Validation & Trust Center
Vendor qualification pack for clinical QA teams
Everything your Quality, IT security and procurement reviewers need to assess ClinOpsWord: how data is handled, which Part 11 controls apply, and how to verify the tool in your own environment.
1. Data architecture
Local-only processing, by design
Zero document upload
Word (.docx) files and datasets are opened with the browser File API and parsed in memory. File bytes are never sent to ClinOpsWord servers.
No third-party AI processing
Audit rules run as deterministic JavaScript on your device. Document content is not sent to any external language model or cloud parser.
Minimal account data
The backend stores only account, plan and billing status. Payments are handled by our payment provider; we never see full card numbers.
Session-scoped results
Findings live in browser memory for the session and are cleared on reload. Exports (CSV / report) are saved only where your user chooses.
2. 21 CFR Part 11
Technical controls matrix
ClinOpsWord is a review aid, not a system of record. The matrix shows which controls the product supports and which remain the customer's responsibility.
| Requirement | How ClinOpsWord addresses it | Responsibility |
|---|---|---|
| §11.10(a) Validation | Deterministic rule engine; identical input yields identical findings and Health Index. OQ scripts below support customer validation. | Shared |
| §11.10(b) Accurate copies | Findings export to human-readable report and CSV with source location for each finding. | Supported |
| §11.10(c) Record protection | Source documents are never modified or stored by ClinOpsWord; originals remain in your controlled repository. | Supported |
| §11.10(d) Limited access | Workspace requires authenticated sign-in; plan entitlements enforced server-side with row-level security. | Supported |
| §11.10(e) Audit trail | Each audit run records file name, size, timestamp and rule results in the exported traceability log. Long-term retention is in the customer's eQMS. | Shared |
| §11.10(g) Authority checks | Role-based access (user / admin) stored in a separate roles table and checked server-side. | Supported |
| §11.10(i) Training | Customer responsibility; product guides and glossary available in-app. | Customer |
| §11.50 / §11.70 E-signatures | ClinOpsWord does not apply electronic signatures. Sign-off happens in your validated eDMS. | Not applicable |
3. IQ / OQ
Qualification summary
Installation Qualification (IQ)
- No local install required — runs in current Chrome, Edge, Firefox or Safari.
- Optional installable app (PWA) uses the same code served over HTTPS.
- Served from https://clinopsword.app with TLS; no plugins or macros.
- Record browser name/version and access date as IQ evidence.
Operational Qualification (OQ)
The scripts below describe expected behaviour so your team can execute and record results with your own test documents. A built-in demo protocol is available in the workspace for dry runs.
| ID | Test step | Expected result |
|---|---|---|
| OQ-01 | Load supported .docx file | File parsed locally; no network request carries file content (verify in browser DevTools Network tab). |
| OQ-02 | Load unsupported / irrelevant file | Relevance check flags document; no clinical findings are fabricated. |
| OQ-03 | Repeat audit on same file 3× | Identical findings list and Health Index each run. |
| OQ-04 | Subject count mismatch (N) between protocol and dataset | Critical finding raised with both values cited. |
| OQ-05 | Alpha level inconsistency (e.g. 0.05 vs 0.025) | Finding raised; equivalent notations (.05 / 0.05) treated as equal. |
| OQ-06 | Missing ICH E6 (R3) required section heading | Finding raised identifying the missing section. |
| OQ-07 | Export results | Report and CSV contain every on-screen finding with risk tier and location. |
| OQ-08 | Sign out, then open workspace URL | Access denied; redirected to sign-in. |
4. Governance
Company & support
Company
ClinOpsWord
Founder & CEO: Khurram Shahzad
Security & QA contact
khurram@clinopsword.com
Vendor questionnaires answered on request
Support
Email support for all paid plans
Response target: 1 business day
This pack describes current product behaviour and is provided for vendor assessment. It does not replace your organisation's computerised system validation.
Ready to run your own OQ?
Start 7-day free trial