Product
CAPA is the spine, and it is not the whole skeleton. Documents, training, design controls, risk and change control sit on the same graph, so a record points at what it concerns and a change to one thing shows you everything it touches.
Core is what every organization runs and nobody can switch off — the registry carries the foreign keys the rest of the product hangs from, and the audit log records every write. Modules are scope choices: a company running design control in another tool turns Design off, and the QMS baseline reports that process as tracked elsewhere rather than as a gap.
Core
Complaints, nonconformances, deviations, audit findings and 483 observations land in one queue. Triage decides what becomes a CAPA and records why, either way. Product disposition (§820.90) and MDR reportability (Part 803) are recorded against the event, on their own clocks.
Core
Products, SKUs, suppliers, lots, processes and documents as real objects with typed relationships. Every record points at what it concerns, so a change to one product surfaces everywhere it ripples.
Core
Answer a short profile — device class, markets, pathway, stage — and get the processes you actually owe, with a written reason for anything you defer. The maturity view scores what is real evidence and what is still a gap.
Core
An append-only trail enforced by database triggers, and Part 11 signatures bound to a hash of the exact content signed. Both are below the application, not a convention inside it.
Module
Numbering, ownership, approval into effect against a frozen revision, periodic review dates and reminders. A document approved on paper before you arrived can be recorded as such without anyone signing an approval they did not give.
Module
Assign people to acknowledge a specific effective version — from a CAPA action, or as a programme: onboarding, annual refreshers, a revision going effective. Completion is an e-signature bound to the version they read.
Module
User needs, inputs, outputs, verification and validation as a traceability matrix that names its own gaps. ISO 14971 hazards, risk evaluation and controls sit on the same graph, so an uncontrolled risk is visible rather than filed.
Module
A change walks the registry and reports what it touches — documents, training, design objects, signed reviews — and each item needs a disposition before the change can be approved.
Core
The ISO 13485 §5.6.2 input pack, assembled from the records themselves. A surface you do not run prints as a bordered statement with write-in lines, never as a zero — a missing input reads to an auditor as one nobody considered.
The CAPA loop is the one an inspector expects to see, and it is where the rest of the system converges. Every stage cites the regulation it satisfies, so the structure of your quality system matches the structure of the audit.
Complaints, deviations, audit findings, and internal reports all land as quality events — from the web form, an email inbox, or the intake API.
Not every event becomes a CAPA. Triage records the decision either way, with a rationale, so a reviewer can see why something was closed without escalation.
Structured 5-Whys and Fishbone tools keep the investigation on the record instead of in a side document nobody can find later.
Actions are typed as correction, corrective, or preventive, each with an owner and a due date, so the plan is auditable rather than narrative.
Owners work their actions and attach evidence. Nothing advances to verification while an action is still open.
Effectiveness checks are their own gated step with a defined method and acceptance criteria — not a checkbox on the way to closure.
Every transition writes to an append-only audit trail, and closure requires an e-signature bound to the exact record content it approves.
Dashboards surface overdue actions, aging CAPAs, and the recurring themes across events for management review.
The parts of a quality system that are tedious to build, expensive to buy, and easy to get subtly wrong.
A web form, a monitored email address, an FDA Form 483 import, and a JSON API all feed the same queue. Nothing arrives in a channel the quality team has to remember to check.
Transitions are enforced in the database, not suggested in the UI. A CAPA cannot skip verification or close with an open action, whoever is clicking.
The dashboard answers what you personally owe and what the organization owes, across every surface you run. A module switched off contributes nothing to it, without any screen having to know why.
Full-text and faceted search across events, investigations, and actions, so you can tell whether this failure has happened before.
Attach photos, test data, and supporting files directly to the record. Files are stored under opaque keys, never the original filename.
Reporters raise events, investigators own actions, quality approvers sign, admins run the org. Permissions are enforced server-side on every query, and every tenant is isolated at the database, not only in the application.
One or two people carrying quality alongside another job. The system has to be usable without a training course.
A notified body, an FDA inspection, or a customer audit — and your CAPA evidence is currently spread across three tools.
It worked at ten CAPAs. At sixty, nobody can tell you which are overdue or whether the last fix actually held.
Free to start. No enterprise contract, no six-month implementation, and nothing behind a demo call.