Written for the people who vet us.
This page is for Quality and IT reviewers. It states our regulatory posture, validation approach, AI governance, and security controls plainly — no marketing language. For a security questionnaire or right-to-audit request, contact us directly.
Regulatory posture
Quorum is built to operate as a regulated GxP system for pharmacovigilance case management.
- 21 CFR PART 11
- Electronic records and signatures, with attributable, contemporaneous, and enduring audit logs.
- EU ANNEX 11
- Alignment for computerised systems used in GxP environments.
- E-SIGNATURES
- Bound to the approving user, action, and timestamp; non-repudiable.
- AUDIT LOGS
- Immutable, append-only record of every change to a case.
Validation
We follow a GAMP 5 / computerised-system-validation (CSV) approach, and ship the validation documentation package with deployment — what we call validation-in-a-box. It is designed so your Quality team can review and approve, not rebuild.
- · Validation plan & risk assessment
- · Requirements & traceability matrix
- · IQ / OQ / PQ protocols & evidence
- · Test scripts and results
- · Release & change-control records
- · Validation summary report
AI governance
Most safety systems have no answer here. This is where ours is strongest — because AI in a regulated workflow is only acceptable if it is controlled, traceable, and never the final authority.
AI proposes; a qualified person commits. Nothing is submitted without sign-off.
Every AI output links to the exact source text it was derived from.
The model version behind each suggestion is recorded and governed by change control.
Ongoing evaluation against held-out cases, with monitoring for performance drift.
Scoped by dataset and term type against a named baseline, not one number on a slide — and we would rather you validated it on a pilot with your own cases than took ours.
No AI output becomes a submitted value without a qualified reviewer approving it. That is the CIOMS Working Group XIV baseline, not our innovation.
The closest thing to harmonised international guidance on AI in pharmacovigilance. Its seven principles — risk-based approach, human oversight, validity and robustness, transparency, data privacy, fairness, and governance — are the frame we design against. On accountability it is unambiguous: legal and ethical responsibility remains with the human organisation, because AI systems cannot be held responsible. Nothing in Quorum is built on the assumption that software can carry that.
Sets out a seven-step, risk-based credibility assessment: define the regulatory question and context of use, assess model risk as influence times consequence, and document a credibility plan proportionate to that risk. It covers post-marketing use explicitly. We maintain that documentation per model and will share it under NDA.
A risk-based and human-centred approach to AI across the lifecycle, including the post-authorisation setting, aligned to existing GxP and ICH Q8–Q10 expectations rather than sitting outside them.
Whatever you delegate — to a provider or to a system — stays inside your pharmacovigilance system and your quality system. Quorum is built to be audited as part of it, not around it.
Security
- SOC 2
- Type II in progress; the current report is available under NDA. [confirm status]
- ENCRYPTION
- Encrypted in transit (TLS 1.2+) and at rest (AES-256).
- ACCESS CONTROL
- Role-based access, SSO / SAML, and least-privilege by default.
- DATA RESIDENCY
- Region selection for hosting and data residency. [confirm regions]
- SUBPROCESSORS
- Current subprocessor list available on request; changes notified in advance.
Security questionnaires & right-to-audit
Send questionnaires, request the SOC 2 report under NDA, or arrange an audit.