ISO 9001 · ISO 14001 · ISO 45001 · 21 CFR Part 11 · Factories Act

One system of record.
One audit trail.
Every standard you are held to.

CompliHub is a single platform that runs your quality, environmental and occupational health & safety management systems together — so evidence is a by-product of doing the work, not a separate project before every audit.

45
Workflow modules, independently licensable
17
Frameworks mapped clause by clause
10/14
OSHA PSM elements covered
1
Audit trail across every module
ISO 9001:2015 ISO 14001:2015 ISO 45001:2018 ISO/IEC 17025:2017 21 CFR Part 11 Factories Act 1948 OSH Code 2020 Water Act 1974 Air Act 1981 EP Act 1986 Hazardous Wastes Rules 2016 EIA Notification 2006 29 CFR 1910 PSM ICH Q7 Schedule M
The Problem

Manufacturers do not fail audits because they are careless.

They fail because the evidence that they were careful lives in eleven different places. The work was done. Proving it was done, in the order it was supposed to be done, by people authorised to do it, is a separate project — and it is the project that consumes the fortnight before every audit.

Parallel systems that must agree

A findings spreadsheet, a shared drive of signed PDFs, a training register in HR's system, a CAPA tracker owned by one person. Every one of them has to say the same thing on audit day. The reconciliation is manual, so for most of the year at least one is wrong.

Evidence reconstructed, not recorded

The permit was approved at 06:40 by phone. The signature was added later, in good faith. Every part of that sequence is normal, and none of it is defensible when an investigator asks how the authorisation is evidenced.

Authority assumed, not enforced

Who may close a major nonconformity? Who may release nonconforming product on concession? Where the system of record is a spreadsheet, there is nothing that could have refused.

Records without meaning

A row says approved_by: 4471. It does not say what user 4471 believed they were attesting to, whether they were reviewing content or accepting responsibility, or what the record said at that moment.

What these four failure modes cost, at every plant:

A fortnight of senior time before every certification and surveillance audit — six people, two weeks, reconstructing what was already done.

🔍

Findings that stay open because nobody owns the clock, and nobody can see the clock.

📊

A second plant that cannot be compared to the first, because neither counts the same things the same way.

The audit finding you did not need to take, because the evidence existed and could not be produced in the room.

The Idea

Make evidence a by-product of doing the work.

Not an activity that follows it. If the permit is issued in the system, the approval trail already exists. If the finding is raised from the checklist item, the link to its evidence already exists. Nothing has to be assembled later, because nothing was ever apart.

The Evidence Test

Five properties every auditable record must have

A certification auditor, a factory inspector and an FDA investigator are asking for the same five things in three vocabularies. A system that gets the architecture right satisfies all three audiences at once.

Attributable

Who did this, and were they entitled to?

Every record carries its actor. Approvals snapshot the signer's name and title at signing time. Authorisation is enforced, not merely recorded.

Sequenced

Did the steps happen in the right order?

State transitions are transactional services with explicit guards. A step that is not the current pending step cannot be actioned.

Meaningful

What did the signer attest to?

For regulated records, one of five declared meanings rendered into a declaration and frozen onto the signature at signing time.

Protected

Could this have been changed after the fact?

Approved revisions are immutable. A correction is a new revision, sequentially approved, with the whole history retained and readable.

Retrievable

Can you produce it now, completely, while I am here?

Every list is searchable, filterable, exportable to CSV. The revision effective on a date three years ago is still there, with its approval chain.

How It Works

Seven design decisions that make evidence hold up

These are not features on a comparison grid. They are the reason the evidence is trustworthy when someone finally reads it.

🔒

One authorisation model, enforced everywhere

The same rules apply in the screen, the query, the export and the admin console. There is no back door that a report can walk through. Hiding a button is not authorisation.

One approval engine, used by everything

Sequential approvals that refuse out-of-order decisions, refuse self-approval, and refuse to route when no approver is configured. It never auto-approves and never picks a default.

🛡

Approved records are immutable

Nothing submitted, approved or effective is quietly edited or deleted. A correction is a new revision, with the whole history retained. The revision that was effective on a date three years ago is still retrievable.

📝

One audit trail, written by the transaction

Not a log somebody remembered to write. The trail is produced by the same transaction that changed the record, with the acting user on it. Downloads of controlled copies are logged separately.

🏭

Multi-site boundary is structural

Every operational record is site-scoped, enforced by a registry. A regression test fails the build if a module is added without registering. Corporate sees all sites; a plant sees its own.

Configuration, not customisation

Permit forms, approval matrices, check sheets and email templates are edited by your administrators. Versioned — a permit already issued always shows the form it was issued against.

Transitions are services, not callbacks

Every state change is an explicit transactional service with guards. It either happens completely or not at all. No silent no-op, no bypassed guard from a new caller.

AI-Powered

ComplianceBuddy — your AI compliance assistant, built in

Ask questions about your compliance posture in plain language. Get answers grounded in your own live data — findings, documents, permits, audit results — scoped to what you are allowed to see.

💬

Plain-language questions

"Which ISO 45001 clauses apply to our permit process?" — ComplianceBuddy answers using context pulled from your live system, not a generic knowledge base.

