Skip to content

Compliance

Cohera is designed from the ground up to support regulatory compliance in pharmaceutical environments. This section provides detailed documentation on how Cohera meets regulatory requirements and guidance for your validation activities.

Cohera supports compliance with major pharmaceutical regulations:

Cohera implements compliance controls as core platform features, not add-ons:

PrincipleCohera Implementation
AttributableEvery action linked to authenticated user with timestamp
LegibleData displayed clearly with full history accessible
ContemporaneousActions recorded at time of occurrence
OriginalOriginal records preserved; changes create new versions
AccurateValidation rules enforce data accuracy
CompleteFull audit trail with no gaps
ConsistentStandardized data entry and validation
EnduringData stored securely with configurable retention
AvailableData accessible for review throughout retention period
  • Immutable audit trails: All changes recorded with before/after values
  • Version control: Complete history of all record changes
  • Access controls: Role-based permissions with audit logging
  • Data integrity checks: Checksums and validation on all records
  • Signature manifestations: Clear indication of signature meaning
  • Signature binding: Cryptographic link between signature and record
  • Non-repudiation: Signatures cannot be removed or altered
  • Authority verification: System validates signer’s authority
  • Multi-factor authentication support
  • Single sign-on (SSO) integration
  • Password policies configurable per organization
  • Session timeout controls
  • Role-based access control (RBAC)
  • Object-level permissions
  • Field-level security for sensitive data
  • Separation of duties enforcement
  • Complete audit trail for all actions
  • Tamper-evident logging
  • Secure audit log storage
  • Audit trail export for regulatory review

Cohera provides documentation and tools to support your Computer System Validation (CSV) activities:

DocumentDescription
System Design SpecificationArchitecture and design documentation
Functional SpecificationDetailed feature documentation
User Requirements TemplateTemplate for defining your requirements
IQ Protocol TemplateInstallation Qualification protocol
OQ Protocol TemplateOperational Qualification protocol
PQ Protocol TemplatePerformance Qualification protocol
Traceability MatrixRequirements to test traceability
SOPsStandard operating procedures
┌─────────────────────────────────────────────────────────┐
│ VALIDATION ENVIRONMENTS │
├─────────────────────────────────────────────────────────┤
│ DEVELOPMENT (DEV) │
│ - New features and fixes │
│ - Not validated │
├─────────────────────────────────────────────────────────┤
│ QUALIFICATION (UAT) │
│ - IQ/OQ/PQ execution │
│ - Customer validation testing │
├─────────────────────────────────────────────────────────┤
│ PRODUCTION (PROD) │
│ - Validated, GxP data │
│ - Change controlled │
└─────────────────────────────────────────────────────────┘

All changes to Cohera follow a documented change control process:

CategoryDescriptionCustomer Impact
CriticalSecurity patches, data integrity fixesImmediate deployment with notification
MajorNew features, significant changesAdvance notice, validation impact assessment
MinorBug fixes, UI improvementsRelease notes, minimal validation impact
ConfigurationCustomer-specific settingsCustomer-controlled
  1. Development: Feature developed and tested
  2. Internal QA: Quality assurance testing
  3. Staging: Pre-production validation
  4. Release Notes: Documentation published
  5. Deployment: Staged rollout
  6. Verification: Post-deployment checks

Cohera maintains qualification as a software supplier:

  • ISO 27001 certified information security management
  • SOC 2 Type II audited controls
  • Regular third-party security assessments
  • Documented software development lifecycle (SDLC)

Cohera supports customer and regulatory audits:

  • Remote audit capability
  • On-site audit scheduling (Enterprise customers)
  • Audit questionnaire completion
  • Evidence package preparation

Cohera supports data residency requirements:

RegionData Center Location
USAWS us-east-1 (N. Virginia)
EUAWS eu-west-1 (Ireland)
APACAWS ap-northeast-1 (Tokyo)

Data does not leave the selected region without explicit customer configuration.

21 CFR Part 11

Start with FDA electronic records requirements. Read the guide

EU GMP Annex 11

Start with European computerized systems requirements. Read the guide