Pharma validation software

Validation software that keeps every requirement traced to the test that proves it

MGTrace is validation software for pharmaceutical and GMP facilities. You write the user requirements, the functional and design specifications, the protocols that verify them — and the traceability matrix writes itself, level by level, from the first requirement to the last executed test. Electronic signatures and the audit trail are built in, not bolted on.

The first 5 users are free, with no time limit; every further user is €39 a month. Data hosted in the EU.

What validation software actually has to do

Computerised-system and equipment validation in pharma is a chain of documents that must agree with each other: a User Requirements Specification, the functional and design specifications that decompose it, and the IQ, OQ and PQ protocols that verify each level. An auditor does not read them one by one — they pick a requirement and follow it down to a test result, then pick a test and follow it back up. When the chain is kept in spreadsheets and Word files, that walk breaks at the first renumbered requirement.

Validation software exists to keep that chain unbreakable: every requirement, element and test is an identified object; every link between them is recorded, dated and attributable; every protocol is authored under version control, executed with results that cannot be edited after the fact, and signed by a person whose identity and intent are recorded. That is what EU GMP Annex 11, 21 CFR Part 11 and GAMP 5 describe — and what MGTrace does, from the V-model of a single system to the traceability matrix of a whole plant.

What MGTrace covers

Specifications with traceable elements

URS, FS, DS and your own document types, written in the editor. Each requirement or element carries a tag; a tag is traced to the level above with one click and coloured by whether it is traced.

IQ, OQ, PQ protocols

Test cases authored as cards — steps, expected results, acceptance criteria — reviewed and approved as a document, then released for execution with results, evidence and signatures in place.

Requirements traceability matrix

Read live for a project or across the plant: every requirement, the elements that decompose it, the I/O it reaches, the tests that verify it, gaps in amber. Exported to CSV with the application version and date stamped on it.

21 CFR Part 11 electronic signatures

A signature records who, when (UTC, from the database clock), the meaning and the reason, and is hashed into the audit trail. Two-factor authentication and a 15-minute inactivity log-off are part of the account.

GMP audit trail

Every controlled change carries its actor, time, old and new value and reason, and can be filtered, paged and exported. Records are soft-deleted only; nothing regulated is physically removed.

Discrepancies and change control

A failed test opens a discrepancy with its own lifecycle; an approved protocol changes through an amendment, never in place; requirements freeze when the document that holds them is approved.

The V-model per system

Each system shows its own V: specifications down the left leg, protocols up the right, the counts of traces between them, and any document or protocol movable to the rung you want it on.

Validation package included

A validation plan, risk assessment, summary report, supplier assessment and periodic review for MGTrace itself, kept current with each release and available for your own computerised-system validation.

Commissioning too

I/O lists, loop checks generated per signal into their protocol, pre-commissioning, FAT, SAT and functional testing — traced to the same specifications as the qualification protocols.

How it works

  1. 1

    Set up the plant

    A site, its areas and systems. Every document and protocol belongs to a system, so traceability stays within it.

  2. 2

    Write the specifications

    Start the URS from a template or from scratch, tag each requirement, send it for review and approval with electronic signatures. Decompose it into the FS and the DS, tracing each element to the one above.

  3. 3

    Author the protocols

    IQ against the DS, OQ against the FS, PQ against the URS — or wherever your V-model puts them. Each test names the element it verifies.

  4. 4

    Execute and sign

    Release a protocol for testing; record results and evidence on the released version; raise discrepancies where a test fails; sign each execution.

  5. 5

    Show the matrix

    Open the traceability matrix for the audit: every requirement covered or not, every test traced or not, with the chain behind each cell.

Compared with how the work is done today

No vendor names: what matters is the way of working. Spreadsheets and Word are what most validation departments actually use; a generic document or QMS suite is what they are usually offered instead.

Spreadsheets & WordGeneric document / QMS suiteMGTrace
Traceability between levelsA matrix maintained by hand; breaks when anything is renumbered.Document-level links, if any; element-level tracing is rare.Element-level, level by level, recomputed from the links — never maintained by hand.
Protocol executionPrinted, executed on paper, scanned; results typed back in.Forms attached to a document; execution often outside the tool.Executed on the released version, results and evidence in place, signed per execution.
Electronic signatures and audit trailWet signatures; no audit trail of the file.Present, configured per project; scope varies.Built in for every controlled record, with meaning, reason and hash chain.
Loop checks and I/OA separate spreadsheet per contractor.Not covered — commissioning lives elsewhere.I/O list as a controlled document; loop checks generated from templates into a protocol, executed and signed, traced to the signal.
Time to first protocolImmediate, and every project starts from zero again.Weeks to months of configuration and validation of the tool.The same afternoon: create the organization, load the worked example, start from a template.
CostFree, plus the hours.Enterprise licence, per site or per year, quoted.Free for the first 5 users; €39 per further user and month.

Built for Annex 11, Part 11 and GAMP 5

Electronic records

Controlled records are versioned, time-stamped by the database, soft-deleted only and reconstructable from the audit trail.

Electronic signatures

Identity, meaning, reason, UTC time and a hash of what was signed; a re-authentication at the moment of signing; two-factor authentication available for every account.

Access and sessions

Roles defined by your organization, a 15-minute inactivity log-off, lock-out after repeated failures, and every sign-in on record.

Data location and backup

Database and files in the EU (Ireland); daily backups with a rehearsed restore, kept in a register you can show.

Read before you buy anything

Questions people ask

Is MGTrace itself validated?
MGTrace is built and released under a documented lifecycle, with a validation plan, risk assessment, validation summary report, supplier assessment and periodic review that we keep current with each release. Under GAMP 5 the system remains yours to validate for its intended use; we give you the package to do it from, plus the self-tests the platform runs on itself.
Does it replace our QMS?
No. MGTrace covers commissioning, qualification and validation: specifications, protocols, execution, traceability, discrepancies and change to those records. CAPA, training, document control for SOPs and the rest of the quality system stay where they are; MGTrace exports what they need.
Where is our data hosted?
The database, authentication and files run in the European Union (Ireland) on Supabase; the application is served by Vercel. Both are named as processors in our Data Processing Agreement, with Standard Contractual Clauses where data leaves the EEA.
What does it cost?
The first 5 users of an organization are free with no time limit and no feature limit. Every further user is €39 a month, or ten months' price for a year.
Can we get our records out?
Yes. The traceability matrix exports to CSV, executed protocols export as execution records, the audit trail exports with filters, and controlled copies of documents carry their version and status. Nothing is locked in a proprietary format.
Do the electronic signatures meet 21 CFR Part 11?
Each signature records the signer's identity, the meaning of the signature, the reason where one is required, and the date and time from the database clock, and is hashed into the audit trail so it cannot be altered or moved to another record. Signing requires re-authentication; a second factor can be required for every account. Whether your use meets Part 11 also depends on your procedures — the package above is written to help you show it.