🔒

Permission-aware & site-scoped

Every response is bounded by the user's access rights and the active site. It cannot reveal records or modules the user does not have permission to see.

Enterprise-grade AI

Powered by Azure OpenAI. Your data stays within your Azure tenant. No training on your data, no third-party model access. Configurable per deployment.

📋

Context from your live system

ComplianceBuddy pulls context from your actual findings, documents, permits, audit results, compliance evaluations and more — giving answers grounded in reality, not theory.

The Module Map

45 workflow modules, independently licensable

Every module shares the same authorisation, approval, notification and audit-trail infrastructure. A module that is off is hidden from the sidebar and blocked at the controller for every user.

Audit & Improvement

  • Audit Programme
  • Audits
  • Findings
  • CAPA Cases

Governance

  • Controlled Documents
  • Management Reviews
  • Quality Objectives
  • Context & Interested Parties

Risk & Compliance

  • Risks & Opportunities
  • Compliance Obligations
  • Environmental Aspects

Process Safety

  • Permit to Work
  • Management of Change
  • HAZOP
  • PSSR
  • Incidents

Occupational Health

  • Employee Health Records
  • Health Surveillance
  • First Aid & Pharmacy
  • Contractor Clearance
  • Exposure Monitoring
  • PPE & Respiratory Protection

Statutory Compliance

  • Statutory Registers & Formats
  • Workplace Inspections
  • Shift Roster
  • Chemical Register & SDS

Pollution Control Board

  • Consents, Clearances & the Board
  • Waste Management
  • Resource & Utility Consumption
  • Statutory Environmental Returns

Behaviour & Participation

  • Safety Observations & BBS
  • Worker Participation
  • Safety Meetings
  • Award & Reward

Quality Operations

  • Nonconforming Output
  • Design & Development
  • Suppliers
  • Customer Satisfaction

GMP Manufacturing

  • Materials & Lots
  • Batch Manufacturing Records
  • Deviations & Recall

Resources & Access

  • Competency & Training
  • Assets & Calibration
  • Visitor Management & Emergency

Two screens sit in the platform base: the compliance dashboard (a weighted score per site, ranked by what would move it) and audit readiness (the questions each inspector asks and the screen that answers each). Both read across modules and are worth more with each one added.

Coverage

What we map — and where we declare gaps

Coverage statements are traceable to the product's maintained clause-mapping documents. The gaps are stated in writing, not hidden until month four.

FrameworkPosition
ISO 9001 / 14001 / 45001Mapped clause by clause, with the gaps named in the mapping document
Factories Act 1948 · OSH Code 2020The statutory register layer a labour inspector opens first
Water Act · Air Act · EP Act · Waste RulesConsents and their conditions, the annual returns, environmental clearance — mapped duty by duty
29 CFR 1910.119 (PSM)10 of 14 elements. We say which four, in writing
21 CFR Part 11No product is compliant — half of Part 11 is procedural. We state what ships, what is yours, and what is being built
ISO/IEC 17025Covered in half — the predictable half. The laboratory verdict is not ours
ICH Q7 · Schedule MElectronic batch record, lot genealogy, recall — the manufacturing record, not the laboratory
Not in the productLIMS. Payroll, wages and attendance. Written lock-out/tag-out procedures per machine. Said before you find out yourself
Resources

Download our sales deck and white paper

Everything we claim is in writing. The white paper maps 17 frameworks clause by clause — including the rows where we fall short.

📊

Sales Deck

19 slides covering the problem, the architecture, the module map, implementation timeline and commercials. The same deck we present in every first meeting.

Download PDF
📖

Compliance White Paper

45 pages. Fourteen sections covering why compliance fails, the design decisions, all 45 modules, clause-by-clause coverage for ISO 9001/14001/45001, statutory safety, pollution control board returns, 21 CFR Part 11, and the twelve questions to ask any vendor.

Download PDF
Implementation

Evidence inside the first month, the spine inside ninety days

Each phase is a vertical slice that goes live rather than a layer that waits. Implementations fail when everything is configured before anything is used.

Weeks 1–2

Foundation

Sites, departments, users, roles, access matrix. The site boundary is real from day one, so a later plant is an addition, not a migration.

Weeks 3–5

First Live Module

The workflow with the sharpest daily pain — usually Permit to Work, Findings or Documents — genuinely in production with real users.

Weeks 5–8

The Improvement Loop

Findings, root cause, CAPA, effectiveness verification. Every other module now has somewhere to send a problem.

Weeks 7–10

Governance

Controlled documents, audit programme, objectives, management review — the certification-facing spine.

Weeks 9–12

Domain Modules

Incidents, MOC, HAZOP, PSSR, occupational health, BBS, emergency preparedness — as licensed.

What we need from you: A named process owner per module (not a committee), your existing forms as they actually are, a decision on historical data, and two hours per week of leadership attention for the first six weeks.
The Benefit Case

Built from your numbers, not our benchmarks

Activities modelled

Audit administration, certification prep, chasing open actions, compiling management reports, permit paperwork — as people × hours × occurrences, at your loaded cost per hour.

