V5 Ultimate
Ultimate
PricingResourcesCompany
Talk to usStart free trial

Security & trust

How we protect the records auditors read.

V5 stores batch and device records, complaints, CAPAs and e-signatures. This page sets out the controls, where data is hosted and how to get the documents your review needs.

Laptop and tablet open on a desk for a security and procurement review
Procurement referenceBackup, recovery & resilienceHow V5 uses AI

On this page

  • Six pillars
  • Where it runs
  • Controls
  • Security assurance
  • Procurement Q&A
  • Security pack
  • Report a vulnerability
Two app locationsNetherlands + Oregon
One databaseOregon, United States
Independent backupsGoogle US multi-region
No AI trainingon Customer Data (EULA §5.1)

Independently assessed. The technical controls in V5 Ultimate 5.10 were assessed as compliant with 21 CFR Part 11 by Dr Bob McDowall (September 2026) — including access control, audit trail and no permanent delete. Scope: manufacturing execution; your own procedures still apply.

Read the assessment
Six pillars

What we protect, how we protect it

One line each. Open any card for the detail.

Encryption — in transit and at restTLS on every connection; encryption and encrypted backups committed in the Commercial Terms.

Encryption for hosted services and encrypted backups are commitments in the Commercial Terms, and user connections use TLS. Per-layer algorithm and scope confirmation is shared on request. On-Premises customers own their encryption keys via their KMS — we never see them.

Identity — SAML SSOSAML 2.0 single sign-on. SCIM provisioning is coming soon.

SAML 2.0 single sign-on with common identity providers such as Okta, Entra ID and Google Workspace; your specific provider is confirmed during scoping. SCIM automatic provisioning is coming soon and is not available yet.

Access control — RBAC + workspace isolationRole-based access, with every tenant query isolated by row-level security.

Roles are stored in a separate user_roles table (not on profiles) to prevent privilege escalation. Every query is RLS-scoped per tenant via security-definer SQL functions. Platform admin gated by hard-coded email allowlist.

Audit trail — queryable, Part 11 controlsWho, when, why and before/after — not editable or deletable in the app.

Signatures, overrides and changes to regulated records are written to an audit trail with user, time, reason and before/after values, and it cannot be edited or deleted through the application. Exact coverage per record type is shown in your demo.

Monitoring & incident responseProduction alerting and a documented incident-response runbook.

Production monitoring with alerts on failed sign-ins, unusual export volume. Documented incident-response runbook with customer notification on confirmed incidents per contract.

Deployment — Cloud or On-PremisesHosted in the Netherlands and Oregon, or On-Premises in your environment.

The hosted application runs in the Netherlands and Oregon (United States) with traffic shared between them; the database, sign-in and file storage remain in Oregon, United States. Hosted services include point-in-time recovery, daily independent copies and a separate backup location; the location of each layer is confirmed for your deployment. On-Premises ships as container images you run in your own environment, with customer-owned database and encryption keys; any outbound connections depend on the features you enable and are confirmed during scoping.

Where V5 Cloud runs

Two app locations. One database.

Traffic is shared between the Netherlands and Oregon. Your records live in one place, with independent backup copies kept separately.

Your team, anywhere

Application

The Netherlands

Google Cloud

Application

Oregon, United States

Google Cloud

Database, sign-in & files

Oregon, United States

Amazon Web Services, via Supabase. EU-only data storage is not offered.

Independent backup copies

Google US multi-region

Kept apart from the live database.

Locations for your deployment are confirmed in your Order. How backup and recovery work

Controls catalog

The checklist your security team will ask for

Three areas. Open one to see every control.

