Spell QMS Pro brings risk, audits, findings, CAPA, document control, change requests, management review and validation into a single audit-grade workspace. Spella, our built-in AI, drafts and verifies at every step.
Enterprise cloud · ISO 13485 / Part 11 aligned · Multi-tenant SSO
The QMS modules
Twelve linked modules cover risk, audits, findings, CAPA, documents, change, management review and validation. They share one evidence trail.
Author, version and approve your Quality Policy with ISO clause gap-check built in.
Per-department, SMART, year-scoped objectives with auto-lint and progress tracking.
Scope statements, departments and the roster of responsible people, all in one place.
Risk register, 5×5 inherent + residual assessments, treatment plans and a live heat-map.
Plans, schedules, scopes, checklists, engagement letters and a binder-ready audit pack.
Raised directly from a non-conforming checklist response. Close with evidence, reopen on regression.
5-Why root cause, corrective + preventive actions, and a 90-day effectiveness watch.
Requester → management recommendation → GM decision → approve, reject or reopen.
Header, agenda, item analysis, decisions and a minutes formatter. Exportable as a signed PDF.
PDF documents with revisions, approval flow, sequence numbering and controlled-copy issuance.
21 CFR Part 11 e-signatures, a 4-step wizard, and a custom-template generator for any software.
A cross-cutting AI teammate that drafts, verifies, generates and narrates inside every screen.
Spella isn't a sidebar chatbot. She drafts, verifies, generates and narrates from inside the same screens your QA team is already on. Every call is audit-logged.
Spella writes the first draft so your team can edit, not stare at a blank page.
Second-pair-of-eyes checks Spella runs before your team submits anything.
Spella assembles structured artifacts in seconds instead of weeks.
Always-on awareness: narration, anomaly alerts and tenant-wide admin help.
Every Spella call is tied to a tenant, a user and an audit event. No silent prompts, no shadow data.
Compliance posture
Does what regulators expect, without the bloat. The five things they ask for first are already in the box.
Every state change is sealed against the previous one and cannot be edited or deleted once written. Tamper-evident, not just timestamped.
Validation approvals require re-authentication, capture signature meaning, and seal who signed and when.
Seven-year record retention out of the box, with a ten-year floor on the audit log. Configurable per tenant.
Data access (Article 15) and erasure (Article 17) requests served from a single admin screen with full traceability.
Every record is scoped to its tenant. Super-admins switch tenants from the topbar; data never crosses by accident.
Platform
We operate the platform end to end so your QA team spends time on quality, not on keeping servers alive.
High-availability deployment with automated failover. Data is encrypted at rest and in transit and never leaves your region.
Email and password today. SAML and OIDC ready for enterprise rollout when you need it, with multi-factor on every account.
Reasoning that drafts, critiques and links your QMS records. Per-tenant credit caps, feature gates and a full audit trail on every call.
Anomaly scans, daily digests, overdue-validation watches, CAPA effectiveness windows and retention purges run on their own, on time.
Engagement letters, digests and notifications delivered from your verified domain, with bounce monitoring built in.
Every action is logged, metered and visible to your administrators. No bolted-on agents, no blind spots.
Trust + security
Encryption at rest and in transit. Role-based access. Per-tenant isolation. A signed Data Processing Agreement on request. Read the full trust posture and grab the DPA template below.
What we don't do
Book a 15-minute call. We'll walk through your current QMS, show you the equivalent screens in Spell QMS Pro, and get back to you with a provisioned tenant inside one business day.
Request access