Regulatory compliance

What qTrace covers —
and what it doesn't

qTrace is a provenance and audit-trail layer for digital pathology analysis in QuPath. Each section below maps our features to specific regulatory articles, and clearly states what remains with your laboratory's LIS, QMS, or IT infrastructure.

ISO 15189:2022 + A11:2023

Mapped

ISO/TC 212 · EN ISO 15189:2022 + A11:2023 (eCEN/EVS)

Medical laboratories — Requirements for quality and competence. qTrace addresses the digital pathology examination process (§7.3) and its documentation, traceability, and record-control obligations.

✓ What qTrace covers

  • §7.3.1 d)Operator identity recorded per session — locked to KYC-verified licence, non-editable
  • §7.3.6Examination procedure auto-documented as reproducible Groovy MetaScript
  • §7.3.2Method reproducibility verified via one-click Replay (Compliance module)
  • §7.4.1.8Amendment tracing — every change creates a new git commit, original preserved
  • §7.5Nonconforming work logged — manual detection corrections tracked in Dashboard Card 7
  • §7.6.3Data integrity — tamper-evident SHA-1 git hash + JWT RS256 authentication
  • §8.4.1Records created at the time of each act — ActionLogger hooks WorkflowListener in real time
  • §8.4.2–3Immutable append-only audit trail, backed up off-site via Cloud Workspace Push
  • §8.8Quality indicators dashboard (Cards 1–7) for management review (§8.9)

⬜ Remains with your laboratory

  • §7.2Pre-analytical processes (sample collection, transport) — handled by your LIS/LIMS
  • §6.5Equipment calibration and metrological traceability — physical instruments, out of scope
  • §7.3.4Measurement uncertainty (MU) evaluation — laboratory's statistical responsibility
  • §7.3.7.2Internal Quality Control (IQC) programmes — dedicated QC software required
  • §6.2Personnel competence records and training programmes — your HR/QMS
  • §8.8.3Internal audit programme — qTrace provides the data, audits remain with the lab

Formulation: “qTrace supports ISO 15189:2022 compliance for digital pathology examination processes” — covering §7.3, §7.6, §8.3–8.4, and §8.8, scoped to the QuPath analysis workflow.

Sources

  • EN ISO 15189:2022 — Medical laboratories: Requirements for quality and competence · ISO/TC 212, published via EVS/eCEN
  • A11:2023 — Amendment 1 to ISO 15189:2022 · corrigendum, published 2023

21 CFR Part 11

Mapped

FDA · 21 CFR Part 11 — Electronic Records; Electronic Signatures (eCFR, up to date 25 June 2026)

Sets criteria under which the FDA considers electronic records and signatures trustworthy and equivalent to paper. qTrace operates as a closed system (§11.3(b)(4)) within the QuPath desktop environment.

✓ What qTrace covers

  • §11.10(e)Secure, computer-generated, time-stamped audit trails — ActionLogger, append-only git, no obscuring of prior records
  • §11.10(b)Accurate and complete copies in human-readable and electronic form — .qtrace JSON + batch ZIP export
  • §11.10(c)Record protection and ready retrieval — git local + Supabase off-site + Dashboard search
  • §11.10(g)Authority checks before every signing — JWT RS256 licence + PIN SHA-256 required
  • §11.50(a)Signature manifestations: printed name (KYC-locked), date-time (ISO 8601), meaning (validation/approval)
  • §11.70Signature embedded in record — git hash covers stamp+record; cannot be excised or transferred
  • §11.100(a–b)Unique electronic signature per individual, identity KYC-verified before licence issuance
  • §11.200(a)(1)(ii)Both components (licence + PIN) required at every signing — no single-component shortcut

⬜ Remains with your laboratory

  • §11.10(a)Full system IQ/OQ/PQ validation — computer hardware and OS qualification remains with the lab
  • §11.10(f)(h)Operational system checks and device checks — IT infrastructure responsibility
  • §11.10(i)(j)Personnel training documentation and written accountability policies — your QMS
  • §11.100(c)FDA Letter of Non-Repudiation Agreement — organisational obligation, not a software feature
  • §11.300ID/password management controls (rotation, loss management) — your IT department

Formulation: “qTrace supports 21 CFR Part 11 compliance for electronic records and electronic signatures in digital pathology workflows” — covering §11.10(e), §11.50, §11.70, §11.100, and §11.200, scoped to the QuPath analysis record lifecycle in a closed system.

Sources

  • 21 CFR Part 11 — Electronic Records; Electronic Signatures · eCFR Title 21, Chapter I, Subchapter A, up to date 25 June 2026

GLP / ALCOA+

Mapped

FDA CGMP Data Integrity Guidance (Dec 2018) · MHRA GxP Data Integrity Guidance (Mar 2018) · PIC/S PI 041-1 (Jul 2021) · OECD GLP ENV/MC/CHEM(98)17 · WHO TRS 996 Annex 5 (2016)

ALCOA+ defines nine attributes any laboratory data record must satisfy to be considered reliable and acceptable by regulatory authorities (FDA, EMA, MHRA, ANVISA). It is a principle-based framework applied across GLP, GMP, and GCP — not a single regulation. qTrace addresses all nine attributes for digital pathology analysis records produced in QuPath.

