Records, data and security
Written for a quality unit that has to defend this in an audit, and for an early-stage company that would rather say what is true today than what sounds good.
Records and audit trail
Every action is attributable to a user and a time. Nothing is overwritten: corrections are recorded as new entries with the prior value retained, so a reviewer can see what the agent read, what it mapped, and why it flagged a result.
We build with 21 CFR Part 11 expectations for electronic records and signatures in mind, and we can supply documentation to support your validation activities. That is what we build toward — it is not a certification we hold.
Your data
Customer documents sit in tenant-isolated storage in the region agreed with you. Access is scoped by role, and retention and deletion are configurable.
Your formulations, specifications and supplier documents are not used to train models sold to anyone else. Formulation secrecy is the currency of this industry, and a contract manufacturer cannot hand its brand owners' recipes to a shared model.
We support deployment options that keep sensitive formulation IP inside your own environment; ask us for the current cloud regions and private-deployment options.
Security posture
| Control | Status |
|---|---|
| Encryption in transit and at rest | Today |
| Role-based access control and tenant isolation | Today |
| Activity logging on every read, mapping and flag event | Today |
| Single sign-on with your identity provider | In progress |
| Independent penetration test | In progress |
| SOC 2 Type II | Roadmap |
How we measure quality
A missed out-of-specification result is the failure mode we optimise against. A false flag costs a reviewer a minute; a missed one puts product on a truck.
We evaluate every model and prompt change against a held-out set of real supplier documents before it reaches a customer environment. Current extraction accuracy and the false-negative rate on out-of-specification results are tracked per document type and reported as part of our pre-release model validation.
Results are reported per document type, because a clean digital CoA and a scanned fax do not behave the same way.
What we do not claim
Keeygre is software for reading documents and preparing review packets. It does not certify products, and it does not replace the quality unit.
Your company remains responsible for its specifications, its suppliers, its manufacturing records and every release decision.