V5 Ultimate
On-prem · Self-hosted · Air-gapped · GxP

On-premises QMS & MES — full GxP, your data, your network.

Some sites can't put batch data in someone else's cloud — sovereignty, defense work, contractual constraints, or sites where the WAN drops every Tuesday. V5 On-Prem is the same platform, deployed on your hardware (or your private cloud), with the same UX, the same validation package, and zero feature gap from the SaaS edition.

The problem

What breaks without this.

Cloud-only vendors can't sell into half your sites

Sovereignty, classified work, contractual data-residency clauses, or unreliable connectivity mean cloud is a non-starter for many plants — and the vendor's answer is 'we'll get there in v.next.'

Air-gap is a hard requirement, not a nice-to-have

Defense, certain CMO contracts, and some government health agencies require an air-gapped deployment that never touches the public internet. Most cloud-first SaaS vendors can't ship it.

On-prem from legacy vendors means 2005 UX

The on-prem product is the abandoned codebase. Cloud users get the features; on-prem users get the maintenance patches.

Validating your own deployment is a project, not a download

Without a vendor IQ/OQ/PQ package mapped to your URS, validation is 6–12 months of internal effort before the first batch runs.

How V5 solves it

Records-by-execution. Compliance, by design.

01

One codebase, two deployment modes

V5 On-Prem is the same codebase as V5 Cloud — same UI, same APIs, same release cadence. Your on-prem site gets every feature the cloud site does, in lockstep.

02

Air-gap capable, with offline activation

V5 runs fully disconnected: offline license activation, in-perimeter updates via signed packages, optional one-way data diode for export-only telemetry.

03

Hardware reference designs + validation package

Sized reference architectures for 50 / 500 / 5,000 users, Kubernetes or VM, Postgres HA. The vendor IQ/OQ/PQ + traceability matrix shortens internal validation to gap testing.

04

Identity that fits your network

SAML 2.0 SSO, LDAP / AD bind, SCIM provisioning, certificate auth, optional FIDO2 hardware keys for Part 11 e-signature.

05

Backup, DR and inspection-ready exports

Encrypted PITR backups, hot/warm DR, and signed export bundles for FDA/EMA inspection — independent of the live system.

Buyer's guide

What to look for when you're buying.

On-prem QMS/MES must be operable by your IT team, not require a phone call to the vendor for every log rotation. Criteria below tell the two apart.

Air-gap capable

What it tests: Does the system run with no outbound internet at all?

Why it matters: Defense, sovereign and regulated networks require it.

V5: Air-gap operable, including licensing and update flow.

Full validation pack

What it tests: Does the release ship with IQ/OQ/PQ that your CSV team can execute?

Why it matters: Otherwise every install is a services engagement.

V5: Validation pack ships with every release; IQ/OQ automated; PQ template for your site.

Update process under change control

What it tests: Are updates version-pinned with a documented delta?

Why it matters: Regulated sites cannot auto-update.

V5: Customer-instigated updates with signed delta and previous versions maintained in Git.

Backup, restore and BCP

What it tests: Are backup/restore, HA and DR procedures documented and tested?

Why it matters: You own the runbook.

V5: Documented and tested runbook per release.

Sizing and reference architecture

What it tests: Do you get a real sizing guide against real workload signals?

Why it matters: Vendors that hand-wave here cost you outages.

V5: Sizing guide with reference architecture — see /resources/on-prem-specification.

Compared

Spreadsheet vs legacy QMS vs V5.

On-prem V5 vs cloud-only vs legacy on-prem.

CapabilitySpreadsheetLegacy QMSV5 Ultimate
Air-gapN/ASometimesYes
Validation packN/AConsultantIncluded per release
Customer-instigated updatesN/AVendor-drivenNative, no push
RunbookN/AAd-hocDocumented and tested
Regulatory deep-dive

The clauses, verbatim — and how V5 answers each.

On-prem is a data-sovereignty and validation story more than a features story.

GAMP 5
A risk-based approach to validation of computerised systems throughout the lifecycle.

V5: Category 4 configuration path; on-prem tenant PQ delta only.

EU GMP Annex 11 §4.5
The regulated user should take all reasonable steps to ensure that the system has been developed in accordance with an appropriate quality management system.

V5: V5 SDLC documented and shared under MSA; source-of-truth in Git.

21 CFR Part 11 §11.10(k)
Use of appropriate controls over systems documentation...

V5: Signed doc set per release with prior versions retained.

How it works in V5

Step by step on the floor.

On-prem lifecycle.

  1. 1
    Size

    Reference architecture applied

    Hardware and network sized to workload.

  2. 2
    Install

    IQ/OQ executed

    Automated where safe; witnessed where required.

  3. 3
    PQ

    Site-specific PQ

    System-assist for private-cloud and on-prem tenants.

  4. 4
    Operate

    Runbook active

    Backup/DR/HA per documented runbook.

  5. 5
    Update

    Customer-instigated release

    Delta reviewed; validation pack executed; previous versions retained.

ROI & cost of failure

The math, with the assumptions visible.

On-prem ROI is sovereignty and control, not headline TCO.

Sovereignty risk

Before
Cloud dependency
With V5
Removed

On-prem full-stack.

Update disruption

Before
Vendor-driven
With V5
Customer-driven

No forced updates.

Time to install

Before
Months
With V5
Weeks

Automated IQ/OQ.

For sovereign customers, sovereignty is the ROI.

Customer scenario

What changed on the floor.

Setting

A defense-adjacent contract manufacturer.

Before

Prior QMS required outbound internet; failed a customer security review.

After

V5 air-gapped; passed security review; customer-instigated update process aligned to change board.

What you get

Proof points

  • Same release cadence as V5 Cloud — no feature gap
  • Air-gap deployments live in defense, biodefense, and classified CMO programs
  • Validation pack: IQ/OQ/PQ, URS traceability, risk assessment, GAMP 5 category mapping
  • Reference architectures from single-VM (under 50 users) to multi-region HA
  • Postgres HA + PITR; Kubernetes or plain VMs; SAML/LDAP/SCIM
  • On-Prem Addendum + signed validation summary included in MSA
Regulatory anchors

Built to satisfy

  • 21 CFR Part 11 (Electronic records & signatures)
  • 21 CFR 820 (QSR — medical devices)
  • 21 CFR 211 (Pharma GMP)
  • EU GMP Annex 11 (Computerised systems)
  • GAMP 5 (validation lifecycle)
  • EU GDPR / data-residency

Frequently asked questions

Is V5 On-Prem a different product from V5 Cloud?+

No — it's the same codebase deployed differently. Same UI, same APIs, same release cadence. On-Prem sites get every feature cloud sites do, in lockstep.

Can V5 run fully air-gapped?+

Yes. Offline license activation, signed in-perimeter update packages, no outbound network requirement. Optional one-way data diode for export-only telemetry.

What does the validation package cover?+

Vendor IQ/OQ/PQ, traceability to a sample URS, risk assessment, GAMP 5 category mapping, and a signed validation summary. Customer-side validation focuses on gap testing, not a from-scratch project.

What infrastructure do we need?+

Sized reference designs from single-VM (under 50 users) to multi-region HA on Kubernetes with Postgres HA + PITR. We publish hardware specs in the on-prem specification PDF.

See V5 on your own line.

Free trial, no card. Live in 7 days with guided onboarding.