In a regulated lab, the pipeline isn't the deliverable.
The evidence that it was validated, and stayed validated, is. Most teams assemble that evidence by hand in Word and Excel after the fact — which is precisely the part that fails an inspection. This captures it as a byproduct of running the pipeline.
It sits alongside the Nextflow pipelines a lab already runs, ingests the provenance those runs already emit, and turns it into a traceable, electronically-signed validation package on top of a tamper-evident audit trail. Nothing about how or where pipelines run has to change.
Six questions, answered from data
A lab running a pipeline that supports a submission has to answer all of these for any result. Each is answered from the record, not from a binder.
- 01
Which version produced this, at which commit, in which containers?
Captured from the run's own telemetry as it executes. Container provenance is tracked per Nextflow process, not per workflow, because nf-core pipelines routinely use a different image per step.
- 02
Was that version validated, by whom, against which requirements?
Requirements, protocols and test cases live per version, and each test execution can point at the actual run that serves as its evidence — real telemetry, not a screenshot pasted into a document.
- 03
Did this run actually use the validated containers?
Every run is diffed against its version's frozen baseline. A mismatched image or commit raises a deviation automatically during ingestion, attributed to the system with a machine-written reason.
- 04
Who signed off, when, and what did the signature mean?
Signing re-verifies the password (plus TOTP where enrolled) at the moment of signature, never trusting the session alone. Printed name, timestamp and meaning are rendered together, on screen and in the PDF.
- 05
Can anyone prove the record wasn't edited afterwards?
Every mutation is hash-chained by a database trigger in the same transaction. The chain is verified on a schedule, and its tip is witnessed nightly to storage the database cannot reach — so even a rewritten history is detectable.
- 06
If we re-run it today, do we get the same outputs?
Reproducibility checks compare output checksums between an original run and a replay. Inputs are compared first: two runs given different inputs should differ, and reporting that as a failure would blame the pipeline for data that moved.
Invite only
There is no public signup, and that is not an omission. A signature is only worth what the identity behind it is worth, so accounts are issued by an organization administrator after the person is known — which is what 21 CFR 11.100(b) asks for. Every account carries one of four roles, and the boundaries between them are enforced by the database rather than by the interface.
- QA
- Approves packages and signs. The only role whose signature can move a package to approved.
- Scientist
- Authors requirements, protocols and test executions, and links them to real run evidence.
- Auditor
- Reads everything and verifies the chain. Writes nothing, by policy rather than by convention.
- Admin
- Manages members and rotates the ingest credential.
Without an account you will reach the login screen and stop there. Requests for records outside your own organization do not return an error either — the policy returns nothing, so another tenant's data is invisible rather than forbidden.
Join the waitlist
No spam. We’ll only email you about early access.