Security & trust
How we protect the records auditors read.
V5 stores batch and device records, complaints, CAPAs and e-signatures. This page sets out the controls, where data is hosted and how to get the documents your review needs.

Independently assessed. The technical controls in V5 Ultimate 5.10 were assessed as compliant with 21 CFR Part 11 by Dr Bob McDowall (September 2026) — including access control, audit trail and no permanent delete. Scope: manufacturing execution; your own procedures still apply.
Read the assessmentWhat we protect, how we protect it
One line each. Open any card for the detail.
Encryption — in transit and at restTLS on every connection; encryption and encrypted backups committed in the Commercial Terms.
Encryption for hosted services and encrypted backups are commitments in the Commercial Terms, and user connections use TLS. Per-layer algorithm and scope confirmation is shared on request. On-Premises customers own their encryption keys via their KMS — we never see them.
Identity — SAML SSOSAML 2.0 single sign-on. SCIM provisioning is coming soon.
SAML 2.0 single sign-on with common identity providers such as Okta, Entra ID and Google Workspace; your specific provider is confirmed during scoping. SCIM automatic provisioning is coming soon and is not available yet.
Access control — RBAC + workspace isolationRole-based access, with every tenant query isolated by row-level security.
Roles are stored in a separate user_roles table (not on profiles) to prevent privilege escalation. Every query is RLS-scoped per tenant via security-definer SQL functions. Platform admin gated by hard-coded email allowlist.
Audit trail — queryable, Part 11 controlsWho, when, why and before/after — not editable or deletable in the app.
Signatures, overrides and changes to regulated records are written to an audit trail with user, time, reason and before/after values, and it cannot be edited or deleted through the application. Exact coverage per record type is shown in your demo.
Monitoring & incident responseProduction alerting and a documented incident-response runbook.
Production monitoring with alerts on failed sign-ins, unusual export volume. Documented incident-response runbook with customer notification on confirmed incidents per contract.
Deployment — Cloud or On-PremisesHosted in the Netherlands and Oregon, or On-Premises in your environment.
The hosted application runs in the Netherlands and Oregon (United States) with traffic shared between them; the database, sign-in and file storage remain in Oregon, United States. Hosted services include point-in-time recovery, daily independent copies and a separate backup location; the location of each layer is confirmed for your deployment. On-Premises ships as container images you run in your own environment, with customer-owned database and encryption keys; any outbound connections depend on the features you enable and are confirmed during scoping.
Where V5 Cloud runs
Two app locations. One database.
Traffic is shared between the Netherlands and Oregon. Your records live in one place, with independent backup copies kept separately.
Application
The Netherlands
Google Cloud
Application
Oregon, United States
Google Cloud
Database, sign-in & files
Oregon, United States
Amazon Web Services, via Supabase. EU-only data storage is not offered.
Independent backup copies
Google US multi-region
Kept apart from the live database.
Locations for your deployment are confirmed in your Order. How backup and recovery work
The checklist your security team will ask for
Three areas. Open one to see every control.
Application controls5 controls
- Two e-signatures (preparer + independent reviewer) on formula and master document approval — same-person approvals rejected per 21 CFR 211.186 / 111.205.
- Immutable approved formulas — edits create v+1 and the previous version stays read-only.
- Operator-only users locked to /app/kiosk — no admin UI access.
- Training status can be checked before operator tasks, where your workspace is configured to do so.
- Device calibration status can be checked before use, where configured; the exact scope is shown in your demo.
Platform controls4 controls
- Row-Level Security on every tenant-scoped table; security-definer functions for cross-tenant operations.
- Service-role database key isolated to server-side admin operations; never bundled to client.
- Secrets stored in encrypted secret manager; rotated on schedule.
- S.G. Systems does not hold SOC 2 or ISO 27001. Hosting providers' own assurance reports describe those providers, not S.G. Systems, and are shared on request through the security review process.