Application controls5 controls
  • Two e-signatures (preparer + independent reviewer) on formula and master document approval — same-person approvals rejected per 21 CFR 211.186 / 111.205.
  • Immutable approved formulas — edits create v+1 and the previous version stays read-only.
  • Operator-only users locked to /app/kiosk — no admin UI access.
  • Training status can be checked before operator tasks, where your workspace is configured to do so.
  • Device calibration status can be checked before use, where configured; the exact scope is shown in your demo.
Platform controls4 controls
  • Row-Level Security on every tenant-scoped table; security-definer functions for cross-tenant operations.
  • Service-role database key isolated to server-side admin operations; never bundled to client.
  • Secrets stored in encrypted secret manager; rotated on schedule.
  • S.G. Systems does not hold SOC 2 or ISO 27001. Hosting providers' own assurance reports describe those providers, not S.G. Systems, and are shared on request through the security review process.
Data residency & ownership4 controls
  • Hosted services: the V5 Cloud application runs in two locations, the Netherlands and Oregon (United States), and traffic is shared between them, so a visitor may be served from either. The database, sign-in and file storage remain in Oregon, United States, so EU-only data storage is not implied. The locations of your database, files and recovery copies are confirmed for your deployment.
  • On-Premises: data stays in your environment; outbound connections depend on the features you enable.
  • Customer-owned export: regulated records can be exported for your own retention; formats are confirmed per record type.
  • S.G. Systems does not use Customer Data to train AI models (EULA §5.1). When AI features are used, submitted content is processed by the AI providers on the sub-processors page; see How V5 uses AI.
Security assurance

Security assurance

S.G. Systems does not currently hold a security certification or attestation such as ISO 27001, SOC 2 or Cyber Essentials.

Published

Vulnerability disclosure policy

A security.txt file names our security contact and links to the reporting guidance on this page. It is a disclosure route, not a certification.

Regulatory assessment · completed

Independent 21 CFR Part 11 assessment

Dr R.D. McDowall (R D McDowall Ltd, UK) assessed the V5 Ultimate 5.10 manufacturing technical controls against 21 CFR Part 11 and 211; report approved 25 September 2026. QMS and QC areas were out of scope, and your own procedures are still required. This is a regulatory assessment, not a security certification.

Read the scope and report

Release management for regulated customers

Updates that respect your validated state.

Regulated customers receive advance notice of releases, access to a validation pack on request, and an opt-in upgrade window before changes are applied to their workspace. Full release-management terms — notification lead times, supported version windows, rollback provisions and validation artefacts — are agreed in the customer contract.

If you have specific GxP, Part 11 or Annex 11 requirements you need us to commit to in writing, raise them during procurement and we'll address them in the Commercial Terms or a regulatory addendum.

Procurement reference

Hosting, backup and recovery — straight answers

The questions supplier-assessment teams ask, answered in one place. Where a signed Order or customer-specific agreement exists, it governs. Otherwise the current S.G. Systems SLA and the applicable commercial terms set the commitments; Orders that accepted MSA V1.24 keep its terms. This page describes how the service currently operates; it does not change, add to or replace any contract term.

Version 1.3 · 6 October 2026 · V5 Ultimate hosted services (Cloud and Private Cloud). On-Premises and customer-managed cloud deployments are operated by the customer; see the On-Premises specification.

Download / print PDF
Service levels and support2Hosting and data location2Backup and recovery6Encryption and data protection3Insurance and commercial terms3

Service levels and support

Is there an uptime SLA, and how does it differ from a 2-hour response?

They are different measures. Uptime measures how much of the month a hosted service is available. A response target measures how quickly a person at S.G. Systems starts working on your issue. For critical (Severity 1) issues that is 2 hours, 24/7/365. It is not uptime, automated recovery or a guaranteed fix time.

  • Uptime, backups, RPO/RTO and service credits apply only to V5 Ultimate Cloud and Private Cloud, under the S.G. Systems SLA (§5 and §6).
  • Severity 1 (critical): a person from S.G. Systems responds within 2 hours, 24/7/365, for every supported deployment, including V5 Classic and on-premises. Hosted services also keep a 1 business hour target during business hours. Other severities run in business hours.
  • A response time is when a person starts working on the issue. It is not a fix time, an automated recovery, an uptime figure or a recovery objective.

Terms: SLA §4 response targets · SLA §5 hosted service levels · SLA §6 service credits. Link to this answer

What happens in a critical outage, and is support 24/7?

A Severity 1 incident gets a human initial response from S.G. Systems within 2 hours, 24/7/365, whether you bought directly or through a reseller, and is worked with engineering until service is restored. You can always report directly to S.G. Systems; the clock starts when your report reaches the S.G. Systems support channel.

  • The commitment is set in the S.G. Systems SLA §4.1. Severity 2 to 4 targets run in business hours (09:00-18:00 local, weekdays) unless your Order says otherwise.
  • Orders that accepted MSA V1.24 keep their accepted support terms until renewal on the new documents.
  • Security incidents follow the notification commitment in Commercial Terms §9.2.

