FDA eSTAR · IEC 62304 · 21 CFR Part 11

Automate 21 CFR Part 11 Compliance Without Slowing Down Engineering.

The first zero-touch QA pipeline for MedTech. Map FDA requirements directly in your code, let AI triage discrepancies, and generate audit-ready traceability matrices instantly.

IEC 62304 Compliant21 CFR Part 11HMAC-Signed EvidenceFDA eSTAR Ready

Core Platform

Three pillars. Zero compliance debt.

Every layer of the Qavro pipeline is purpose-built for FDA submission requirements — not retrofitted onto a generic CI tool.

Zero-Touch CLI

Automated Ingestion

Map FDA requirements directly in your code. The omnis-run CLI binds test execution to regulatory clauses in real-time.

test_dicom_parser.py

1 import pytest

2 from omnis_run import req

3

4 @pytest.mark.req("IEC-62304-5.1")

5 def test_dicom_parse():

6 assert parse_dicom(fixture)

$ omnis-run . ── SIGNED

AI Triage Inbox

AWS Bedrock Triage

Stop manually reviewing false positives. Our AI agent automatically categorises test failures against your risk management files.

AI Triage InboxBedrock Active

test_phi_anonymizer.py

IEC-62304-5.7

Pass

test_cgm_alerts.py

IEC-62304-5.5

Flagged

test_s3_ecg_pipeline.py

IEC-62304-5.3

Pass
Immutable Audit Trails

Append-Only Ledgers

Cryptographically-sealed evidence logs. Generate 21 CFR Part 11 compliant traceability matrices instantly.

LOG-0041Sealed

sha: a3f9c2d8…4e1b

prev: b7e10d22…f229
LOG-0042Sealed

sha: c2d84a91…9b03

prev: a3f9c2d8…4e1b
LOG-0043Pending

sha: d91f3e0c…c571

prev: c2d84a91…9b03

How It Works

From commit to compliance, automatically.

01

Push Code

Every commit to main triggers the omnis-run CI/CD wrapper, capturing test execution in real time.

02

Automated Traceability

Evidence logs are HMAC-signed and linked to IEC 62304 clauses — no manual mapping required.

03

eSTAR Generation

Export a submission-ready FDA eSTAR Software Documentation Attachment as a compiled PDF.

Platform Preview

The Single Source of Compliance Truth.

Every CI/CD run, every regulatory clause, every digital signature — unified in one cryptographically-sealed ledger.

app.qavro.io / dashboard / traceability
Qavro/IEC 62304 Traceability MatrixLive · 21 CFR Part 11

IEC 62304 · 21 CFR Part 11 — Evidence Log

5 clauses
ClauseRequirementMethodSigStatus
5.1.1

Software Development Planning

test_dev_plan_audit.py

Doc Reviewa3f9c2…d841Compliant
5.3.2

Software Architectural Design

test_arch_design.py

Static Analysisb7e10d…f229Compliant
5.5.1

Software Unit Implementation

test_dicom_parser.py

Unit Testc2d84a…9b03Compliant
5.7.4

Regression & Integration Testing

test_cgm_alerts.py

CI/CD Suited91f3e…c571Pending
11.10(e)

Audit Trail — Time-Stamped Records

test_audit_trail.py

Log Ingestione47a81…b362Compliant
Submission Readiness
4/5 clauses verified80.0%

CI/CD Activity

Live

test_dicom_parser.py

2026-06-09T04:12:08Z

Signed

test_phi_anonymizer.py

2026-06-09T03:47:33Z

Signed

test_cgm_alerts.py

2026-06-09T03:11:55Z

Review

test_soup_codecs.py

2026-06-09T02:58:17Z

Signed

test_s3_ecg_pipeline.py

2026-06-09T02:30:44Z

Signed
5 evidence logs · Last ingested 2 min ago · Chain: VERIFIEDOpen Full Matrix

Under the Hood

Enterprise-Grade Architecture

Supabase RLS

Absolute data isolation.

Strict Row-Level Security policies enforced at the Postgres level. Multi-tenant architecture guarantees that cross-contamination of regulatory evidence is cryptographically impossible.

AES-256 Encryption

Tamper-proof audit logs.

All Part 11 audit trails are hashed and encrypted at rest. Evidence ledgers are append-only, preventing post-execution mutation by any user or automated process.

Deterministic CLI

Zero silent failures.

The omnis-run binary is compiled under strict IEC 62304 bounds. Network drops or parsing errors trigger explicit aborts to guarantee pipeline integrity.

Get Started Today

Ready to automate your
regulatory pipeline?

Get your workspace eSTAR-ready in less than five minutes.

No credit card required · IEC 62304 compliant from day one