Document CPX-TRUST-001Version 3.1Effective 28 Aug 2026Next review 26 Nov 2026Owner security@clinplex.com
Security and trust

Read-only by design. Verifiable by default.

Clinplex reads regulated records: SOPs, deviations, CAPAs, batch records, validation packages, submission modules. It never writes to your validated systems, never trains a model on your data, and deletes what you send on request from Clinplex-controlled storage. This page states what we implement, what we inherit from our hosting providers, and what is still planned. It is versioned and reviewed like any other controlled document.

Read-only.

No write access to your QMS, LIMS, validation or ERP systems. Findings are exported to you; nothing flows back.

Never trained on.

Your records are not used to train, fine-tune or evaluate any model, ours or a provider's.

Deleted on request.

Clinplex-controlled source records and derived findings are deleted when you ask, and deletion from Clinplex-controlled storage is confirmed in writing.

NDA first.

A mutual NDA is executed before any record is exchanged, including for the free Inspection Stress Test.

How a record moves

The lineage of one document, from the moment you agree to send it to the moment it no longer exists on our side.

  1. Mutual NDA

    Sent within one business day of your request. No records change hands before signature.

  2. Transfer

    Records are exchanged after signature by reply email or a secure link you specify. Redacted records are accepted. For pilots and deployments, read-only connectors pull records from your systems; nothing is written back.

  3. Processing

    Records are evaluated against the regulatory frameworks that govern them. Access is gated by role-based access control, and every action is written to the audit chain with the user's identity.

  4. Findings

    You receive ranked gaps, the governing clause for each, linked-record impact and a drafted remediation. Every finding is time-stamped and attributable.

  5. Retention and deletion

    Clinplex-controlled copies are retained only for the duration of the engagement and then deleted. Deletion from Clinplex-controlled storage is available on request and confirmed in writing.

Encryption and infrastructure

Hosting
Managed cloud infrastructure with controlled database, object-storage and backup services. Detailed architecture and current subprocessors are provided during security review under NDA.
In transit
Customer and application traffic is protected with HTTPS/TLS and modern transport-security controls.
At rest
Provider-managed encryption at rest is used for application data and stored objects. Detailed storage and key-management controls are available during diligence.
Backups
Managed backups are subject to restore and integrity verification. Recovery architecture and control evidence are available in the security packet.
Secrets
Application secrets are managed outside source code with restricted access and automated scanning controls.
Security headers
Security headers and browser protections are applied at the application and edge layers.

Application and network controls

Abuse protectionImplemented
Authentication and analysis endpoints are protected by application and managed-edge controls.
Network accessImplemented
Application and administrative access paths are restricted under least-privilege controls. Detailed network architecture is available during security review.
Audit evidenceImplemented
Control and audit evidence is available to authorized customers under NDA.

21 CFR Part 11 technical controls

Clinplex is not a system of record. Your QMS, LIMS and validation systems remain authoritative; Clinplex reads them and returns findings, so your validated state is not changed by using it. For the records Clinplex itself creates, the controls below are implemented today.

21 CFR 11.10(d)

Unique user identification

Every user has a unique identifier, and attributable actions are carried into the audit trail.

21 CFR 11.10(e)

Immutable, timestamped audit trail

Record creation and change events are captured in a timestamped, attributable, tamper-evident audit trail with controlled change history.

21 CFR 11.10(d)

System access controls

Role-based access control, configurable per organization, with separate roles for QA, regulatory affairs, IT and admin.

21 CFR 11.10(g)

Session controls

Session controls include configurable inactivity limits and re-authentication for sensitive actions such as signature and role changes.

21 CFR 11.50, 11.70

Electronic signatures

Signatures bind printed name, date and time, and meaning to the signed record. Signature manifests are append-only and cannot be copied or transferred to another record.

21 CFR 11.10(g)

Authority checks

Operations are checked against the user's authority, with security-relevant events captured for administrative review.

A validation documentation set and the full Part 11 control mapping are available under NDA.

AI processing controls

Clinplex uses controlled model-inference services as one component of the analysis workflow. Customer content is not used by Clinplex to train or fine-tune models.

  1. Controlled transfer

    Records are transferred over encrypted channels and handled under access controls appropriate to the engagement.

  2. Contracted inference

    Where third-party model inference is used, processing occurs under applicable enterprise/API terms and contractual controls. Current provider, retention and data-flow details are disclosed in the security packet and DPA.

  3. Attributed results

    Returned findings are tied to their regulatory basis and retained with attributable audit information inside Clinplex.

  4. Human accountability

    Model output is advisory. Final compliance, gap and CAPA decisions remain with named, qualified reviewers.

Implemented

No Clinplex model training

Customer records are not used by Clinplex to train or fine-tune models.

Implemented

Human review

Model output does not autonomously set final compliance, gap or CAPA status.

Contractual

Provider controls

Provider handling and retention terms are disclosed during security review and governed by applicable agreements.

Compliance and assurance

Control areaStatus
Provider infrastructure assurance and attestationsInherited
21 CFR Part 11-supporting application controlsImplemented
Application-layer SOC 2 certificationNot claimed
HIPAA Business Associate AgreementNot offered; do not send PHI

Detailed architecture, provider attestations, independent-testing status, Part 11 control mapping and validation documentation are provided during security review under NDA.

Sub-processors

Clinplex uses contracted providers for hosting, data storage, model inference, business communications and the marketing site. The current provider list, processing purposes, applicable regions and contractual terms are supplied in the DPA and security packet before customer data processing.

Customers under a DPA are notified of applicable sub-processor changes in accordance with the agreement.

Retention, deletion and incident response

Clinplex-controlled records are retained for the duration of the engagement and deleted afterward. Deletion from Clinplex-controlled storage is available on request and confirmed in writing.

Clinplex maintains a documented incident-response procedure. Customer notification obligations and timelines are governed by applicable agreements and law.

Report a vulnerability to security@clinplex.com. Good-faith reporters are not pursued.

Frequently asked questions

Where does customer data reside?
On managed cloud infrastructure subject to access controls and encryption. Current provider and region details are supplied during security review and in the DPA.
Is SOP or record content used to train AI models?
No. Clinplex does not use customer content to train or fine-tune models. Third-party processing terms are disclosed during security review.
How are 21 CFR Part 11 requirements addressed?
Clinplex is not the customer's system of record. For records it creates, Clinplex implements identity, access, audit, session and electronic-signature controls designed to support applicable Part 11 requirements. The detailed control mapping is available under NDA.
Is a BAA available for HIPAA?
No. Clinplex does not currently offer a BAA. Do not send protected health information; redact records before transfer.
Where can I review detailed architecture and testing evidence?
Architecture, current subprocessors, provider attestations, independent-testing status, validation documentation and detailed security controls are provided through the security-review process under NDA.

Need the full packet?

Architecture overview, the 21 CFR Part 11 control mapping, the validation documentation set, DPA and sub-processor agreements are available under NDA. One email, one business day.

Request the security packet →