Terms: SLA §4.1 critical support · SLA §3 reporting an issue · Commercial Terms §9.2 security incidents. Link to this answer

Hosting and data location

Who hosts the service?

The V5 Ultimate application runs on Google Cloud Run. The database, sign-in and file storage run on Supabase, which operates on Amazon Web Services. Independent backup and archive copies are kept in Google Cloud Storage. Source code and deployments are managed in GitHub.

  • This describes the V5 Ultimate application. The public marketing website is hosted separately and holds no Customer Data from the application.
  • Operating servers in more than one location does not by itself provide failover for the database or for a whole provider.
  • The sub-processors that process Customer Data are listed on the Sub-processors page.

Terms: Sub-processors. Link to this answer

Where is our data stored geographically?

The V5 Cloud application runs in two locations, the Netherlands and Oregon (United States), and traffic is shared between them, so a visitor may be served from either. The database, sign-in and file storage remain in Oregon, United States, so EU-only data storage is not implied. The locations of your database, files and recovery copies are confirmed for your deployment.

  • As recorded on 30 September 2026, the database, sign-in and files were in Oregon (AWS, via Supabase) and independent backup copies in a Google United States multi-region location. Which of these apply to your deployment is confirmed in your Order.
  • Running the application in the Netherlands does not mean every part of the service, or every backup, is held in the EU. Ask us to confirm each layer for your deployment.
  • On-Premises customers keep data in their own environment.

Terms: On-Premises specification. Link to this answer

Backup and recovery

Failure scenarios, retention vs backups and evidence status in one forwardable page: Backup, recovery & resilience.

What is the Recovery Time Objective (RTO)?

Contractually, the S.G. Systems SLA sets an RTO of 8 hours for Severity 1 incidents on Cloud and 4 hours on Private Cloud. Internally we work to a 4-hour target for restoring the complete service, but that target is provisional and has not yet been proven in a full recovery exercise.

  • The internal 4-hour figure is an objective, not a tested result, and does not replace the contract.
  • A complete takeover of production at another provider has not yet been exercised end to end (see Latest recovery test).

Terms: SLA §5.1 Cloud · SLA §5.2 Private Cloud. Link to this answer

What is the Recovery Point Objective (RPO)?

Contractually, the S.G. Systems SLA sets an RPO of 24 hours on Cloud and 12 hours on Private Cloud. How much data could be lost in practice depends on what fails: if data is corrupted while our database provider is still running, we aim to recover to within about 5 minutes; if the provider itself is unavailable, the latest independent database copy can be up to about 24 hours old, plus the time taken to recover.

  • The 5-minute figure is a working objective for that one scenario and is still being qualified. It is not a guaranteed data-loss limit for the whole service.
  • Private Cloud backup timing is deployment-specific. Ask for the evidence for your deployment before relying on a figure other than the SLA.

Terms: SLA §5.1 Cloud · SLA §5.2 Private Cloud. Link to this answer

How often is the database backed up?

Point-in-time recovery is switched on for the database, and a full independent copy of the database and files is taken every day. Files are also copied on a separate 5-minute schedule, and archive transfers run hourly.

  • Point-in-time recovery is configured for 7 days. The history actually available varies and has recently been slightly under 7 days, so we do not promise an uninterrupted 7-day window.
  • The 5-minute schedule applies to files only. The whole database is not copied every 5 minutes.
  • The S.G. Systems SLA commitment for Cloud is encrypted backups every 24 hours (§5.1).

Terms: SLA §5.3 disaster recovery. Link to this answer

How long are backups and records kept?

Rolling recovery copies are kept for at least 30 days and operational evidence for 365 days. Scoped manufacturing and contract-signature records are also archived with a 15-year minimum retention setting. No automatic deletion of archives is currently enabled.

  • The archive retention setting is not yet locked, so it can be changed by administrators. We do not describe it as tamper-proof (WORM) storage, and proving that complete, readable historical records can be produced for the full period is still in progress.
  • Backup retention is separate from your contract rights. After termination, Customer Data is retrievable on request for 90 days under Commercial Terms §5.4 (MSA §5.4 for prior Orders), then deleted from active systems subject to the DPA, legal holds and backup rotation. You remain responsible for your own regulatory record retention (§7.3).

Terms: Commercial Terms §5.4 after termination · Commercial Terms §7.3 data retention. Link to this answer

When was recovery last tested, and what did it show?

