Frequently asked questions
Everything a quality team asks before signing up. Don’t see your question? Ask us.
An AI-native electronic quality management system (eQMS) for small life-sciences teams — 21 CFR Part 11 and GAMP 5, with seventeen connected modules (document control, change control, complaints, CAPA, corrections & removals, nonconformances, design controls/DHF, human factors (HFE/UE), risk, post-market surveillance, training, suppliers, calibration & maintenance, audits, management review, quality policy & objectives, and projects/validation) that all share one immutable audit trail.
Small and mid-size medical device companies, and early-stage and pre-commercial biotech and pharma — teams too small for Veeva and tired of the price tag and long rollouts of the incumbents. If you're running quality on spreadsheets or a shared drive, this replaces that with a real, compliant system.
Published, transparent pricing starting at $9,900/year — no "contact sales to see a price." See the pricing page for all tiers and a year-one cost comparison against the incumbents.
The validation package is. Every plan includes it — Validation Plan, System Requirements Specification, Part 11 traceability, IQ and PQ protocols, and 4,500+ automated tests. Validation itself is not something a vendor can hand you — it is your demonstration that the system fits your intended use. Your User Requirements Specification is your own document — it captures what your processes need. We execute Installation Qualification against your instance, as its own hourly line. PQ is yours by definition — it demonstrates your processes, on your system, run by your trained people — and we support you through it rather than a separate $20–50k implementation invoice. If you want hands-on help with your URS or your PQ, we can introduce you to an independent validation consultant, billed at their rate and passed through at cost.
Set-up takes days, not the 3–9 month rollouts the incumbents run. Every customer gets guided onboarding (remote by default) so you're configured correctly and don't have to figure out compliance on your own. Qualifying it for your intended use takes longer: we execute Installation Qualification against your instance, and your Performance Qualification moves at your quality team's pace.
Yes. AI-assisted migration ingests your legacy documents (PDF/Word), proposes the metadata, and a human reviews before anything commits. Legacy documents are imported as "migrated" with their prior approval recorded — never with a forged electronic signature — and your quality lead signs a single migration verification.
Straight answer, because this is the question that decides whether a switch is realistic. Documents come across through bulk migration. Five registers come across from a spreadsheet — a risk analysis, your supplier list, your equipment register, your complaint log, and your nonconformance log — where a risk analysis lands as one new Draft assessment and the others land one record per row. Both routes keep the previous system's approval recorded as legacy and never forge a signature over it, you check every row before it commits, and your quality lead signs one verification bound to exactly what was accepted. Everything else has no importer: CAPAs, training records, internal audits, change controls, the design history file, management reviews, and post-market surveillance plans stay where they are. That is deliberate — we import what can be validated field by field and refused when it can't, rather than inferring what a CAPA investigation concluded, because you cannot audit a guess. What we do instead is plan it with you during onboarding: open records are usually few and are re-raised by hand with the old number written into them, training is re-assigned on the migrated documents, and your closed history is exported from the old system and retained outside Indelio for your retention period. We write that plan down per record type before your old subscription lapses — it is CUEC-09 in the validation package, because losing access to closed records you are still required to keep is the real risk in any eQMS switch.
A fair question, and you should ask it. We're young, and you'd be putting your controlled documents, signatures, and audit trail on us — so here's what protects you, none of which requires trusting us. You're never locked in: no multi-year contract, month-to-month if you want it, so the most you ever have at risk is the time since your last invoice. Your records are portable — Indelio runs on standard PostgreSQL and your documents, signatures, and full audit history export in human-readable form whenever you ask. No record is ever deleted: signatures and the audit trail are append-only, enforced at the database against every application account, our own included, and anything removed from a draft is recorded in the audit trail with what it held. And the validation package — Validation Plan, SRS, traceability matrix, IQ and PQ protocols, and your executed records — are documents in your possession that don't stop existing if we do. An established vendor answers this with their size; we answer it with your exit.
You own your data. Pricing is month-to-month if you want it — no multi-year lock-in — and the platform runs on standard Postgres, so your records are portable. We win by being worth keeping, not by trapping you.
The controls are enforced server-side, not bolted on the surface: an immutable, hash-chained audit trail; two-component electronic signatures re-verified at signing; segregation of duties enforced server-side — in most modules separating the steps, so whoever signs one gate cannot sign the next, and in a set of single-signature records separating the author from the approver; and content-hash binding so any edit after signing breaks the seal. See the Security & Compliance page for the full picture.
Row-level security scopes every table to your organization at the database layer, so tenants are isolated by the database — not just the app. Access is role-based, with two-factor authentication mandatory on administrator accounts and available to every user, plus idle-session timeout and failed-login lockout. Any keys you bring are encrypted at rest.
AI assists (drafting and revising SOPs, listing the regulations an SOP cites for you to verify, migrating documents) but is never the final approver — a human signs every record. AI inputs are sanitized against prompt injection, and you can bring your own AI key so your AI usage runs under your own data terms.
Straight answer: the Part 11 controls are built and tested today, and no platform arrives validated. Operational Qualification evidence — the automated test suite — comes with every plan. Installation Qualification is executed against your instance by us, priced as its own hourly line, because most of it reads the hosting and database consoles a tenant does not have. Performance Qualification is yours: it runs your processes, under your SOPs, with your people, so you execute and sign it and we never can — a system is only "validated" once that's done against your instance. A SOC 2 program is on our roadmap, pursued when a customer requires it. We'd rather tell you exactly where we are than overstate it.
Yes — a 30-day free trial with the full platform, not a limited demo. Thirty days is deliberate: segregation of duties means you can't approve your own document, so genuinely evaluating it needs a second user and a full author → review → approve cycle with e-signatures. Anything you build during the trial carries over if you convert, so you never redo the work. Separately, we're taking on three Founding Partners who get the platform free for 60 days, with onboarding and Installation Qualification included at no charge, in exchange for real use and feedback.
Support is by email at info@voxelioai.com on US business days (Eastern time), with a first reply within one business day. Critical issues — you can't sign in, can't sign a record, or a record or file looks wrong or missing — are acknowledged the same business day, on every plan. Priority support (Scale): a first reply the same business day for anything received by 12:00 ET. These are reply times, not fix times.