Read-only by design. Verifiable by default.
Clinplex reads regulated records. It never writes to your validated systems, never trains a model on your data, and deletes what you send on request. This page states what we implement, what we inherit from hosting providers, and what is in progress. It also carries our privacy policy and terms of use. It is versioned and reviewed like any other controlled document.
Read-only.
No write access to your QMS, LIMS, validation or ERP systems. Findings are exported to you; nothing flows back.
Never trained on.
Your records are not used to train, fine-tune or evaluate any model, ours or a provider's.
Deleted on request.
Clinplex-controlled source records and derived findings are deleted when you ask, confirmed in writing.
NDA first.
A mutual NDA is executed before any record is exchanged, including for the free Inspection Stress Test.
How a record moves
One document, from the moment you agree to send it to the moment it no longer exists on our side.
Mutual NDA
Sent within one business day of your request. No records change hands before signature.
Transfer
By reply email or a secure link you specify. Redacted records are accepted. For pilots and deployments, read-only connectors pull records from your systems.
Processing
Records are evaluated against the frameworks that govern them. Access is gated by role, and every action is written to the audit chain with the user's identity.
Findings
Ranked gaps, the governing clause for each, linked-record impact and a drafted remediation. Every finding is time-stamped and attributable.
Retention and deletion
Clinplex-controlled copies are retained for the duration of the engagement, then deleted. Deletion is available on request at any time and confirmed in writing.
Infrastructure and application controls
21 CFR Part 11 technical controls
Clinplex is not a system of record. Your QMS, LIMS and validation systems remain authoritative, so your validated state is unchanged. For the records Clinplex itself creates, these controls are implemented today.
Unique user identification
Every user has a unique identifier; attributable actions carry into the audit trail.
Immutable, timestamped audit trail
Record creation and change events are captured in a tamper-evident, attributable audit trail with controlled change history.
System access controls
Role-based access, configurable per organization, with separate roles for QA, regulatory affairs, IT and admin.
Session and authority checks
Configurable inactivity limits, re-authentication for sensitive actions, and operations checked against the user's authority.
Electronic signatures
Signatures bind printed name, date, time and meaning to the record. Manifests are append-only and cannot be transferred to another record.
Documentation set
A validation documentation set and the full Part 11 control mapping are available under NDA.
AI processing controls
Clinplex uses controlled model-inference services as one component of the analysis workflow. Customer content is never used to train or fine-tune models.
Compliance and assurance
| Control area | Status |
|---|---|
| Provider infrastructure assurance and attestations | Inherited |
| 21 CFR Part 11-supporting application controls | Implemented |
| SOC 2 Type II, application layer | In progress |
| HIPAA Business Associate Agreement | Not offered · do not send PHI |
Sub-processors: Clinplex uses contracted providers for hosting, storage, model inference, business communications and this website. The current list, purposes, regions and terms are supplied in the DPA and security packet before any customer data is processed; customers under a DPA are notified of changes per the agreement.
What we hold, and what we don't.
This policy covers two things: what this website collects about visitors, and how Clinplex handles the regulated records customers send during an engagement. The second is governed primarily by the NDA and, where executed, a Data Processing Agreement.
Customer records during engagements
- Records are exchanged only after a mutual NDA is signed.
- Processing is read-only. Nothing is written back to your systems.
- Records are never used to train, fine-tune or evaluate any model, ours or a provider's.
- Records are retained for the duration of the engagement, then deleted. Deletion on request at any time, confirmed in writing.
- Do not send protected health information. Clinplex does not offer a BAA; redact before transfer.
Website visitors
Contact-form submissions and email correspondence are used to respond to you and are not sold or shared for marketing. The sub-processor list and a DPA are available on request.
Your choices
Email security@clinplex.com to access, correct or delete personal information we hold about you. We reply within one business day.
For clinplex.com. Engagements are governed by contract.
These terms cover use of this website. Product engagements, including pilots, the Inspection Stress Test and deployments, are governed by their own written agreements, including a mutual NDA and, where executed, a DPA. Where those agreements and this page differ, the agreements control.
Informational content
Content on this site describes Clinplex's capabilities and evaluation results as of the dates stated. It is not regulatory, legal or compliance advice, and it is not a representation that using Clinplex satisfies any regulatory requirement. Your obligations under applicable regulations remain yours.
Evaluation results
Published performance figures are defined and sourced in the claims register on the Evidence page. They describe measured results on the stated corpus and are not a guarantee of results on your records.
Acceptable use and intellectual property
Do not submit protected health information through this site or attempt to probe, scan or disrupt it. The Clinplex name, wordmark and site content belong to Clinplex. You may link to and quote this site with attribution; do not republish substantial portions without permission.
No warranty; limitation of liability
The site is provided as-is, without warranties of any kind. To the maximum extent permitted by law, Clinplex is not liable for damages arising from use of the site. Liability in product engagements is addressed in the applicable agreement.
Changes
This page, including the privacy policy and terms, is versioned like a controlled document. Material changes update the version and effective date above; customers under a DPA are notified of changes affecting them. Questions: security@clinplex.com.
Need the full packet?
Architecture overview, the 21 CFR Part 11 control mapping, the validation documentation set, DPA and sub-processor agreements are available under NDA. One email, one business day.
Request the security packet →