GxP-Desk turns the Word-and-Excel grind of CSV into a guided, AI-assisted workflow — drafting URS, risk assessments, and test scripts grounded in your tenant's data, routing them through Part 11 e-signatures, and exporting audit-ready deliverables on demand.
Most CSV programs run on Word templates, SharePoint folders, and email approvals — a fragile chain that breaks the moment FDA asks who signed what, when.
A single LIMS configuration change cycles through impact assessment, test script authoring, execution, and review — most of it copy-pasted between Word and Excel.
Validation engineers spend more time formatting headers and chasing approvals than thinking about risk. ALCOA+ falls apart under that workload.
A broken audit trail or missing e-signature is enough to delay a launch. Annex 11 grew from 5 pages to 17 sections — most teams haven't caught up.
The rest of your inventory sits in a 'we'll get to it' backlog. Inspectors notice. Periodic review cycles are the first thing to slip when the team is underwater.
Retrieval-augmented generation reads your SOPs, prior validation packages, and system inventory before drafting a starting point — your team reviews, edits, and finalizes every deliverable before it's used.
▎
A guided path that mirrors the GAMP 5 V-model — without the templates.
Open a change request, scope the impacted systems from your inventory, and record a risk classification per ICH Q9 through a guided assessment.
AI Composer drafts URS, risk assessments, and IQ/OQ/PQ scripts grounded in your prior packages and SOPs — your team reviews and edits every draft before it's used.
Run scripted tests, attach evidence, route for review with two-component e-signatures and Separation of Duties enforced.
One-click DOCX/PDF deliverables — formatted and paginated. Audit trail bundle attached on request for the inspector.
Built on validated e-records, enforced Separation of Duties, and a tamper-evident audit trail — so your inspection package is half-written before it begins.
Validated e-records, two-component e-signatures, signed reason codes, computer-generated timestamps.
Part 11 control matrix ↓Risk-based validation, signature linking, periodic review. Inspection-ready in EMA jurisdictions.
Annex 11 control matrix ↓We operate against SOC 2 Type II control objectives — security, availability, and confidentiality. We have not yet engaged an auditor; formal certification is on our roadmap.
We align to ISO 27001:2022 control objectives, with documented controls and a risk register. Formal certification is planned; we are not yet certified.
GAMP 5 (2nd ed.) categorisation and lifecycle phases as modelled in the platform.
GAMP 5 lifecycle map ↓RAG-grounded generation with a human reviewer required before use. Model cards, data lineage documentation, and full EU AI Act conformity are on our roadmap.
Volume scales by managed systems, not seats. Single Account, multiple Tenants — always included.
Single tenant, up to 25 managed systems.
Multi-tenant, up to 250 managed systems.
Global programs, isolated deployment options, custom validation.
“I started GxP-Desk after watching brilliant validation engineers spend their best hours formatting headers in Word. The science of compliance is risk thinking — not paperwork. Every feature here exists to give that time back.”Christoph SeydelFounder · 16 years in leading roles on global validation projects
A working session with a validation engineer — not a sales pitch. You'll leave with a draft URS and risk assessment for one of your systems.