Electronic records, controlled and trusted.
TruTechnologies is designed to support 21 CFR Part 11.10 — the FDA’s closed-system controls for electronic records in clinical research.
What 21 CFR Part 11.10 requires.
Part 11 sets the criteria under which the FDA considers electronic records to be trustworthy, reliable, and equivalent to paper records. It applies to records created, modified, maintained, archived, retrieved, or transmitted under any FDA predicate rule — including GCP-regulated clinical trials.
Meeting § 11.10 is not a single feature — it is a combination of data integrity, strict access controls, independent tracking, and rigorous system validation. TruTechnologies delivers all four.
Four pillars of § 11.10 compliance.
Validated systems
Computer System Validation aligned with GAMP 5. IQ/OQ/PQ documentation, traceability matrices, and release records available under NDA.
Secure user authentication
Access requires unique credentials. The system encrypts passwords, enforces strong selection criteria, and automates credential expiration.
Secure, time-stamped audit trails
Every create, read, update, and delete action is recorded with attributable user, UTC timestamp, and before/after values — independent of operator control.
Access & authority checks
Role-based access, MFA, and authority checks ensure only authorized individuals can use the system or alter operations.
Electronic records controls.
Here’s how key § 11.10 requirements map to supporting TruTechnologies capabilities for electronic records.
Systems are validated to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.
Records are generated in electronic and human-readable forms suitable for agency inspection, review, and copying.
Records are protected to enable accurate and ready retrieval throughout the retention period.
Access is limited to authorized individuals via unique credentials, role-based permissions, and automated password expiration.
Secure, computer-generated, time-stamped audit trails capture operator actions that create, modify, or delete electronic records.
Workflow sequencing and operational checks enforce protocol-defined steps and prevent out-of-order events.
Authority checks ensure only individuals with administrator-managed permissions can execute system tasks and access information.
Data input and operational sources are validated and secured using strict HTTPS protocols.
Personnel managing client-facing systems are verified to be fully trained on all relevant security policies and SOPs.
System documentation is protected via strict access controls and a formal, time-sequenced Quality Management System.
Audit-ready documentation.
Sponsors and CROs can request our full Part 11 validation package under NDA, including:
GAMP 5–aligned plan governing scope, risk, and approach.
Installation, operational, and performance qualification with executed evidence.
User and functional requirements traced to test cases and code.
Documented analysis of system functionality, data integrity, and product quality risk.
SOPs for change management, release approval, and emergency fixes.
Representative exports demonstrating completeness and immutability.
Need our Part 11 package for an audit?
We'll share validation evidence, SOPs, and a clause-by-clause compliance matrix under NDA — typically within two business days.