Skip to content
Security & compliance

Written for the people who vet us.

This page is for Quality and IT reviewers. It states our regulatory posture, validation approach, AI governance, and security controls plainly — no marketing language. For a security questionnaire or right-to-audit request, contact us directly.

01

Regulatory posture

Quorum is built to operate as a regulated GxP system for pharmacovigilance case management.

21 CFR PART 11
Electronic records and signatures, with attributable, contemporaneous, and enduring audit logs.
EU ANNEX 11
Alignment for computerised systems used in GxP environments.
E-SIGNATURES
Bound to the approving user, action, and timestamp; non-repudiable.
AUDIT LOGS
Immutable, append-only record of every change to a case.
02

Validation

We follow a GAMP 5 / computerised-system-validation (CSV) approach, and ship the validation documentation package with deployment — what we call validation-in-a-box. It is designed so your Quality team can review and approve, not rebuild.

INCLUDED IN THE PACKAGE
  • · Validation plan & risk assessment
  • · Requirements & traceability matrix
  • · IQ / OQ / PQ protocols & evidence
  • · Test scripts and results
  • · Release & change-control records
  • · Validation summary report
03

AI governance

Most safety systems have no answer here. This is where ours is strongest — because AI in a regulated workflow is only acceptable if it is controlled, traceable, and never the final authority.

Human-in-the-loop by design

AI proposes; a qualified person commits. Nothing is submitted without sign-off.

Traceable to source

Every AI output links to the exact source text it was derived from.

Versioning & change control

The model version behind each suggestion is recorded and governed by change control.

Evaluation & drift monitoring

Ongoing evaluation against held-out cases, with monitoring for performance drift.

Accuracy reported the way you would want to see it

Scoped by dataset and term type against a named baseline, not one number on a slide — and we would rather you validated it on a pilot with your own cases than took ours.

A person decides, at every step

No AI output becomes a submitted value without a qualified reviewer approving it. That is the CIOMS Working Group XIV baseline, not our innovation.

POLICYNo training on customer data. Your cases are never used to train shared models.
WHAT WE ALIGN TO
CIOMS Working Group XIV — Artificial Intelligence in Pharmacovigilance, final report December 2025

The closest thing to harmonised international guidance on AI in pharmacovigilance. Its seven principles — risk-based approach, human oversight, validity and robustness, transparency, data privacy, fairness, and governance — are the frame we design against. On accountability it is unambiguous: legal and ethical responsibility remains with the human organisation, because AI systems cannot be held responsible. Nothing in Quorum is built on the assumption that software can carry that.

FDA — draft guidance, Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products (7 January 2025)

Sets out a seven-step, risk-based credibility assessment: define the regulatory question and context of use, assess model risk as influence times consequence, and document a credibility plan proportionate to that risk. It covers post-marketing use explicitly. We maintain that documentation per model and will share it under NDA.

EMA — Reflection paper on the use of Artificial Intelligence in the medicinal product lifecycle (EMA/CHMP/CVMP/83833/2023, adopted 30 September 2024)

A risk-based and human-centred approach to AI across the lifecycle, including the post-authorisation setting, aligned to existing GxP and ICH Q8–Q10 expectations rather than sitting outside them.

EMA — Good Pharmacovigilance Practices Module I, section I.C.1.5, on tasks subcontracted by the marketing authorisation holder

Whatever you delegate — to a provider or to a system — stays inside your pharmacovigilance system and your quality system. Quorum is built to be audited as part of it, not around it.

04

Security

SOC 2
Type II in progress; the current report is available under NDA. [confirm status]
ENCRYPTION
Encrypted in transit (TLS 1.2+) and at rest (AES-256).
ACCESS CONTROL
Role-based access, SSO / SAML, and least-privilege by default.
DATA RESIDENCY
Region selection for hosting and data residency. [confirm regions]
SUBPROCESSORS
Current subprocessor list available on request; changes notified in advance.

Security questionnaires & right-to-audit

Send questionnaires, request the SOC 2 report under NDA, or arrange an audit.

security@usequorum.ai