On 30 September 2026 we restored the previous day's real backup copies into an isolated environment. The database tables, rows and available files were checked, stored signature hashes were verified, and a sample of encrypted values was successfully decrypted.

  • Not yet proven: a full production takeover at another provider, a hosted point-in-time restore, restoring original passwords, MFA and single sign-on, every external dependency, and end-to-end service timings.
  • A separate test showed application traffic rerouting in about 79 seconds. That was an application-only routing test, not a database recovery and not a service-level commitment.
  • Our policy requires restore tests at least every 90 days and an annual regional or provider exercise.

Link to this answer

Do you have a business continuity and disaster recovery policy?

We have a documented backup and recovery policy and operating guide (current versions dated 30 September 2026). A summary and the latest test evidence are available on request, usually under NDA. We do not currently publish a separate, broader business continuity plan, and we don't claim one beyond what those documents cover.

  • The infrastructure programme behind the policy closed with recorded exceptions. That is not a blanket compliance approval.
  • An approved assessment (rev 3, 25 September 2026) covers the V5 Ultimate 5.10 manufacturing technical controls. It does not cover the QMS or QC areas and is not a disaster-recovery certification.
  • The S.G. Systems SLA §5.3 commits to a disaster recovery plan and periodic recovery testing.

Terms: SLA §5.3. Link to this answer

Encryption and data protection

How is data encrypted?

The Commercial Terms (MSA V1.24 for prior Orders) commit to encryption for hosted services and encrypted backups. Connections from users to the service use TLS. We are confirming the exact algorithms and scope for each layer, and share that confirmation on request rather than publish unverified detail.

  • One internal connection, between the database connection pooler and the database, is still being confirmed. For that reason we don't claim end-to-end encryption.
  • On-Premises customers manage their own encryption and keys.

Terms: Commercial Terms §7.3 · Commercial Terms §9.1 security. Link to this answer

How quickly will you notify us of a breach?

Without undue delay and in any event within 72 hours of becoming aware of a Security Incident, followed by a detailed report within 3 business days. The clock runs from awareness, not from later confirmation. Any shorter period required by law or the DPA applies.

Terms: Commercial Terms §9.2. Link to this answer

Can we export our data when we leave, and what does it cost?

Yes. You can export using the software's standard export methods during the subscription and for 90 days after termination on request. Standard exports are not charged as migration services. Custom formats or extra work need a separate written agreement.

  • Standard exports keep records linked to their audit trail and e-signature information as far as the export format allows.

Terms: Commercial Terms §12.5 data export · Commercial Terms §5.4 after termination. Link to this answer

Insurance and commercial terms

What cyber and professional indemnity insurance do you hold?

We don't publish insurance limits. Ask us for current certificates and we will share them through the document request below.

Link to this answer

Can the deposit be reviewed?

Payment and deposit terms are set in your Order and the applicable commercial terms. Requests to change them are reviewed by our commercial team; nothing is agreed until it is confirmed in writing.

Terms: Commercial Terms Section 6 fees and payment. Link to this answer

Can the liability cap be reviewed?

The current Commercial Terms (§17) limit total liability to the fees paid under the applicable Order in the 12 months before a claim, subject to its agreed terms and exceptions. Requests to change the cap are reviewed by our commercial team and apply only once agreed in writing.

Terms: Commercial Terms §17.1. Link to this answer

Sources and evidence dates

  • S.G. Systems Support & Service Level Agreement (v5ultimate.com/legal/sla, provided by S.G. Systems, LLC for direct and reseller customers), V5 Commercial Terms for Software and Services (v5ultimate.com/legal/commercial-terms) and SG Systems EULA (v5ultimate.com/legal/eula) — contractual commitments; Orders that accepted Master Services Agreement V1.24 (v5ultimate.com/legal/msa) keep its terms
  • SG Systems backup and recovery policy SG-POL-BR-001 v2.9 and guide SG-GDE-BR-001 v2.7, 30 September 2026 — current operating facts (internal; summarised here, not published)
  • Isolated recovery check of 30 September 2026 using 29 September 2026 copies — latest evidence
  • Owner/CTO confirmation, 6 October 2026: the application runs in the Netherlands and Oregon with traffic shared between them; the database is unaffected (internal)

Controlled documents (backup and recovery policy summary, recovery-test evidence, encryption scope, insurance certificates, deployment-specific terms) are shared on request, usually under NDA. 16 questions answered on this page.

