Compliance
Compliance and quality
An honest boundary: what the product does, what we show on request, and what stays with the customer.
The product provides
- An immutable audit trail: a per-tenant cryptographic chain, append-only at the database level, before/after, actor and reason for change.
- Electronic signatures: re-authentication, meaning and scope, a hash of the data snapshot; editing covered data invalidates the signature — cannot be switched off.
- The moment of entry is stored separately from the event time — this is what proves a record is contemporaneous.
- Hierarchical locks by scope, soft and hard; unlocking requires both a permission and a reason.
- Policy-based access: deny by default, explainable denial, segregation of duties.
- Blinding: the server masks in every channel; unblinding happens only through an explicit gesture, and that gesture itself is audited.
- Clinical data is never physically deleted.
- Time is stored in UTC only, ISO 8601; the time zone is a property of presentation.
- Versioned public API; an unsanctioned contract change fails the build.
- A traceability matrix “platform invariant → test”, generated from the code.
- An architecture decision log — decision governance is documented.
- Release change control: the server authorizes publication after quality gates; a failed gate means the release did not happen. Process details — in the “on request” column.
- Backups and liveness/readiness probes; notification when services go down.
- Production environment hosted in the Russian Federation.
Available on request
- The invariant traceability matrix and the composition of the test suite.
- A description of the architecture and the boundaries of responsibility.
- A description of the change-management and release-publication process.
- Backup and restore procedures with target objectives.
- A list of open-source components in use, with licences.
- Delivery model: hosted in the vendor's environment (Russia) or installed in the customer's environment.
Customer's responsibility
- Validating the system for their own processes (URS, tests, report) and maintaining that validation.
- Standard operating procedures, user training, the delegation log.
- Access management: granting rights, periodic review, revocation.
- The personal-data controller role: legal grounds, notifications, consents.
- Retention and archiving according to their own schedules.
Roles under 152-FZ
The personal-data controller is the investigative site or the sponsor. X7 Insight acts as a processor on the controller's behalf; the scope of processing and the protection requirements are fixed by contract. Health data is a special category of personal data. The production environment is hosted in the Russian Federation.
We will walk you through the product on a demo study and answer your questions.
Request a demo