Back to Clinical & Regulated

Technical readiness document

21 CFR Part 11 Technical Readiness

A point-by-point mapping of 21 CFR Part 11 record-keeping principles to the technical controls RedInkAI currently ships — and what remains the sponsor’s or CRO’s validation responsibility.

This document is intended for internal validation teams, quality assurance, and regulatory affairs personnel who need to enter RedInkAI into their document library. It is not a compliance certificate.

Version: 1.0
Date: Feb 20, 2026
Owner: RedInkAI Founding Team
Status: Aware · not “compliant”

Part 11 → RedInkAI control mapping

Each row cites a Part 11 subpart, restates the principle in plain language, describes the control RedInkAI ships against it, and explicitly names what the sponsor’s validation work still owns.

§ 11.10(a)

Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.

RedInkAI controls

Every InkTrail event is hash-chained to the previous event using SHA-256. Any modification, insertion, or deletion of a prior event breaks the chain, and the break is visible at the public /verify endpoint without RedInkAI involvement.

Sponsor / CRO owns

Formal system validation (IQ/OQ/PQ) inside the sponsor’s validated environment.

§ 11.10(b)

The ability to generate accurate and complete copies of records in both human-readable and electronic form for inspection.

RedInkAI controls

The Authorship Packet exports as both a signed PDF (human-readable) and a signed JSON (electronic). Both formats contain the same underlying chain and are independently verifiable.

Sponsor / CRO owns

Record retention policy alignment with the sponsor’s document control SOP.

§ 11.10(c)

Protection of records to enable their accurate and ready retrieval throughout the records retention period.

RedInkAI controls

Records stored on RedInkAI infrastructure with encryption at rest and in transit. Enterprise tier supports single-tenant deployment and configurable retention windows.

Sponsor / CRO owns

Retention-period determination based on applicable regulation (21 CFR 312.62, 21 CFR 812.140, ICH E6, etc.).

§ 11.10(d)

Limiting system access to authorized individuals.

RedInkAI controls

Role-based access controls at the project level. Enterprise tier includes SSO via SAML/OIDC. Admin actions are separately logged.

Sponsor / CRO owns

User-provisioning SOPs and periodic access review.

§ 11.10(e)

Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions.

RedInkAI controls

Every event is timestamped by the RedInkAI server (not the client machine). Timestamps are part of the hashed record and cannot be edited retroactively without breaking the chain.

Sponsor / CRO owns

Time-source qualification (NTP source, drift monitoring) at the sponsor’s infrastructure boundary.

§ 11.10(f)

Use of operational system checks to enforce permitted sequencing of steps and events.

RedInkAI controls

Chain-of-custody enforced at the storage layer: events are append-only. Any attempt to reorder, delete, or modify a prior event is detected at verification time.

Sponsor / CRO owns

Sequence-of-steps definition in the sponsor’s process (e.g., "reviewed before signed off").

§ 11.10(g)

Use of authority checks to ensure that only authorized individuals can use the system, sign a record, access the operation or computer system, or alter a record.

RedInkAI controls

Authenticated user identity is bound to every event in the chain. Draft-level modifications carry both the acting user’s ID and a server-side timestamp.

Sponsor / CRO owns

Segregation-of-duties policy for reviewer / approver roles.

§ 11.10(h)

Use of device (e.g., terminal) checks to determine, as appropriate, the validity of the source of data input or operational instruction.

RedInkAI controls

Session tokens are bound to authenticated users; API calls originate from known frontend surfaces. Not currently claiming device-level attestation (TPM / hardware-bound identity).

Sponsor / CRO owns

Device-management policy (MDM, endpoint controls) at the sponsor’s IT boundary.

§ 11.10(k)

Use of appropriate controls over systems documentation.

RedInkAI controls

This document plus the technical architecture summary available on request. Change logs to controls are versioned and dated.

Sponsor / CRO owns

Internal documentation of the sponsor’s validated configuration.

§ 11.30

Controls for open systems (encryption / digital signature standards).

RedInkAI controls

TLS for transit; AES-256 at rest. Chain integrity uses SHA-256. Public verification is asymmetric (public/private key pair; only RedInkAI holds the private key). Standards are documented.

Sponsor / CRO owns

Sponsor-side key-management policy if leveraging additional signature layers on top of RedInkAI’s.

§ 11.50

Signature manifestations must contain information associated with the signing (printed name, date/time, and meaning of the signature).

RedInkAI controls

The Authorship Packet’s signature block includes: full printed name, ISO-8601 UTC timestamp, packet ID, and a "meaning of signature" line (e.g., "I attest that this work was produced as documented in the InkTrail").

Sponsor / CRO owns

The specific "meaning of signature" language required by the sponsor’s SOP.

§ 11.70

Electronic signatures and handwritten signatures executed to electronic records shall be linked to their respective electronic records to ensure they cannot be excised, copied, or otherwise transferred.

RedInkAI controls

The signature block is part of the hashed chain. Removing or transferring the signature to a different record breaks the chain and is detected at /verify.

Sponsor / CRO owns

None specific — this is fully controlled by the RedInkAI record model.

What we deliberately do not claim

Overclaimed regulatory language is legal exposure. We’d rather be under-claimed and defensible than over-claimed and questioned by a reviewer who does this for a living.

  • "21 CFR Part 11 compliant." Formal compliance is a system-in-context determination that includes the sponsor’s validation work; not something a vendor can grant unilaterally.
  • "GxP validated." A validation pack (IQ/OQ/PQ, User Requirements, Traceability Matrix) is not currently shipped. Available as a paid engagement in the Enterprise tier.
  • "Certified by FDA." Software of this kind is not certified by FDA; that is not how the framework works, and we would not represent otherwise.
  • "Replaces sponsor validation obligations." RedInkAI is an input to your validation activities, not a substitute for them.
  • "Legal privilege" or "attorney-client protection" for any records produced. Those are determinations for the sponsor’s counsel, not RedInkAI.

Ready to bring your sponsor’s validation team into a conversation?

Schedule a 30-minute Part 11 walkthrough

Version 1.0 · Feb 20, 2026 · Prepared by RedInkAI · This document is provided as a technical reference; it is not a compliance opinion, warranty, or representation of validated system status.