Enterprise-grade security for pharmaceutical compliance.
CompliRx protects your data with encryption, strict tenant isolation, role-based access control, and tamper-evident audit trails that satisfy 21 CFR Part 11 and FDA inspection requirements.
Defense in depth, across every layer.
Security controls that pharmaceutical facilities can rely on, from database isolation to application hardening to infrastructure.
Encryption
All data is encrypted both in transit and at rest using industry-standard algorithms.
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Encrypted credential storage for sensor integration API keys
- Secure session management with automatic expiration
Tenant isolation
Every facility's data is strictly isolated at the database level, no shared queries, no cross-tenant leakage.
- Row-Level Security (RLS) policies enforced on every table
- Facility-scoped data isolation with mandatory facility_id filtering
- Organization-scoped access control for multi-facility operators
- Security-definer functions prevent RLS policy recursion
Access control
Granular role-based access control ensures the right people have the right permissions.
- 4-tier RBAC model: admin, manager, operator, viewer
- Resource:action permission format for granular control
- Team-based access pools with qualification gating
- Invitation-based onboarding, no self-registration
- User-to-facility access matrix for multi-site operators
Audit trail (21 CFR Part 11)
Every action is logged with full context. Tamper-evident electronic signatures ensure data integrity for FDA compliance.
- Complete activity logging with 40+ tracked action types
- Compliance-relevant event flagging for inspection review
- Electronic signature hashing using SHA-256 with deterministic key sorting
- IP address and user agent captured on every signed action
- ALCOA+ principles: Attributable, Legible, Contemporaneous, Original, Accurate
- Password re-authentication required at time of signing
Application security
Defense-in-depth protections are built into every layer of the application.
- Content Security Policy (CSP) headers on all responses
- XSS protection via DOMPurify sanitization on user-generated content
- File upload validation: type whitelist, size limits, magic byte verification
- Rate limiting on authentication endpoints
- Input validation with Zod schemas on all API boundaries
- Retry logic with exponential backoff (skips 4xx, retries 5xx and network errors)
Infrastructure
Managed infrastructure with automated operations, edge-distributed compute, and built-in redundancy.
- Supabase (PostgreSQL) managed database with automated backups
- Vercel deployment with global edge network and DDoS protection
- Deno edge functions with isolated execution sandboxes
- Environment-based secret management, no secrets in code
- Automated daily database backups with point-in-time recovery
Compliance readiness
CompliRx is built to meet the regulatory requirements pharmaceutical facilities face every day.
- SOC 2 Type II readiness (planned)
- HIPAA Business Associate Agreement (BAA) available
- 21 CFR Part 11 compliant electronic records and signatures
- FDA inspection-ready audit trail with exportable reports
- USP <797> and <800> operational compliance built in
Ready to secure your compliance workflow?
Book a demo to see how CompliRx protects your facility's data while keeping you inspection-ready.