Data residency & ownership4 controls
- Hosted services: the V5 Cloud application runs in two locations, the Netherlands and Oregon (United States), and traffic is shared between them, so a visitor may be served from either. The database, sign-in and file storage remain in Oregon, United States, so EU-only data storage is not implied. The locations of your database, files and recovery copies are confirmed for your deployment.
- On-Premises: data stays in your environment; outbound connections depend on the features you enable.
- Customer-owned export: regulated records can be exported for your own retention; formats are confirmed per record type.
- S.G. Systems does not use Customer Data to train AI models (EULA §5.1). When AI features are used, submitted content is processed by the AI providers on the sub-processors page; see How V5 uses AI.
Security assurance
S.G. Systems does not currently hold a security certification or attestation such as ISO 27001, SOC 2 or Cyber Essentials.
Vulnerability disclosure policy
A security.txt file names our security contact and links to the reporting guidance on this page. It is a disclosure route, not a certification.
Independent 21 CFR Part 11 assessment
Dr R.D. McDowall (R D McDowall Ltd, UK) assessed the V5 Ultimate 5.10 manufacturing technical controls against 21 CFR Part 11 and 211; report approved 25 September 2026. QMS and QC areas were out of scope, and your own procedures are still required. This is a regulatory assessment, not a security certification.
Read the scope and reportRelease management for regulated customers
Updates that respect your validated state.
Regulated customers receive advance notice of releases, access to a validation pack on request, and an opt-in upgrade window before changes are applied to their workspace. Full release-management terms — notification lead times, supported version windows, rollback provisions and validation artefacts — are agreed in the customer contract.
If you have specific GxP, Part 11 or Annex 11 requirements you need us to commit to in writing, raise them during procurement and we'll address them in the Commercial Terms or a regulatory addendum.
Procurement reference
Hosting, backup and recovery — straight answers
The questions supplier-assessment teams ask, answered in one place. Where a signed Order or customer-specific agreement exists, it governs. Otherwise the current S.G. Systems SLA and the applicable commercial terms set the commitments; Orders that accepted MSA V1.24 keep its terms. This page describes how the service currently operates; it does not change, add to or replace any contract term.
Version 1.3 · 6 October 2026 · V5 Ultimate hosted services (Cloud and Private Cloud). On-Premises and customer-managed cloud deployments are operated by the customer; see the On-Premises specification.
Service levels and support
Is there an uptime SLA, and how does it differ from a 2-hour response?
They are different measures. Uptime measures how much of the month a hosted service is available. A response target measures how quickly a person at S.G. Systems starts working on your issue. For critical (Severity 1) issues that is 2 hours, 24/7/365. It is not uptime, automated recovery or a guaranteed fix time.
- Uptime, backups, RPO/RTO and service credits apply only to V5 Ultimate Cloud and Private Cloud, under the S.G. Systems SLA (§5 and §6).
- Severity 1 (critical): a person from S.G. Systems responds within 2 hours, 24/7/365, for every supported deployment, including V5 Classic and on-premises. Hosted services also keep a 1 business hour target during business hours. Other severities run in business hours.
- A response time is when a person starts working on the issue. It is not a fix time, an automated recovery, an uptime figure or a recovery objective.
Terms: SLA §4 response targets · SLA §5 hosted service levels · SLA §6 service credits. Link to this answer
What happens in a critical outage, and is support 24/7?
A Severity 1 incident gets a human initial response from S.G. Systems within 2 hours, 24/7/365, whether you bought directly or through a reseller, and is worked with engineering until service is restored. You can always report directly to S.G. Systems; the clock starts when your report reaches the S.G. Systems support channel.
- The commitment is set in the S.G. Systems SLA §4.1. Severity 2 to 4 targets run in business hours (09:00-18:00 local, weekdays) unless your Order says otherwise.
- Orders that accepted MSA V1.24 keep their accepted support terms until renewal on the new documents.
- Security incidents follow the notification commitment in Commercial Terms §9.2.
Terms: SLA §4.1 critical support · SLA §3 reporting an issue · Commercial Terms §9.2 security incidents. Link to this answer
Hosting and data location
Who hosts the service?
