From Your Documents to Audit-Ready Answers

Generic RAG retrieves text. ComplianceGxP understands compliance.

01

Ingest Your Documents

Upload SOPs, validation protocols, regulatory guidelines, deviations, and CAPAs. Each document is parsed (PDF/DOCX/XLSX/TXT), chunked along pharma-aware section boundaries, and embedded into a private FAISS index isolated per namespace.

SOP · Validation Plan · Deviation · CAPA · Regulatory · Audit

Architecture at a Glance

FastAPI service. FAISS vector store. Claude Sonnet for generation. SHA-256-hashed keys. JSONL audit. Docker + Caddy for deploy.

🔗

RAG Pipeline

Documents → pharma-aware chunker → local embeddings (all-MiniLM-L6-v2, 384-dim) or OpenAI embeddings → FAISS IndexFlatIP (cosine, threshold 0.3) → Claude Sonnet generation with mode-specific system prompts.

🛡

Multi-Tenant Isolation

Each client gets a separate FAISS index, metadata file, and JSONL audit log under data/clients/<namespace>/. Per-key tier flags (can_ingest, can_read_logs) enforce least-privilege access.

📋

Validation Package

IQ-CGXP-001 (16 test cases — env, deps, file I/O), OQ-CGXP-001 (33 test cases — auth, ingestion, all 4 modes, audit log), PQ-CGXP-001 template per client. Run via python tests/validation/run_oq.py.

🤖

Agent-Ready Surfaces

HTTP API with auto-generated Swagger UI at /docs. MCP server endpoint at /mcp/ for direct connection from Claude AI & Claude Code. SHARP headers for healthcare agent interop.

Try It in One Minute

The hosted Community Edition is open to everyone: sign up with your email, get 50 free credits every month, upload your own documents, and pay only the actual cost of what you run — transparent, tamper-evident, no subscription.

Sign Up Free

Need data segregation on your own infrastructure? On-premise & white-label →

What ships in the box:

QA Mode
Sourced Q&A · citations
Deviation Mode
5M RCA · classification
CAPA Mode
Corrective action drafts
CSV Mode
IQ / OQ / PQ outlines
GAMP5 Validation
IQ/OQ/PQ test suite
Audit Trail
JSONL · per query
MCP Server
Claude AI & Code interop
SHARP
Healthcare agent protocol

Need a managed instance, validation evidence, or your own SOP library ingested?
See the Private Pilot Programme →

📝

Interactive API Docs

The full API surface is auto-documented via Swagger UI at /docs and ReDoc at /redoc. Raw OpenAPI 3.1 spec at /openapi.json.

Who’s Behind ComplianceGxP

Mauro Moro

Mauro Moro — Founder & Builder

I spent 25+ years in pharma automation, MES/SCADA, and GxP computer system validation — on real plant floors, through real FDA and EMA inspections. The modes and prompts above are not generic AI — they encode how I learned to think through a deviation, a CAPA, a CSV protocol over a 25-year career. That is what you cannot prompt-engineer in an afternoon.

Connect with me on LinkedIn ↗ — I’m building this in the open.

Ready to try this with your own documents?

We’re accepting a limited number of qualifying pharma, biotech, and CDMO teams for a free 90-day pilot — ComplianceGxP trained on your actual SOPs, validation protocols, and regulatory guidelines.

Apply for Free Pilot