— Compliance →

Audit-ready is a state, not a scramble.

Most systems bolt a compliance module onto the same disconnected stores. Holonyx puts 21 CFR Part 11 in the schema: the record and its evidence are the same object, and the chain that proves it is verifiable end to end, on demand.

holonyx · GET /api/audit/verify-chain?org=acme-bio
# walks every AuditEntry in sequence order and recomputes the chainentries 128,904from 2026-01-02T09:14:07Zto 2026-09-10T16:52:41Zrecomputed 128,904 / 128,904first_break nonestatus CHAIN INTACT ✓

Illustrative output — the figures are an example. The endpoint is real: the chain is per-organization and independently verifiable, so an inspector can run it, not just read a claim about it.

The mechanisms

  1. 01

    A permanent, tamper-evident history

    Every change to a record is logged automatically — who, what, when, and the new value — and each entry is cryptographically linked to the one before it. Edit or delete an entry after the fact, and the break in the chain is immediately visible.

    §11.10(e)
  2. 02

    Signatures tied to the exact thing they approved

    A signature is bound to the exact content it signed off on. If that content changes afterward, the signature no longer matches — and the mismatch is flagged, not hidden. Who signed, what it meant, and when are stored with the record itself, not in a separate log that can drift out of sync.

    §11.50 / §11.70 / §11.100 / §11.200
  3. 03

    Approval status that updates itself

    A batch record's status (green / yellow / red) updates the moment something relevant is signed — not on a fixed review calendar. It's always accurate, because nothing that feeds into it can change without leaving a signature.

    periodic-review replacement
  4. 04

    Validation documents live in the same system

    Your requirements, design specs, qualification protocols and reports, and deviations (URS, FRS, DQ/IQ/OQ/PQ, SVSR) are real records here — not PDFs in a separate folder — and stay traceably linked to exactly what they validate.

    GAMP 5 aligned

— In the schema →

These rules are enforced the moment the system starts — before it accepts a single request. Integrity is not a runtime hope.

data-model · excerpt
# every audit entry must be unique — no duplicate historyREQUIRE UNIQUE AuditEntry.id# every entry has exactly one place in the sequence, per organizationREQUIRE UNIQUE AuditEntry.(organization, sequence_no)# hash = SHA-256( previous entry's hash | id | time | user | action | record | new value )AuditEntry → PREVIOUS → AuditEntry # the chainAuditEntry → BELONGS TO → Organization

The audit trail

Append-only, hash-chained, verifiable on demand.

Every create, update, delete, sign, approve and export across every module is logged with user, role, IP and session — and the Chain Integrity tab recomputes the whole chain and reports any break.

Audit trail with chain integrity status

Part 11, control by control

Each control shows its configured status.

Unique user IDs, electronic signatures, audit trail, record integrity, access controls, system validation, operational and authority checks — with the evidence and the reference for each.

Compliance configuration listing 21 CFR Part 11 controls

Validation

URS to SVR, tracked in the product, honest about where you are.

The Quality & CSV Hub tracks systems through the V-model with requirements traceability and an FMEA register. Approving a workflow, schema or result schema drafts the Performance Qualification protocol that qualifies the change. Nothing shows as validated until real qualification steps have run.

Quality and CSV hub

Documents

Evidence linked to the thing it proves.

Generated qualification documents live in the Document Vault with lifecycle status and link back to the protocol that produced them — no orphaned PDFs in a shared folder.

Document vault

Bring your CSV lead to the walkthrough.

We will run verify-chain against a seeded org, sign a batch record, and show the qualification state move — live.

Book a walkthrough