The V5 Ultimate application runs on Google Cloud Run. The database, sign-in and file storage run on Supabase, which operates on Amazon Web Services. Independent backup and archive copies are kept in Google Cloud Storage. Source code and deployments are managed in GitHub.
- This describes the V5 Ultimate application. The public marketing website is hosted separately and holds no Customer Data from the application.
- Operating servers in more than one location does not by itself provide failover for the database or for a whole provider.
- The sub-processors that process Customer Data are listed on the Sub-processors page.
Terms: Sub-processors. Link to this answer
Where is our data stored geographically?
The V5 Cloud application runs in two locations, the Netherlands and Oregon (United States), and traffic is shared between them, so a visitor may be served from either. The database, sign-in and file storage remain in Oregon, United States, so EU-only data storage is not implied. The locations of your database, files and recovery copies are confirmed for your deployment.
- As recorded on 30 September 2026, the database, sign-in and files were in Oregon (AWS, via Supabase) and independent backup copies in a Google United States multi-region location. Which of these apply to your deployment is confirmed in your Order.
- Running the application in the Netherlands does not mean every part of the service, or every backup, is held in the EU. Ask us to confirm each layer for your deployment.
- On-Premises customers keep data in their own environment.
Backup and recovery
Failure scenarios, retention vs backups and evidence status in one forwardable page: Backup, recovery & resilience.
What is the Recovery Time Objective (RTO)?
Contractually, the S.G. Systems SLA sets an RTO of 8 hours for Severity 1 incidents on Cloud and 4 hours on Private Cloud. Internally we work to a 4-hour target for restoring the complete service, but that target is provisional and has not yet been proven in a full recovery exercise.
- The internal 4-hour figure is an objective, not a tested result, and does not replace the contract.
- A complete takeover of production at another provider has not yet been exercised end to end (see Latest recovery test).
Terms: SLA §5.1 Cloud · SLA §5.2 Private Cloud. Link to this answer
What is the Recovery Point Objective (RPO)?
Contractually, the S.G. Systems SLA sets an RPO of 24 hours on Cloud and 12 hours on Private Cloud. How much data could be lost in practice depends on what fails: if data is corrupted while our database provider is still running, we aim to recover to within about 5 minutes; if the provider itself is unavailable, the latest independent database copy can be up to about 24 hours old, plus the time taken to recover.
- The 5-minute figure is a working objective for that one scenario and is still being qualified. It is not a guaranteed data-loss limit for the whole service.
- Private Cloud backup timing is deployment-specific. Ask for the evidence for your deployment before relying on a figure other than the SLA.
Terms: SLA §5.1 Cloud · SLA §5.2 Private Cloud. Link to this answer
How often is the database backed up?
Point-in-time recovery is switched on for the database, and a full independent copy of the database and files is taken every day. Files are also copied on a separate 5-minute schedule, and archive transfers run hourly.
- Point-in-time recovery is configured for 7 days. The history actually available varies and has recently been slightly under 7 days, so we do not promise an uninterrupted 7-day window.
- The 5-minute schedule applies to files only. The whole database is not copied every 5 minutes.
- The S.G. Systems SLA commitment for Cloud is encrypted backups every 24 hours (§5.1).
How long are backups and records kept?
Rolling recovery copies are kept for at least 30 days and operational evidence for 365 days. Scoped manufacturing and contract-signature records are also archived with a 15-year minimum retention setting. No automatic deletion of archives is currently enabled.
- The archive retention setting is not yet locked, so it can be changed by administrators. We do not describe it as tamper-proof (WORM) storage, and proving that complete, readable historical records can be produced for the full period is still in progress.
- Backup retention is separate from your contract rights. After termination, Customer Data is retrievable on request for 90 days under Commercial Terms §5.4 (MSA §5.4 for prior Orders), then deleted from active systems subject to the DPA, legal holds and backup rotation. You remain responsible for your own regulatory record retention (§7.3).
Terms: Commercial Terms §5.4 after termination · Commercial Terms §7.3 data retention. Link to this answer
When was recovery last tested, and what did it show?
