, what we inherit from our hosting providers, and what is still planned. It is versioned and reviewed like any other controlled document.
Read-only.
No write access to your QMS, LIMS, validation or ERP systems. Findings are exported to you; nothing flows back.
Never trained on.
Your records are not used to train, fine-tune or evaluate any model, ours or a provider's.
Deleted on request.
Clinplex-controlled source records and derived findings are deleted when you ask, and deletion from Clinplex-controlled storage is confirmed in writing.
NDA first.
A mutual NDA is executed before any record is exchanged, including for the free Inspection Stress Test.
How a record moves
The lineage of one document, from the moment you agree to send it to the moment it no longer exists on our side.
Mutual NDA
Sent within one business day of your request. No records change hands before signature.
Transfer
Records are exchanged after signature by reply email or a secure link you specify. Redacted records are accepted. For pilots and deployments, read-only connectors pull records from your systems; nothing is written back.
Processing
Records are evaluated against the regulatory frameworks that govern them. Access is gated by role-based access control, and every action is written to the audit chain with the user's identity.
Findings
You receive ranked gaps, the governing clause for each, linked-record impact and a drafted remediation. Every finding is time-stamped and attributable.
Retention and deletion
Clinplex-controlled copies are retained only for the duration of the engagement and then deleted. Deletion from Clinplex-controlled storage is available on request and confirmed in writing.
Encryption and infrastructure
Application and network controls
21 CFR Part 11 technical controls
Clinplex is not a system of record. Your QMS, LIMS and validation systems remain authoritative; Clinplex reads them and returns findings, so your validated state is not changed by using it. For the records Clinplex itself creates, the controls below are implemented today.
Unique user identification
Every user has a unique identifier, and attributable actions are carried into the audit trail.
Immutable, timestamped audit trail
Record creation and change events are captured in a timestamped, attributable, tamper-evident audit trail with controlled change history.
System access controls
Role-based access control, configurable per organization, with separate roles for QA, regulatory affairs, IT and admin.
Session controls
Session controls include configurable inactivity limits and re-authentication for sensitive actions such as signature and role changes.
Electronic signatures
Signatures bind printed name, date and time, and meaning to the signed record. Signature manifests are append-only and cannot be copied or transferred to another record.
Authority checks
Operations are checked against the user's authority, with security-relevant events captured for administrative review.
A validation documentation set and the full Part 11 control mapping are available under NDA.
AI processing controls
Clinplex uses controlled model-inference services as one component of the analysis workflow. Customer content is not used by Clinplex to train or fine-tune models.
Controlled transfer
Records are transferred over encrypted channels and handled under access controls appropriate to the engagement.
Contracted inference
Where third-party model inference is used, processing occurs under applicable enterprise/API terms and contractual controls. Current provider, retention and data-flow details are disclosed in the security packet and DPA.
Attributed results
Returned findings are tied to their regulatory basis and retained with attributable audit information inside Clinplex.
Human accountability
Model output is advisory. Final compliance, gap and CAPA decisions remain with named, qualified reviewers.
No Clinplex model training
Customer records are not used by Clinplex to train or fine-tune models.
Human review
Model output does not autonomously set final compliance, gap or CAPA status.
Provider controls
Provider handling and retention terms are disclosed during security review and governed by applicable agreements.
Compliance and assurance
| Control area | Status |
|---|---|
| Provider infrastructure assurance and attestations | Inherited |
| 21 CFR Part 11-supporting application controls | Implemented |
| Application-layer SOC 2 certification | Not claimed |
| HIPAA Business Associate Agreement | Not offered; do not send PHI |
Detailed architecture, provider attestations, independent-testing status, Part 11 control mapping and validation documentation are provided during security review under NDA.
Sub-processors
Clinplex uses contracted providers for hosting, data storage, model inference, business communications and the marketing site. The current provider list, processing purposes, applicable regions and contractual terms are supplied in the DPA and security packet before customer data processing.
Customers under a DPA are notified of applicable sub-processor changes in accordance with the agreement.
Retention, deletion and incident response
Clinplex-controlled records are retained for the duration of the engagement and deleted afterward. Deletion from Clinplex-controlled storage is available on request and confirmed in writing.
Clinplex maintains a documented incident-response procedure. Customer notification obligations and timelines are governed by applicable agreements and law.
Report a vulnerability to security@clinplex.com. Good-faith reporters are not pursued.
Frequently asked questions
- Where does customer data reside?
- On managed cloud infrastructure subject to access controls and encryption. Current provider and region details are supplied during security review and in the DPA.
- Is SOP or record content used to train AI models?
- No. Clinplex does not use customer content to train or fine-tune models. Third-party processing terms are disclosed during security review.
- How are 21 CFR Part 11 requirements addressed?
- Clinplex is not the customer's system of record. For records it creates, Clinplex implements identity, access, audit, session and electronic-signature controls designed to support applicable Part 11 requirements. The detailed control mapping is available under NDA.
- Is a BAA available for HIPAA?
- No. Clinplex does not currently offer a BAA. Do not send protected health information; redact records before transfer.
- Where can I review detailed architecture and testing evidence?
- Architecture, current subprocessors, provider attestations, independent-testing status, validation documentation and detailed security controls are provided through the security-review process under NDA.
Need the full packet?
Architecture overview, the 21 CFR Part 11 control mapping, the validation documentation set, DPA and sub-processor agreements are available under NDA. One email, one business day.
Request the security packet →