Pharmaceutical and Life Sciences

QA and security need the same record.

Schedule a meeting

Drug makers and labs under 21 CFR Part 11, EU GMP Annex 11 and GDPR

Security built for regulated labs and plants

Keep an independent, signed copy of lab and plant audit trails without changing a validated system.

Rules

RuleWhat the inspector testsARRTECH recordsStays with you
21 CFR 11.10(e)An independent, time-stamped audit trail.A signed copy from databases and files. →The system’s own audit trail.
Annex 11 §9Audit trails regularly reviewed.Scheduled reports and a silent-source alert. →QA’s review.
FDA data integrity Q&AOne account, one person.Sign-in classification and correlation rules. →Unique accounts in the GxP system.
21 CFR 11.50, 11.70Electronic signatures.None. →Signatures.
21 CFR 211.68(b)Controls on computerized systems.Role-based rights and a console audit log. →Validating your use.

21 CFR Part 11

Keep an independent copy of audit trails

21 CFR 11.10(e) requires secure, time-stamped audit trails that do not hide earlier entries. ARRTECH keeps a signed, independent copy of lab and plant audit trails without changing the validated system.

FDA warning letters

Catch a lab instrument that stops logging

FDA warning letters often cite audit trails that were turned off or never reviewed. ARRTECH SIEM alerts when an instrument or system stops sending logs.

Data integrity

Spot shared logins on lab systems

Shared logins break ALCOA+, because an action cannot be traced to one person. ARRTECH classifies sign-ins, so one account used on many hosts stands out.

Trade secrets

Stop research data leaving

Research data and formulas are trade secrets. ARRTECH DLP checks uploads, USB drives and prompts to AI tools, and recognizes excerpts of protected files.

By rule

Annex 11 §9

Audit trails regularly reviewed. ARRTECH: Scheduled reports and a silent-source alert.

Questions

Can research data leave by cloud upload or USB?

ARRTECH DLP inspects uploads from any application, controls USB drives by device, person or time, and recognizes excerpts of protected files and database records. A file can be encrypted so it opens only on company computers.

What about AI tools?

ARRTECH DLP checks prompts and uploads to AI tools and records who sent what, from which device, where, and which rule applied.

Does it change a validated system?

No. Cyberdroid AI Detection reads a copy of your logs from a read-only location and never changes anything.

What stays with you?

Each system’s own audit trail, electronic signatures and QA review. ARRTECH is not sold as a validated system.

Sources

Guide

What does 21 CFR 11.10(e) require?

Secure, computer-generated, time-stamped audit trails that record changes without obscuring earlier entries.

What is ALCOA+ data integrity?

Data that is attributable, legible, contemporaneous, original and accurate, plus complete, consistent, enduring and available.

What does EU GMP Annex 11 say about audit trails?

Audit trails should be available, readable and regularly reviewed.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.