On 30 September 2026 we restored the previous day's real backup copies into an isolated environment. The database tables, rows and available files were checked, stored signature hashes were verified, and a sample of encrypted values was successfully decrypted.
- Not yet proven: a full production takeover at another provider, a hosted point-in-time restore, restoring original passwords, MFA and single sign-on, every external dependency, and end-to-end service timings.
- A separate test showed application traffic rerouting in about 79 seconds. That was an application-only routing test, not a database recovery and not a service-level commitment.
- Our policy requires restore tests at least every 90 days and an annual regional or provider exercise.
Do you have a business continuity and disaster recovery policy?
We have a documented backup and recovery policy and operating guide (current versions dated 30 September 2026). A summary and the latest test evidence are available on request, usually under NDA. We do not currently publish a separate, broader business continuity plan, and we don't claim one beyond what those documents cover.
- The infrastructure programme behind the policy closed with recorded exceptions. That is not a blanket compliance approval.
- An approved assessment (rev 3, 25 September 2026) covers the V5 Ultimate 5.10 manufacturing technical controls. It does not cover the QMS or QC areas and is not a disaster-recovery certification.
- The S.G. Systems SLA §5.3 commits to a disaster recovery plan and periodic recovery testing.
Terms: SLA §5.3. Link to this answer
Encryption and data protection
How is data encrypted?
The Commercial Terms (MSA V1.24 for prior Orders) commit to encryption for hosted services and encrypted backups. Connections from users to the service use TLS. We are confirming the exact algorithms and scope for each layer, and share that confirmation on request rather than publish unverified detail.
- One internal connection, between the database connection pooler and the database, is still being confirmed. For that reason we don't claim end-to-end encryption.
- On-Premises customers manage their own encryption and keys.
Terms: Commercial Terms §7.3 · Commercial Terms §9.1 security. Link to this answer
How quickly will you notify us of a breach?
Without undue delay and in any event within 72 hours of becoming aware of a Security Incident, followed by a detailed report within 3 business days. The clock runs from awareness, not from later confirmation. Any shorter period required by law or the DPA applies.
Can we export our data when we leave, and what does it cost?
Yes. You can export using the software's standard export methods during the subscription and for 90 days after termination on request. Standard exports are not charged as migration services. Custom formats or extra work need a separate written agreement.
- Standard exports keep records linked to their audit trail and e-signature information as far as the export format allows.
Terms: Commercial Terms §12.5 data export · Commercial Terms §5.4 after termination. Link to this answer
Insurance and commercial terms
What cyber and professional indemnity insurance do you hold?
We don't publish insurance limits. Ask us for current certificates and we will share them through the document request below.
Can the deposit be reviewed?
Payment and deposit terms are set in your Order and the applicable commercial terms. Requests to change them are reviewed by our commercial team; nothing is agreed until it is confirmed in writing.
Terms: Commercial Terms Section 6 fees and payment. Link to this answer
Can the liability cap be reviewed?
The current Commercial Terms (§17) limit total liability to the fees paid under the applicable Order in the 12 months before a claim, subject to its agreed terms and exceptions. Requests to change the cap are reviewed by our commercial team and apply only once agreed in writing.
Sources and evidence dates
- S.G. Systems Support & Service Level Agreement (v5ultimate.com/legal/sla, provided by S.G. Systems, LLC for direct and reseller customers), V5 Commercial Terms for Software and Services (v5ultimate.com/legal/commercial-terms) and SG Systems EULA (v5ultimate.com/legal/eula) — contractual commitments; Orders that accepted Master Services Agreement V1.24 (v5ultimate.com/legal/msa) keep its terms
- SG Systems backup and recovery policy SG-POL-BR-001 v2.9 and guide SG-GDE-BR-001 v2.7, 30 September 2026 — current operating facts (internal; summarised here, not published)
- Isolated recovery check of 30 September 2026 using 29 September 2026 copies — latest evidence
- Owner/CTO confirmation, 6 October 2026: the application runs in the Netherlands and Oregon with traffic shared between them; the database is unaffected (internal)
Controlled documents (backup and recovery policy summary, recovery-test evidence, encryption scope, insurance certificates, deployment-specific terms) are shared on request, usually under NDA. 16 questions answered on this page.
