Designed and tested against 21 CFR Part 11.
The controls below are built into the data layer, not bolted on. Nexrial is software, not a compliance certification — the controls are real and verifiable; the validation attestation is yours to make, with the evidence we provide.
Immutable audit trail
Every create, update, and signature is captured at the database layer with the user, a server-side timestamp, and the reason for change. Entries can’t be edited or switched off.
21 CFR §11.10(e)Native e-signature manifestations
Each electronic signature records the signer’s identity, the date and time, and the meaning of the signing (review, approval, responsibility) — bound to the record it signs.
21 CFR §11.50 · §11.70Delegation-driven access
The delegation of authority log governs system permissions: access is limited to authorized individuals, and what each person can do mirrors what an inspector reviews on day one.
21 CFR §11.10(d)Authority checks
Only authorized individuals can use the system, sign a record, or perform a delegated operation — enforced against the same delegation log, not a separate permission table.
21 CFR §11.10(g)Record retention & export
Records are protected for accurate, ready retrieval throughout the retention period, with full on-demand export in standard formats — no lock-in, no exit fee.
21 CFR §11.10(c)Unique credentials
Each user has a unique account; signings are attributable to one identifiable person. Administrative actions are themselves logged in the audit trail.
21 CFR §11.300The two documents an inspector asks for first.
Nexrial keeps both current automatically. The delegation log governs system access; the audit trail records every edit with its reason. No reconstructing binders the night before.
Sample records, de-identified. Audit entries can’t be edited or switched off — that’s the point of §11.10(e).
Where AI touches your records.
AI assists; people decide.
Nexrial uses AI to assist with drafting and analysis — protocol summaries, adverse-event narratives, and eligibility checklists. Every output is a clearly-marked draft.
All regulated records require human review and signature; AI does not sign or approve controlled records. AI runs on enterprise infrastructure under contract, and your data is never used to train third-party AI models.
What sponsors and monitors ask.
Is Nexrial validated against 21 CFR Part 11?
Nexrial is designed and tested against 21 CFR Part 11 — audit trail, native e-signatures, and access controls. Validation documentation is available for your procurement and sponsor review. (Nexrial is software, not a compliance certification — the controls are real; the attestation is yours to make with the evidence we provide.)
Can monitors and CRAs get access?
Yes — scoped, read-only monitor access for visits, so a CRA reviews exactly what they need without touching your live data.
Do you sign a HIPAA BAA?
Yes. A Business Associate Agreement is executed before any PHI is entered into the Service — not after onboarding, not on request. Request the BAA →
Where does AI touch my regulated records?
Only where you invoke it, and only to produce clearly-marked drafts for human review — protocol summaries, AE narratives, eligibility checklists. AI does not sign or approve controlled records. Your data is never used to train third-party AI models.
Can I export my data and audit trail?
Yes — full export on demand, anytime, in standard formats, including the audit trail. No lock-in and no exit fee, during the subscription and after it.