MedTech · Validated Multi-Tenant SaaS

A Quality System That Ships With Its Own Validation Evidence

Medical-device companies cannot adopt a cloud QMS until it has been validated — months of unbillable work most vendors push onto the customer. We built one that validates itself, inside the product, and signs the PDF at the end.

Industry

MedTech / Regulatory

Solution

Validated eQMS

Engagement

~14 Months, Ongoing

Services

AI & Enterprise Development

Talk to Us
Validated eQMS for Medical Devices — OpenMalo case study
Client Context

The Software You Cannot Use Until You Prove It Works

A medical-device company's quality system is not paperwork — it is the evidence that its device is safe, and it is what a regulator asks for. Most of it lives in Word documents, spreadsheets and a wiki, with version drift between them and audit preparation that takes weeks of manual reconciliation.

Moving that to the cloud has a catch that outsiders never see: under 21 CFR Part 11, the customer must first validate the software itself — install, operational and performance qualification — before they are allowed to keep records in it. Most vendors hand that back to the customer. It is months of work that produces no product.

21 CFR Part 11ISO 13485 & 14971IQ/OQ/PQ Validation
The Challenge

The Problems We Set Out to Solve

The source is clear that these are drawn from the codebase, plan files and meeting notes rather than from a formal client brief — but they are the problems the architecture was built against, and they are specific.

Quality records scattered across documents, spreadsheets and a wiki, with version drift

Customers unable to adopt any cloud QMS without running IQ/OQ/PQ validation themselves

Regulatory data living outside the QMS — copy-pasted between portals, going stale

Design and risk artefacts authored by hand from blank templates, frequently incomplete

Investor material maintained separately, disconnected from the device data behind it

Our Solution

Validation as a Product Feature

The idea that shapes everything: if the customer must validate the software, then validating the software should be something the software does.

A Validation Sandbox Per Tenant

A cloned sandbox provisioned atomically, with the signer personas created automatically, so the customer executes install, operational and performance qualification inside the product — and gets a signed PDF pinned to a specific release at the end.

One Source of Truth for Quality

Document authoring with full versioning and templates, with every artefact carrying an audit trail — the version drift between the document, the spreadsheet and the wiki simply has nowhere to happen.

Regulatory Data Inside the Workflow

Device codes, European device nomenclature and notified-body data pulled in through purpose-built functions and surfaced directly inside device definition and gap analysis, instead of copy-pasted from a portal.

AI Where the Authoring Is Heaviest

Around seventy-five AI functions covering document generation, gap-step assessment, hazard generation, verification planning, predicate trails and vigilance forms — the parts previously typed from a blank page.

Key Features

What the Platform Does

Document Studio

Full document authoring with versioning, templates and validation — the single place quality records are written.

Validation Sandbox

A per-tenant cloned sandbox with auto-provisioned signer personas, in-app IQ/OQ/PQ execution, and one-click signed-PDF generation pinned to a release.

CAPA

Corrective and preventive action lifecycle with electronic-signature approvals.

Non-Conformity

Capture, investigation and closure of non-conformities against the product they concern.

Change Control

Change request through impact analysis to approval, with the trail intact.

Design Risk & Hazards

Risk management to ISO 14971, with AI-assisted hazard generation from the device definition.

Technical File

A technical-file builder structured to the European regulation's annexes, assembled from the same data as everything else.

Device & BOM

Unique device identification, device families, bill of materials and components.

Gap Analysis

Multi-standard gap checklists with AI-assisted assessment of each step.

Audits & PMS

Internal and supplier audits, plus post-market surveillance plans, escalations and vigilance reports.

Verification & Validation

Verification and validation plans with evidence synced to the artefacts they prove.

Design Review

Formal design-review meetings with attendees, verdict and electronic signature.

Training & Competency

Training plans, a competency matrix, and AI-generated training quizzes.

Suppliers

Supplier registry, audits and evaluation documents.

Budget & NPV

Company and phase budgets with risk-adjusted net present value and what-if analysis.

Investor Surface

Investor share links and marketplace previews, driven by the same product data rather than a separate deck.

Super-Admin Console

Around twenty pages covering tenants, billing, plans, releases, templates, API keys, AI usage and the audit log.

Technology Stack

Multi-Tenant, Audit-Grade, AI-Assisted

Frontend

ReactTypeScriptViteTailwind CSSRadix UI

Backend

168 Edge FunctionsSupabaseNode.js Services

Data & Access

PostgreSQL + RLS995 Migrations7+ Roles

AI & Compliance

~75 AI FunctionsRAG PipelineIQ/OQ/PQ Engine
How We Delivered

Fourteen Months, Five Phases

  1. 1

    Core QMS Modules

    The document model, the quality lifecycle, and the modules a device company cannot operate without.

  2. 2

    Multi-Tenancy & Super-Admin

    Strict tenant isolation with a privileged bypass held in one place, plus the console that runs the platform.

  3. 3

    AI-Assisted Authoring

    The AI functions across document generation, hazard analysis, gap assessment and verification planning, with tiered key resolution so customers can bring their own.

  4. 4

    Validation Framework

    The launch sprint that made IQ/OQ/PQ a feature: per-tenant sandbox, auto-provisioned signers, in-app execution, signed PDFs pinned to a release.

  5. 5

    Scale-Up

    Per-tenant database split and customer onboarding, planned against a concrete roadmap rather than hoped for.

  6. 6

    How We Worked

    Weekly launch-sprint meetings and five-minute micro-syncs during the sprint, working bug to fix to staging to next bug, with named per-client branches for customer-specific work.

The Result

What Was Delivered

5

Live Customer Tenants

10+

Tools Replaced

168

Edge Functions

995

DB Migrations

  • Validation — install, operational and performance qualification — is executed inside the product, and the signed evidence is generated there too.

  • Five customer tenants run live on the platform, each isolated from the others at the database level.

  • More than ten separate tools are replaced by one system, with a single audit trail across all of them.

  • Regulatory data is pulled into the workflow rather than copy-pasted from a portal, so device classifications do not quietly go stale.

FAQ

Frequently Asked Questions

Yes — that is the idea the whole system is built around. Instead of handing validation back to the customer, we made it a product feature: a cloned sandbox is provisioned per tenant with signer personas created automatically, the customer executes install, operational and performance qualification inside the product, and a signed PDF pinned to a specific release is generated at the end.

Building software that has to pass an audit?

We build systems where the access model, the audit trail and the validation evidence hold up under a regulator — not just under a demo.

Talk to a Delivery Expert