SOPManagerPRO
Security & Trust

Controls that support governed quality work.

SOPManagerPRO combines organisation-scoped access, controlled workflows, auditability and security-focused account controls with quality-system governance. These controls support customer security and compliance programmes; they do not replace supplier qualification, intended-use validation or organisation-specific risk assessment.

Control who can enter, approve and administer.

Authentication and role governance are designed around individual accountability rather than shared access.

Individual user accounts

Users sign in with named accounts associated with their organisation and assigned role. Shared credentials should not be used for controlled approvals.

Two-factor authentication

TOTP authenticator-based 2FA is supported, and organisations can require users to enable it according to their security policy.

Failed-login protection

Repeated failed sign-in attempts trigger temporary account lockout. Successful authentication regenerates the session identifier.

Security controls are connected to the quality system.

The platform keeps governance evidence close to the records, approvals and users it relates to.

Audit trail

Significant document, user, approval and administrative activity is recorded for traceability and can be subjected to formal audit-trail review.

User access review

Periodic access-review workflows help organisations review whether user roles and permissions remain appropriate under least-privilege principles.

Controlled e-signature workflows

Approval actions can require re-authentication and capture signer identity and signature meaning such as Reviewed, Approved or Authorized.

Organisation-scoped records with governed operations.

SOPManagerPRO is a multi-company platform. Customer records and user access are scoped to the relevant organisation workspace, while privileged platform administration remains separately controlled.

Organisation-specific workspacesDocuments, training, quality records and users are associated with an organisation context.
CSRF-protected state changesApplication forms use server-generated anti-CSRF protection for authenticated and public account workflows.
Server-side password hashingPasswords are stored as cryptographic hashes rather than recoverable plaintext credentials.
Secrets kept server-sideAI/API credentials are intended to remain outside public browser code and outside normal source-control commits.

Security is more than login controls.

The platform includes governance areas for computerised systems, suppliers, backup verification, restore tests and business-continuity evidence so customers can connect technical operation to their quality system.

Computerised-system governance

Maintain system ownership, validation status, supplier/service-provider information and review evidence in an Annex 11-oriented governance workflow.

Backup & restore evidence

Record backup-verification and restore-test evidence according to the organisation's approved continuity and recovery procedures.

AI governance

Optional AI-assisted features are subject to intended-use governance and human review. AI output is not an approval, certification or regulatory decision.

Validation responsibility remains with the customer.

Regulated organisations should define intended use, perform supplier qualification, configure roles and workflows, test critical functions, document deviations and approve the configured system under their own validation procedure. Contact SOPManagerPRO to discuss the validation-support evidence currently available for your implementation.

Clear boundaries matter.

Privacy baselineRead the public Privacy Policy for controller/processor roles, data categories, rights and AI-service considerations.
Terms for regulated useThe Terms of Service state that software functionality alone does not make a customer GMP, ISO or Part 11 compliant.

Need a security or validation discussion?

Talk to us about intended use, onboarding, access governance or available implementation evidence.

hello@sopmanagerpro.com