Only what you buy

Only activities from modules you are actually licensing can appear. A saving from a module you did not buy is how a deal dies at the second meeting.

Year one discounted

Year one benefit is discounted for realisation: nobody gets the full benefit while the old spreadsheet is still open "just in case".

Your model, your figures

You leave the meeting with the model populated with your numbers, and you are free to argue with every one of them.

Proof

Twelve questions to ask any vendor

Use these on us and on everyone else you are evaluating. Ask for the answers in writing. The last four are the ones most vendors will not put in writing at all.

1

Show me findings from three different sources in one aging report.

One register, one severity scale, one aging clock, one closure rule. Findings raise from every module through the same path.

2

Can one person raise, investigate and close the same major NC?

No. Self-approval is refused in the service layer, and a major NC requires an approved root cause and CAPA before closure.

3

Show me the SOP revision effective on the date of an incident three years ago.

Approved revisions are immutable. Every historical version stays retrievable, with its approval history.

4

What happens if no approver is configured for this permit type on night shift?

The system refuses to route and says so. It does not auto-approve and does not pick a default.

5

Can a plant see another plant's records?

No. Enforced in one place, across a registry of every operational model, with a regression test that fails the build.

6

Who configures a new permit form, and what does it cost?

Your administrators, from inside the application, at no cost. Configurations are versioned, so a permit already issued still shows the form it was issued against.

7

Can I export everything? What happens to my data if we part ways?

Standard PostgreSQL, documented schema, CSV export on every list within the user's own authorisation. No proprietary format and no exit toll.

8

Does approval record what the approver was attesting to?

For regulated records, one of five declared meanings, rendered into a declaration and frozen onto the signature at signing time.

9

Are you 21 CFR Part 11 compliant?

No — and neither is any product, because half of Part 11 is procedural. We state what ships, what is yours, and what is being built. We will hand your QA team the full internal gap analysis.

10

Show me your clause mapping including where you fall short.

17 frameworks, 9 mapping documents, gaps declared. Available to your evaluation team on request — including the sections where they say we fall short.

11

What does your product deliberately not do?

A complete list with what we recommend instead for each item. Published honestly, not hidden until month four of your implementation.

12

Who owns the validation package?

A joint deliverable with a named owner on each side. We supply requirements and design inputs, the automated test suite as OQ raw material. We do not claim to hand you a validated system.

We published questions 9 to 12 because they are the questions we are most confident answering — and because a vendor who answers "yes, we are Part 11 compliant" to question 9 has told you something important about every other answer they gave you.

Deployment

Your data, your infrastructure, your choice

Conventional, boring, well-understood technology. A deliberate choice for a system a plant will run for a decade.

Infrastructure

  • On-premise, private cloud or hosted
  • Single PostgreSQL database per org
  • No shared multi-tenant database
  • Containerised deployment
  • Ruby on Rails 8, server-rendered HTML
  • No exotic runtime or cloud vendor lock-in

Security

  • Authorisation enforced at the query layer
  • Site isolation with regression tests
  • 30-minute session timeout
  • 10-attempt lockout with auto-recovery
  • Static scanning and dependency auditing
  • File attachments through a policy layer

Data Ownership

  • Standard PostgreSQL, documented schema
  • CSV export on every list
  • No proprietary storage format
  • No exit toll — your data is yours
  • Perpetual licence option available
  • One org, one database, one upgrade cycle
For your IT function: Ruby on Rails 8, PostgreSQL, server-rendered HTML with progressive enhancement, background jobs in the same database, containerised deployment. No per-seat client, no dependency on a single cloud vendor's proprietary services.
About Us

Deepak Cybit — Empowering Businesses with Tailored Digital Solutions

We design and deliver intelligent, scalable, and user-focused software that simplifies complexity and accelerates growth.

Founded in 2016, Deepak Cybit is a software development and industry-specific applications provider based in Vadodara, Pune and Mumbai. Combining deep industry expertise with sharp design and engineering, our team builds tools that go beyond functionality — they empower organisations to operate smarter.

From automating legacy systems to enhancing safety and R&D processes, we help you lead in the age of digital transformation. Our technology is reliable, intuitive, and designed to evolve with your business.

Our Mission

We empower businesses through purpose-driven digital solutions — fusing intelligent design, seamless functionality, and deep domain expertise to create experiences that inspire, engage, and transform.

Our Vision

To become a trusted leader in digital transformation — empowering industries through innovative, impactful, and visually intelligent solutions that inspire confidence and deliver measurable value.

Our Goal

We aim to consistently exceed client expectations by delivering intelligent, user-first solutions — building long-term partnerships rooted in trust, innovation, and a shared drive for meaningful outcomes.

Next Step

Thirty minutes on your worst workflow

Not a slide deck. A working session against your own material. Bring one real permit, one real finding with its CAPA, and one real SOP revision — and we will run them end to end.

1

We show

One complete workflow end to end, on your terms — the one you named on the call, not our favourite screen.

2

You test

Ask the four questions. Try to break the authorisation. Ask for a record we have not prepared.

3

You decide

A scoped quotation and a benefit case built from your own numbers, inside a week.