Change history
Current · v1.3 · 6 October 2026
Application locations updated: the V5 Cloud application now runs in the Netherlands and Oregon (United States), with traffic shared between both, instead of a split by customer region.
Scope: Application servers only. The database, sign-in and file storage remain in Oregon, United States, and EU-only data storage is not implied. Recovery evidence status is unchanged: complete end-to-end service recovery evidence is still required.
Evidence: Owner and CTO confirmation, 6 October 2026. No test result, failover qualification or approval is implied.
Affects: /security, /security/backup-recovery, /faq/where-is-my-data-stored, /numbers
v1.2 · 2 October 2026
Deployment split clarified: EMEA and EU deployments run in the Netherlands; the rest of the world runs in Oregon, United States. An internal programme name was removed from the assessment answer.
Scope: Deployment server locations only. It does not mean every database, file, backup or provider location, or every earlier customer deployment, is in that region; each layer is confirmed per deployment.
Evidence: Owner and CTO confirmation, 2 October 2026. No test result or approval is implied.
Affects: /security, /security/backup-recovery, /faq/where-is-my-data-stored, Security procurement reference PDF v1.2
v1.1 · 2 October 2026
Server operating locations updated to Oregon (United States) and the Netherlands; Iowa removed. Statements that hosting is US-only or that no EU location exists were withdrawn.
Scope: Server locations only. Database, files and recovery-copy locations are confirmed per deployment; no EU residency, region choice, failover or recovery claim is made.
Evidence: Owner and CTO confirmation, 2 October 2026. No test result or approval is implied.
Affects: /security, /security/backup-recovery, /faq/where-is-my-data-stored, Security procurement reference PDF v1.1 (superseded the same day; not published)
v1.0 · 30 September 2026
First published procurement reference: service levels, hosting layers (application in Oregon and Iowa, database in Oregon, US multi-region backups), backup, recovery and retention.
Scope: Hosted Cloud and Private Cloud.
Evidence: Backup and recovery policy and guide of 30 September 2026; isolated recovery check of 30 September 2026.
Affects: /security, Security procurement reference PDF v1.0
SQA, DPA, Part 11 — under NDA
Everything a supplier assessment asks for, in one pack.
Sub-processors
The official list of sub-processors, with purpose, data and location, is kept on one page so it never drifts. We notify designated Customer contacts at least 30 days before adding a new sub-processor.
View the listOn-Premises deployments: no sub-processor has access to Customer Data — all data stays in your environment.
Supplier Quality Addendum (SQA)GxP obligations, on request under NDA.
GxP-specific obligations: change-control notification, deviation reporting, audit rights, validation deliverables. Available on request under NDA.
Data Processing Addendum (DPA)Data-processing terms for personal data.
Contractual data-processing terms for personal data in Customer Data. Under the Commercial Terms (§2.32) the DPA is incorporated where required by law or where we process personal data in Customer Data, and is available on request. Sub-processors are listed on the sub-processor page, which also describes the transfer safeguards used, such as the EU Standard Contractual Clauses.
21 CFR Part 11 / EU Annex 11Clause-by-clause control matrix.
Control matrix mapping platform features to each clause is available on request. An approved assessment (25 September 2026) covers the V5 Ultimate 5.10 manufacturing technical controls. It does not cover the QMS or QC areas, is not a disaster-recovery certification, and does not replace your own intended-use validation.
We answer security questionnaires without flinching.
Architecture diagrams, sub-processor list, DPA, SCCs, SQA and supplier qualification questionnaire — available on request.
Found a vulnerability?
Email support@sgsystemsglobal.com with a clear description and reproduction steps. We acknowledge within two working days, will keep you informed of remediation, and won't pursue good-faith researchers who follow this policy. Full policy at /.well-known/security.txt.
