Written before the change
The audit record for a regulated change is committed before the change takes effect. A change cannot happen and then be described favourably afterwards.
Compliance
OpenAcura is the assured execution platform for regulated industries, built to support your 21 CFR Part 11 and EU Annex 11 obligations and aligned to ISO 27001. Every regulated action is electronically signed and recorded on a digitally secure audit trail — before the change it describes, not after.
Three things that matter
An approval is evidence when the record shows who gave it, when, and that it has not changed since.
The audit record for a regulated change is committed before the change takes effect. A change cannot happen and then be described favourably afterwards.
Dual-PIN signing, second-factor authority checks and mandatory intent statements are configurable per site, and an altered record is detectable whichever controls are on.
An electronic signature captures the signer, their stated intent, and the exact version of the record signed. A signature cannot be carried over to a later revision.
The audit trail
Every change is audited — who, what, when, and the values before and after. Records are added to, never edited, and an altered record is detectable.
The rigour is built in rather than bolted on, and how much of it you switch on is your decision. Dual-PIN signing, second-factor authority checks and mandatory intent statements are configurable per site — so a warehouse working to ISO 9001 is not pushed through controls written for a GMP cleanroom.
Electronic signatures
Under Part 11 a signature has to identify the signer, record what they meant by signing, and be bound to the specific record.
OpenAcura asks the signer to re-authenticate at the point of signing, records the intent as a named meaning — approved, rejected, verified effectiveness — and binds the signature to that version of the record. Change the record and the signature no longer applies; a new one is required.
ALCOA+ data integrity
ALCOA+ is often quoted and rarely broken down. Here is what each of the nine properties means in practice, and where the platform holds it.
Every entry carries who made it and when, taken from the authenticated session rather than a typed name.
Records are readable and permanent. Nothing is overwritten; superseded versions stay available.
The timestamp is the moment of the action, captured by the system, not entered afterwards.
The first capture is retained. Later edits are new versions with their own signatures.
Values are constrained at entry, and changes to a signed record require a reason.
Repeat work, failed attempts and voided entries stay in the record rather than disappearing.
One clock, one identity model, one audit format across every capability.
Retention is set per record type and enforced.
Any record can be produced on request, as an export, for the full retention period.
21 CFR Part 11
Part 11 governs electronic records and electronic signatures. The parts that fall to a software platform are access control, audit trails, record retention, operational checks on sequencing, and signature manifestation.
OpenAcura implements each of those, and the records it holds are exported as the evidence when an inspector asks.
ISO 27001
Access is role-based and least-privilege. Credentials for connected systems are held in an encrypted vault rather than in configuration. Data is encrypted in transit and at rest, and administrative actions are audited to the same standard as regulated ones.
Bring the question your last auditor asked. We will put it to the record and show you the export.
We use essential cookies to make this site work, and optional analytics cookies to understand which pages are useful. You can decline the optional ones and nothing breaks. See the privacy notice.