Validation & Trust Center

Vendor qualification pack for clinical QA teams

Everything your Quality, IT security and procurement reviewers need to assess ClinOpsWord: how data is handled, which Part 11 controls apply, and how to verify the tool in your own environment.

Send us your questionnaire

1. Data architecture

Local-only processing, by design

Zero document upload

Word (.docx) files and datasets are opened with the browser File API and parsed in memory. File bytes are never sent to ClinOpsWord servers.

No third-party AI processing

Audit rules run as deterministic JavaScript on your device. Document content is not sent to any external language model or cloud parser.

Minimal account data

The backend stores only account, plan and billing status. Payments are handled by our payment provider; we never see full card numbers.

Session-scoped results

Findings live in browser memory for the session and are cleared on reload. Exports (CSV / report) are saved only where your user chooses.

2. 21 CFR Part 11

Technical controls matrix

ClinOpsWord is a review aid, not a system of record. The matrix shows which controls the product supports and which remain the customer's responsibility.

RequirementHow ClinOpsWord addresses itResponsibility
§11.10(a) ValidationDeterministic rule engine; identical input yields identical findings and Health Index. OQ scripts below support customer validation.Shared
§11.10(b) Accurate copiesFindings export to human-readable report and CSV with source location for each finding.Supported
§11.10(c) Record protectionSource documents are never modified or stored by ClinOpsWord; originals remain in your controlled repository.Supported
§11.10(d) Limited accessWorkspace requires authenticated sign-in; plan entitlements enforced server-side with row-level security.Supported
§11.10(e) Audit trailEach audit run records file name, size, timestamp and rule results in the exported traceability log. Long-term retention is in the customer's eQMS.Shared
§11.10(g) Authority checksRole-based access (user / admin) stored in a separate roles table and checked server-side.Supported
§11.10(i) TrainingCustomer responsibility; product guides and glossary available in-app.Customer
§11.50 / §11.70 E-signaturesClinOpsWord does not apply electronic signatures. Sign-off happens in your validated eDMS.Not applicable

3. IQ / OQ

Qualification summary

Installation Qualification (IQ)

  • No local install required — runs in current Chrome, Edge, Firefox or Safari.
  • Optional installable app (PWA) uses the same code served over HTTPS.
  • Served from https://clinopsword.app with TLS; no plugins or macros.
  • Record browser name/version and access date as IQ evidence.

Operational Qualification (OQ)

The scripts below describe expected behaviour so your team can execute and record results with your own test documents. A built-in demo protocol is available in the workspace for dry runs.

IDTest stepExpected result
OQ-01Load supported .docx fileFile parsed locally; no network request carries file content (verify in browser DevTools Network tab).
OQ-02Load unsupported / irrelevant fileRelevance check flags document; no clinical findings are fabricated.
OQ-03Repeat audit on same file 3×Identical findings list and Health Index each run.
OQ-04Subject count mismatch (N) between protocol and datasetCritical finding raised with both values cited.
OQ-05Alpha level inconsistency (e.g. 0.05 vs 0.025)Finding raised; equivalent notations (.05 / 0.05) treated as equal.
OQ-06Missing ICH E6 (R3) required section headingFinding raised identifying the missing section.
OQ-07Export resultsReport and CSV contain every on-screen finding with risk tier and location.
OQ-08Sign out, then open workspace URLAccess denied; redirected to sign-in.

4. Governance

Company & support

Company

ClinOpsWord

Founder & CEO: Khurram Shahzad

Security & QA contact

khurram@clinopsword.com

Vendor questionnaires answered on request

Support

Email support for all paid plans

Response target: 1 business day

This pack describes current product behaviour and is provided for vendor assessment. It does not replace your organisation's computerised system validation.

Ready to run your own OQ?

Start 7-day free trial