Document CPX-TRUST-001Version 4.0Effective 10 Sep 2026Next review 10 Dec 2026Owner security@clinplex.com
Trust

Read-only by design. Verifiable by default.

Clinplex reads regulated records. It never writes to your validated systems, never trains a model on your data, and deletes what you send on request. This page states what we implement, what we inherit from hosting providers, and what is in progress. It also carries our privacy policy and terms of use. It is versioned and reviewed like any other controlled document.

Read-only.

No write access to your QMS, LIMS, validation or ERP systems. Findings are exported to you; nothing flows back.

Never trained on.

Your records are not used to train, fine-tune or evaluate any model, ours or a provider's.

Deleted on request.

Clinplex-controlled source records and derived findings are deleted when you ask, confirmed in writing.

NDA first.

A mutual NDA is executed before any record is exchanged, including for the free Inspection Stress Test.

How a record moves

One document, from the moment you agree to send it to the moment it no longer exists on our side.

  1. Mutual NDA

    Sent within one business day of your request. No records change hands before signature.

  2. Transfer

    By reply email or a secure link you specify. Redacted records are accepted. For pilots and deployments, read-only connectors pull records from your systems.

  3. Processing

    Records are evaluated against the frameworks that govern them. Access is gated by role, and every action is written to the audit chain with the user's identity.

  4. Findings

    Ranked gaps, the governing clause for each, linked-record impact and a drafted remediation. Every finding is time-stamped and attributable.

  5. Retention and deletion

    Clinplex-controlled copies are retained for the duration of the engagement, then deleted. Deletion is available on request at any time and confirmed in writing.

Infrastructure and application controls

Hosting
Managed cloud infrastructure with controlled database, object-storage and backup services. Architecture and current sub-processors are provided during security review under NDA.
Encryption
HTTPS/TLS in transit. Provider-managed encryption at rest for application data and stored objects. Key-management detail is available during diligence.
Backups
Managed backups with restore and integrity verification. Recovery architecture is documented in the security packet.
Secrets and headers
Application secrets are managed outside source code with restricted access and automated scanning. Security headers are applied at the application and edge layers.
Network accessImplemented
Authentication and analysis endpoints are protected by application and managed-edge controls. Administrative access paths are restricted under least privilege.
Incident responseImplemented
Documented incident-response procedure. Customer notification obligations and timelines follow the applicable agreements and law. Report a vulnerability to security@clinplex.com; good-faith reporters are not pursued.

21 CFR Part 11 technical controls

Clinplex is not a system of record. Your QMS, LIMS and validation systems remain authoritative, so your validated state is unchanged. For the records Clinplex itself creates, these controls are implemented today.

21 CFR 11.10(d)

Unique user identification

Every user has a unique identifier; attributable actions carry into the audit trail.

21 CFR 11.10(e)

Immutable, timestamped audit trail

Record creation and change events are captured in a tamper-evident, attributable audit trail with controlled change history.

21 CFR 11.10(d)

System access controls

Role-based access, configurable per organization, with separate roles for QA, regulatory affairs, IT and admin.

21 CFR 11.10(g)

Session and authority checks

Configurable inactivity limits, re-authentication for sensitive actions, and operations checked against the user's authority.

21 CFR 11.50, 11.70

Electronic signatures

Signatures bind printed name, date, time and meaning to the record. Manifests are append-only and cannot be transferred to another record.

Validation

Documentation set

A validation documentation set and the full Part 11 control mapping are available under NDA.

AI processing controls

Clinplex uses controlled model-inference services as one component of the analysis workflow. Customer content is never used to train or fine-tune models.

Transfer
Records move over encrypted channels under access controls appropriate to the engagement.
InferenceContractual
Where third-party inference is used, processing occurs under enterprise/API terms and contractual controls. Provider, retention and data-flow detail is disclosed in the security packet and DPA.
Attribution
Returned findings are tied to their regulatory basis and retained with attributable audit information inside Clinplex.
Human accountabilityImplemented
Model output is advisory. Final compliance, gap and CAPA decisions remain with named, qualified reviewers.

Compliance and assurance

Control areaStatus
Provider infrastructure assurance and attestationsInherited
21 CFR Part 11-supporting application controlsImplemented
SOC 2 Type II, application layerIn progress
HIPAA Business Associate AgreementNot offered · do not send PHI

Sub-processors: Clinplex uses contracted providers for hosting, storage, model inference, business communications and this website. The current list, purposes, regions and terms are supplied in the DPA and security packet before any customer data is processed; customers under a DPA are notified of changes per the agreement.

Need the full packet?

Architecture overview, the 21 CFR Part 11 control mapping, the validation documentation set, DPA and sub-processor agreements are available under NDA. One email, one business day.

Request the security packet →