Compliance
GLP work has to be defensible years after the study closes. These are the controls the system carries, and the ones still ahead.
Every entry carries who wrote it and when, in an append-only record. Corrections are recorded as corrections — the prior value stays readable and the change is attributed. Nothing is overwritten in place.
Agents write to the same record as people. Work done by an automation is attributed to the automation and to the human whose key it used, so an audit trail never contains an action nobody is accountable for.
People sign in through your identity provider, so account lifecycle stays where your IT already manages it. Access is scoped by team, and a sponsor sees the studies delivered to them and nothing else.
Agents reach the system through scoped API keys that a named human grants and can revoke. A key is issued for a purpose, not handed out permanently, and revoking one takes effect immediately.
Part 11 asks for attributable, contemporaneous, and durable records; for controls on who may act; and for electronic signatures bound to the records they sign.
Signing a notebook entry demands two identification components at the moment of signing, per 11.200 — a live session is not enough. The signer re-enters their credentials and they are verified against your identity provider right then. An air-gapped deployment substitutes its own two-component check at the same seam rather than losing the control.
A signed entry is immutable, and not only by convention: the database itself refuses to rewrite one. A correction is a new entry that names the original, and the original stands as signed. GLP's second pair of eyes is a countersign — a witness attests to work, and the system will not let the signer witness their own.
Each deployment ships with a validation package: the requirements, the tests that exercise them, and the evidence they passed on the build you are running. Agentic testers produce it, which is what makes a system built for one lab affordable to qualify.
The package supports your qualification; it does not replace it. Installation, operational, and performance qualification for your intended use happen inside your quality system, and that system is yours.
Because you upgrade on your own schedule, revalidation happens when you choose to take a change rather than when a vendor pushes one.
Each customer runs its own deployment and its own database. There is no shared multi-tenant store holding your study data next to another lab's, which is the answer to most of the questions a sponsor asks about segregation.
Retention follows the study: the audit record is kept for the life of the study and its statutory retention period, not for a subscription term.
The domain model is arranged around the SEND datasets from the start. Subject disposition, reference start dates, test codes, and substance identifiers use SEND's own controlled terms in the columns you enter them into, so a delivery is a projection of your data rather than a conversion pass that reinterprets it. Fewer transformations between the bench and the submission means fewer places for the data to drift.
The export itself is the work in front of us. The vocabulary is in place today; the packaged deliverable is not yet shipped, and we will say so here until it is.
The audit record
Access and attribution
21 CFR Part 11
Validation
Where your data lives
Data integrity and delivery
This page describes controls, not a certification. We have not been through a third-party audit, and we will say so here when that changes.
Send them to hello@vsqrd.com and you will get answers from the people who built it.
Questions from your QA