Verixa — AI-enabled compliance platform for regulated pharma

Designed against FDA 21 CFR Part 11 · EU Annex 11 · ICH Q9 · FDA CSA (as a design reference)

Verixa needed a governed-AI workflow platform for regulated pharma — engineered without trading regulatory rigour for speed. Sense7Ai partnered as engineering and delivery partner to design, build, and verify it under a controlled SDLC. The customer validates intended use.

The platform supports complex compliance workflows across quality management, electronic records, and inspection preparation — built on a secure, scalable, enterprise-ready architecture.

At a glance

A Sense7Ai ProductLive · production
Engagement
Engineering, Validation & Delivery Partner
Outcome
Phase 1 deliveredpre-validationdesign-partner stage
Frameworks in scope
FDA 21 CFR Part 11EU Annex 11ICH Q9 (QRM)FDA CSA
Stack
TypeScript (React + Vite)Node.js, Fastify 5PostgreSQL + pgvectorAWS
Controls in scope07
Tamper-evident Audit Trail
Electronic Signatures
Validation-Support Templates (IQ/OQ/PQ)
CAPA Workflows
Role-Based Access Control
Human-in-loop Review
Structured Evidence for QA Review
Constraints

The challenges

Verixa needed to validate the market and ship a production-ready pharma compliance platform fast — without trading regulatory rigour for speed.

CONSTRAINT-01Non-negotiable
REQ

Multiple regulatory frameworks, one coherent platform.

NOTE

Quality management, electronic records, and inspection preparation each carry distinct requirements under FDA 21 CFR Part 11, EU Annex 11, ICH Q9, and FDA CSA. Bolting them together post-build wasn't an option — the architecture had to satisfy all four from day one.

CONSTRAINT-02Non-negotiable
REQ

Validation support engineered in, not retrofitted.

NOTE

IQ/OQ/PQ template support, change traceability, and controlled documentation were engineered from the start.

CONSTRAINT-03Non-negotiable
REQ

Evidence organised for QA review by default.

NOTE

Audit trails designed for engineers do not survive a regulator's read. Every record is designed to surface in a form that supports QA review and inspection preparation — not reconstructed in a remediation cycle.

Six capabilities Sense7Ai delivered

Together, these six capabilities form the Verixa compliance platform — a single system regulated pharma teams use for quality management, electronic records, and inspection preparation.

Electronic Records & Audit Traceability

Tamper-evident audit logging with end-to-end traceability, electronic signature support, historical activity visibility, and structured audit workflows that support QA review and inspection preparation — mapped to FDA 21 CFR Part 11 and EU Annex 11 requirements.

Frameworks
21 CFR Part 11EU Annex 11
Controls
Tamper-evident Audit TrailElectronic SignaturesStructured Evidence for QA Review

Quality & Risk Management Workflows

Risk-based quality management workflows covering deviation management, CAPA tracking and review, risk classification processes, effectiveness verification, and controlled approval mechanisms aligned to ICH Q9.

Frameworks
ICH Q9
Controls
CAPA Workflows

Workflow Governance & Recorded Handoffs

Bounded quality workflows (Document Control, Deviation, RCA, CAPA) with configurable, recorded human decision gates between them, per the customer's approved procedure.

Frameworks
Human-in-the-loop
Controls
Human-in-loop Review

Validation & Compliance Infrastructure

Risk-based validation support aligned to FDA CSA principles as a design reference — validation-support templates, controlled test documentation, change traceability, and evidence management. The customer owns intended-use validation.

Frameworks
FDA CSA
Controls
IQ/OQ/PQ Validation

Role-Based Access & Approval Controls

Granular role-based permissions, controlled workflow approvals, electronic acknowledgement support, user activity traceability, and segregation-of-duty controls.

Frameworks
RBACE-acknowledgement
Controls
Role-Based Access Control

Compliance Dashboards & Secure Cloud Infrastructure

Centralised compliance dashboards and audit evidence workflows for quality leads and inspectors — running on controlled data ingestion pipelines, secure processing infrastructure, and customer-isolated cloud environments on AWS.

Stack
AWSCustomer-isolated
Operating tenets

Engineering approach

Compliance infrastructure is first-class architecture

Audit trails, validation evidence, and traceability records are structural requirements, not features. The platform cannot record a controlled event without also generating its inspector-readable evidence.

Validation effort is risk-proportional

Following FDA CSA guidance, validation evidence was scoped to the actual risk each component carries to product quality. High-risk components received full IQ/OQ/PQ; lower-risk components received scaled evidence proportional to their risk profile.

Human oversight on regulated decisions

Deviation dispositions, CAPA approvals, and controlled workflow sign-offs include human-in-the-loop gates. Automation supports — it does not replace — regulated human judgement.

Evidence organised for review by design

All audit trails and verification records surface through views designed for quality teams' QA review and inspection preparation.

Engagement model

How we worked

Dedicated engineering pod against a written SOW under the Sense7Ai MSA, working alongside Verixa stakeholders and domain experts throughout the engagement. Agile delivery with bi-weekly sprint cycles, weekly stakeholder reviews, and validation-focused documentation maintained continuously. Traceability support carried through every sprint output.

StackTypeScript (React + Vite), Node.js with Fastify 5, PostgreSQL + pgvector, AWS secure cloud infrastructure with customer-isolated deployment environments.

Outcomes

Delivered: Phase 1 GMP quality workflows, verified under a controlled SDLC.

Program status · Verixa · Design-partner stage · pre-validationVerified under SDLC · risk-scaled · evidence-bound

The Verixa platform is complete for Phase 1 scope and is in the design-partner stage, pre-validation.

Operational outcomes will be published by Verixa only after verified customer results exist, with written approval.

Detailed timelines and performance data are withheld under confidentiality obligations.

Frequently asked questions

Is the Verixa platform 21 CFR Part 11 compliant?
Verixa provides controls intended to support applicable 21 CFR Part 11 requirements — tamper-evident audit logging, electronic signatures, access controls. Compliance is a customer determination based on intended-use validation; verification of the e-signature substrate is in progress in the design-partner stage.
What regulatory frameworks does Verixa support?
Verixa is built for FDA 21 CFR Part 11, EU Annex 11, ICH Q9 (Quality Risk Management), and FDA CSA (Computer Software Assurance) validation principles. These frameworks informed the architecture from the start, rather than being addressed as bolt-on modules.
Does Verixa support IQ/OQ/PQ validation?
Verixa provides risk-based validation-support templates and evidence aligned to FDA CSA principles — controlled test documentation, change traceability, and evidence management, scaled to component risk. The customer executes and owns validation for its intended use.
What audit evidence is provided to inspectors?
Audit trails and verification records surface through structured views designed to support the customer's QA review and inspection preparation. Verixa does not determine inspection readiness.

Ready to build your regulated pharma AI platform?

Tell us about the compliance platform you need to ship. Qualified inquiries typically receive a same-day or next-business-day response; scoping calls follow within five business days, subject to availability.

Schedule a scoping callCheck the diligence pack