Skip to content

FAQ

The questions we get asked before a demo.

Including the ones where the answer is “no”. If yours isn’t here, ask us. We’d rather answer it now than have it come up halfway through an evaluation.

Compliance

Part 11 and the standards QAbility maps to.

What does QAbility do for 21 CFR Part 11?

QAbility supplies technical controls that support Part 11 — electronic signatures and an append-only audit trail. Compliance itself depends on your own procedures and validation, which no software can supply. Signing re-verifies who you are with a dedicated signature PIN, and the record captures what the signature meant, when, from which IP address and user agent, with a SHA-256 hash over those signing details. Each signature is bound to exactly one signed record by a database constraint, and the audit trail behind them is append-only.

See the signatures and audit trail

Which standards does QAbility map to?

ISO 9001, ISO 13485, 21 CFR Part 11 and the FDA Quality System Regulation (21 CFR 820), plus 21 CFR 211.170 and EU Annex 19 for reserve samples, and ANSI/ASQ Z1.4 and ISO 2859 for acceptance sampling. Complaint reportability covers FDA MDR, EU MDR and MoCRA. The document, training, CAPA and audit-trail primitives are framework-agnostic.

Product

How the work actually gets done in the system.

Does QAbility handle risk assessment and root-cause analysis?

Yes, and both sit inside the review step where the decision is actually made rather than in a separate tool. You design your own risk matrix — likelihood by severity, with an optional detectability axis — and root-cause analysis offers Fishbone, 5 Whys, Is/Is-Not and a why-tree. Both are captured on the CAPA, nonconformance or change request they belong to, and frozen at approval so later template edits cannot rewrite history.

See it on a CAPA

Can we run inspections and QC on the shop floor?

Yes. Log books, gemba walks, and shift handovers are captured as form-driven field records with configurable edit windows that lock them into immutable, signed evidence. QC acceptance inspection uses AQL sampling plans (ISO 2859-1 / ANSI Z1.4), with admin-defined custom plans where you need your own tables.

See logbooks

How does the supplier portal work?

Suppliers log in through a scoped portal with its own session and a reduced endpoint surface — they only ever see their own records, document requests, and assignments, never the main app. The supplier register, evaluations, and shared documents live inside your QMS, on the same audit trail and RBAC. Suppliers using the portal are not counted as billed users.

See the supplier portal

Security

Where data lives and how people sign in.

Where is my data stored?

Each customer's data is logically isolated, with PostgreSQL row-level security in the database. Access is granted by role, module and action, and on the core quality records it can be narrowed to a person's own records, their department or their site. Data is encrypted in transit. If you have a specific hosting or residency requirement, talk to us about it before you buy rather than after.

See the security controls

How do people sign in?

By password, or with Google or Microsoft. Multi-factor is by authenticator app, with recovery codes as the backup, and a tenant policy can compel it before a session is issued. The same verified identity is what backs a Part 11 electronic signature. Talk to us about enterprise SSO if it is a requirement for your deployment.

See the sign-in controls

Buying

Implementation, pricing and trying it first.

How long does implementation take?

It depends on your scope — the sites, record types and documents you are bringing across. We plan the rollout with you, and existing SOPs can be bulk-imported rather than re-keyed. Implementation is a defined one-time package — configuration, five hours of live training and the validation scripts — not an open-ended consulting engagement, and the knowledge base, tutorial videos and webinars stay open to your whole team afterwards. We would rather give you a timeline after we have seen your program than quote one before.

See what implementation includes

How does pricing work?

Three fixed annual plans — 5, 25 and 50 quality users — from $6,000, with the whole quality system in all of them. Sit between two plans and you take the lower one, adding users at its rate until the plan above is simply cheaper. Past fifty users we shape a plan around your program rather than publish one. What matters is who counts: people assigned in a core quality module are billable, while suppliers on the portal, shop-floor staff and everyone completing assigned training are free. Sites are not a billing axis. On top of the subscription there is a one-time implementation package from $5,000, optional paid support tiers, and storage buckets if a long-running system outgrows its allowance. Anything outside that is consulting at $150 per hour, estimated and approved before it starts. Multi-site programs are quoted as Enterprise.

See pricing

Can we try it before we buy?

Not through a self-serve trial — we scope the deployment with you first, because what a quality system needs depends on your sites, your people and the capabilities in scope. What we do instead is walk you through the product against your own processes, so you see it doing your work rather than a generic demo dataset.

Book a walkthrough

Ask us the one that isn’t on this page. Pricing has its own questions on the pricing page. Anything about how a record actually behaves is quickest to show on a call.