Change history

Current · v1.3 · 6 October 2026

Application locations updated: the V5 Cloud application now runs in the Netherlands and Oregon (United States), with traffic shared between both, instead of a split by customer region.

Scope: Application servers only. The database, sign-in and file storage remain in Oregon, United States, and EU-only data storage is not implied. Recovery evidence status is unchanged: complete end-to-end service recovery evidence is still required.

Evidence: Owner and CTO confirmation, 6 October 2026. No test result, failover qualification or approval is implied.

Affects: /security, /security/backup-recovery, /faq/where-is-my-data-stored, /numbers

v1.2 · 2 October 2026

Deployment split clarified: EMEA and EU deployments run in the Netherlands; the rest of the world runs in Oregon, United States. An internal programme name was removed from the assessment answer.

Scope: Deployment server locations only. It does not mean every database, file, backup or provider location, or every earlier customer deployment, is in that region; each layer is confirmed per deployment.

Evidence: Owner and CTO confirmation, 2 October 2026. No test result or approval is implied.

Affects: /security, /security/backup-recovery, /faq/where-is-my-data-stored, Security procurement reference PDF v1.2

v1.1 · 2 October 2026

Server operating locations updated to Oregon (United States) and the Netherlands; Iowa removed. Statements that hosting is US-only or that no EU location exists were withdrawn.

Scope: Server locations only. Database, files and recovery-copy locations are confirmed per deployment; no EU residency, region choice, failover or recovery claim is made.

Evidence: Owner and CTO confirmation, 2 October 2026. No test result or approval is implied.

Affects: /security, /security/backup-recovery, /faq/where-is-my-data-stored, Security procurement reference PDF v1.1 (superseded the same day; not published)

v1.0 · 30 September 2026

First published procurement reference: service levels, hosting layers (application in Oregon and Iowa, database in Oregon, US multi-region backups), backup, recovery and retention.

Scope: Hosted Cloud and Private Cloud.

Evidence: Backup and recovery policy and guide of 30 September 2026; isolated recovery check of 30 September 2026.

Affects: /security, Security procurement reference PDF v1.0

For regulated buyers

SQA, DPA, Part 11 — under NDA

Everything a supplier assessment asks for, in one pack.

Sub-processors

The official list of sub-processors, with purpose, data and location, is kept on one page so it never drifts. We notify designated Customer contacts at least 30 days before adding a new sub-processor.

View the list

On-Premises deployments: no sub-processor has access to Customer Data — all data stays in your environment.

Supplier Quality Addendum (SQA)GxP obligations, on request under NDA.

GxP-specific obligations: change-control notification, deviation reporting, audit rights, validation deliverables. Available on request under NDA.

Data Processing Addendum (DPA)Data-processing terms for personal data.

Contractual data-processing terms for personal data in Customer Data. Under the Commercial Terms (§2.32) the DPA is incorporated where required by law or where we process personal data in Customer Data, and is available on request. Sub-processors are listed on the sub-processor page, which also describes the transfer safeguards used, such as the EU Standard Contractual Clauses.

21 CFR Part 11 / EU Annex 11Clause-by-clause control matrix.

Control matrix mapping platform features to each clause is available on request. An approved assessment (25 September 2026) covers the V5 Ultimate 5.10 manufacturing technical controls. It does not cover the QMS or QC areas, is not a disaster-recovery certification, and does not replace your own intended-use validation.

For security reviews

We answer security questionnaires without flinching.

Architecture diagrams, sub-processor list, DPA, SCCs, SQA and supplier qualification questionnaire — available on request.

Read the Commercial TermsRead the S.G. Systems SLARead the EULAPrivacy & subprocessors

Found a vulnerability?

Email support@sgsystemsglobal.com with a clear description and reproduction steps. We acknowledge within two working days, will keep you informed of remediation, and won't pursue good-faith researchers who follow this policy. Full policy at /.well-known/security.txt.

Showing the site for the United States. Choose your region to see local spelling, dates and prices.

V5 Ultimate
Ultimate

Warehouse, quality and manufacturing software for regulated operations.

ProductIndustriesPricingResourcesSecurity & TrustCompanyLegal centre

© V5 Ultimate

Page version 1.14 · Last revised 5 Oct 2026