21 CFR Part 11Updated September 26, 2026

Part 11 controls built into every record

Electronic signatures that re-check the signer, an audit trail nobody can edit, server-set timestamps and access that expires on schedule. The controls Part 11 asks for are part of how Capture stores data, not a setting to switch on.

  • E-signatures with re-authentication
  • Tamper-evident audit trail
  • Role-based access

Free sandbox · No credit card · 21 CFR Part 11 aligned

Electronic signature

Meaning of signature

I have reviewed this adverse event and confirm the assessment of seriousness, severity and causality.

Signer

Dr. A. Ozola, PI

Password

••••••••••

Verified on the serverAutofill blockedSingle-use token
Sign

SHA-256

hash chain across audit entries

0

edits or deletes allowed on the audit trail

90 days

password expiry, enforced on the server

7

study roles with their own permissions

Part 11 controls

What Part 11 asks for, and where Capture handles it

A plain summary of the technical controls. Compliance also depends on your own procedures and validation.

Audit trail of record changes

Field-level audit written by the database, with who, when, old value, new value and reason.

Records that cannot be altered unnoticed

Append-only audit trail with a per-study SHA-256 hash chain and a verify check.

Electronic signatures linked to records

Password re-entry at signing, with the signer, time and meaning of the signature stored.

Limited system access

Role-based permissions per study and site, with passwords that expire.

Accurate timestamps

Timestamps and IP addresses set by the server, never by the browser.

Records kept for review

Clinical data is soft-deleted only, and audit exports are filterable CSV.

E-signatures

Signatures that prove who signed and why

Every signature asks for the password again, checked on the server. The record stores the signer, the time and the meaning of the signature, such as an investigator attesting to an AE assessment.

  • Password re-entry verified on the server with a single-use token.
  • Browser autofill blocked in every signature dialog.
  • Meaning statement stored with each signature.
  • Signing under delegation recorded as such.
  • Expired accounts cannot sign until the password is changed.
Electronic signature

Meaning of signature

I have reviewed this adverse event and confirm the assessment of seriousness, severity and causality.

Signer

Dr. A. Ozola, PI

Password

••••••••••

Verified on the serverAutofill blockedSingle-use token
Sign

Audit trail

An audit trail that cannot be rewritten

Database triggers write the audit trail, one row per changed field. Updates and deletes are blocked, and each entry carries a hash of the one before it, so any tampering breaks the chain.

  • Old and new value, user, reason and server time for every change.
  • SHA-256 hash chain per study, with a "Verify chain" check.
  • Technical events kept in a separate system log, so the GCP audit trail holds regulated actions only.
  • Readable descriptions and filters by category, user, participant and date.
More on audit trail software

Weight changed 68.0 to 68.5 kg

Site coordinator · Reason: Transcription error

9f2c…a71e

Query Q-0014 answered on Weight

Site coordinator · Reason: Source checked

4b8d…c203

Vital signs form locked

Data manager · Reason: Visit cleaned

e61a…58f0
Verify chain Intact

Check the controls yourself

Sign a form, change a value and read the audit trail in a free sandbox.

Explore the controls free

Access

Access that stays limited to the right people

Permissions follow the role matrix for every study and site. Passwords expire every 90 days, and an expired account can read but cannot write or sign until the password is changed.

  • Study owner, PI, sub-investigator, coordinator, monitor, data manager and participant roles.
  • Site staff see only their assigned sites.
  • Password expiry enforced on the server, not just shown as a banner.
  • Participant portal sessions that time out, with login events audited.
  • SO

    Study owner

    Builds and configures the study

  • PI

    Principal investigator

    Oversees the site, signs off the casebook

  • SI

    Sub-investigator

    Enters and signs clinical data

  • SC

    Study coordinator

    Screens subjects, enters visit data

  • CRA

    Monitor (CRA)

    Verifies data, raises queries

  • DM

    Data manager

    Reviews, freezes and locks data

  • PT

    Participant

    Completes their own questionnaires

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Is Capture 21 CFR Part 11 compliant?

Capture provides the technical controls Part 11 requires: audit trail, electronic signatures, access control and secure timestamps. Full compliance also depends on your procedures, training and validation of your study.

How do electronic signatures work?

The signer re-enters their password, which is verified on the server. The signature stores who signed, when and the meaning of the signature, and is linked to the record.

Can the audit trail be edited?

No. The audit trail is append-only: updates and deletes are blocked in the database, and entries are hash-chained so tampering is detectable.

Are timestamps reliable?

Yes. Timestamps and IP addresses on audit entries are set by the server, not supplied by the browser.

What happens when a password expires?

The user can still sign in and read, but cannot write data or sign until they change the password. The block is enforced on the server.

Does this also cover EU Annex 11?

The same controls, audit trail, signatures and access management, support Annex 11 expectations too. As with Part 11, your procedures complete the picture.

Can deleted data be recovered?

Clinical data is never hard deleted. Removed records are soft-deleted and remain in the audit history.

Can I review the controls before buying?

Yes. Everything described here is available in the free sandbox.

See the Part 11 controls in action

Free sandbox with every feature. No credit card, no sales call.

Explore the controls free