✓ What qTrace covers

  • AttributableOperator identity locked per session via ActionLogger; ValidationStamp identity cryptographically bound to KYC-verified licence — name non-editable, non-transferable
  • LegiblePlain-text JSON format — human-readable in any text editor, no proprietary software required; integrity via git hash, not encryption
  • ContemporaneousActionLogger hooks WorkflowListener in real time — events recorded at the exact moment of each QuPath act, never reconstructed after the fact
  • OriginalGitBridge append-only policy — every modification creates a new commit; the first recording is always recoverable; batch exports flagged as copies
  • AccurateDirect QuPath API interception, no manual transcription; corrections (Dashboard Card 7) appended separately with own timestamp — original record unchanged
  • Complete (+)Full session captured: all workflow steps, classifier changes, annotations, extension list, internal parameters, and manual correction records
  • Consistent (+)Versioned JSON schema, ISO 8601 timestamps throughout, chronological order guaranteed by WorkflowListener event stream — identical format regardless of operator or machine
  • Enduring (+)Open JSON format with no third-party dependency; .qtrace co-located with WSI survives any qTrace update; Cloud Workspace Push provides off-site Supabase backup
  • Available (+)Dashboard search by project/date/operator; batch ZIP export; plain-text format readable without qTrace installed — auditors can examine files directly

⬜ Remains with your laboratory

  • Wet lab dataPCR, spectrophotometry, centrifugation records, paper lab notebooks — your ELN/LIMS; ALCOA+ applies to all lab data, not only digital analysis
  • SOPs / DMSWritten procedures and work instructions must themselves be managed in an ALCOA+-compliant document management system (QMS/DMS)
  • TrainingPersonnel competence and qualification records — regulated ALCOA+ data, belongs in your HR/QMS system
  • Scanner / WSIRaw whole-slide images and scanner acquisition metadata (calibration, lighting, scan parameters) — scanner vendor and imaging archive responsibility
  • CSV / GAMP 5Computer System Validation of the full installation (workstation, OS, network, QuPath) per OECD GLP Consensus Doc n°17 / GAMP 5 — laboratory obligation

Formulation: “qTrace supports GLP/ALCOA+ data integrity principles for digital pathology analysis records in QuPath” — all nine ALCOA+ attributes addressed for the QuPath workflow record lifecycle, scoped to digital image analysis data.

Sources

  • FDA — Data Integrity and Compliance With Drug CGMP · Guidance for Industry, December 2018
  • MHRA — GxP Data Integrity Guidance and Definitions · Revision 1, March 2018

IVDR 2017/746

Mapped

EU Regulation 2017/746 · Official Journal L 117, 5.5.2017 — on in vitro diagnostic medical devices (CELEX:32017R0746)

IVDR primarily regulates IVD device manufacturers and health institutions that develop and use devices in-house. For labs using QuPath + qTrace for diagnostic purposes, qTrace addresses the audit trail and traceability layer that supports the Article 5(5) health institution exemption (which explicitly requires ISO 15189 compliance) and the technical documentation, performance study conduct, and PMS data collection obligations.

✓ What qTrace covers

  • Art. 5(5)(b–c)Health institution exemption requires ISO 15189 compliance + QMS — qTrace is the audit trail layer that evidences both; directly enables lab eligibility
  • Art. 10(3)Performance evaluation (Annex XIII + PMPF) — .qtrace sessions capture the analysis workflow data that feeds performance evaluation records
  • Art. 10(4)Technical documentation (Annexes II–III) — software version, classifier SHA-256 hash, parameters, git history support the analysis-workflow component
  • Art. 10(7)Record retention ≥ 10 years — open JSON format + git local + Supabase off-site, no proprietary lock-in, no automatic expiry
  • Art. 10(8)QMS data layer — audit trail feeds performance evaluation, PMS, and corrective action records required by the QMS
  • Art. 68(3)Performance study data recording — ActionLogger captures study analysis data in real time, accurately, verifiably, with operator identity locked
  • Art. 73(5)Performance study report (Annex XIII §2.3.3) — batch export + MetaScript provide complete reproducible documentation of analysis methods
  • Art. 78Post-market surveillance data — accumulated .qtrace sessions form a real-world performance dataset for PMS reports and PSUR (Art. 80–81)

⬜ Remains with your laboratory

  • Art. 17–18EU Declaration of Conformity and CE marking — manufacturer obligations; not a software feature
  • Art. 24–26UDI assignment and Eudamed registration — manufacturer obligations
  • Art. 29Summary of Safety and Performance (class C/D devices) — document authored by the manufacturer
  • Art. 48Conformity assessment by Notified Body — third-party certification process
  • Art. 56Performance evaluation plan and clinical evidence generation — statistical analysis and regulatory authoring remain with the manufacturer
  • Art. 59Informed consent and subject personal data management — sponsor/lab obligation under GDPR

Formulation: “qTrace supports IVDR 2017/746 compliance for digital pathology analysis workflows in QuPath” — addressing Art. 5(5) health institution exemption, Art. 10 technical documentation, Art. 68(3) performance study data recording, and Art. 78 post-market surveillance data collection, scoped to the QuPath analysis workflow.

Sources

  • Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 · OJ L 117, 5.5.2017, CELEX:32017R0746 — official text read from docs/Normes/

ICH E6(R3) GCP

Mapped

ICH Harmonised Guideline E6(R3) — Good Clinical Practice · Step 4, 06 January 2025 · database.ich.org

ICH E6(R3) is the global standard for Good Clinical Practice in clinical trials. The R3 revision (January 2025) substantially strengthens requirements for data integrity, audit trails, and computerised systems governance (§4 Data Governance). qTrace addresses the audit trail and traceability layer for QuPath-based digital image analysis records in clinical trial settings — covering Principles 9.2–9.5, §3.16 Data and Records, and §4.2 Data Life Cycle Elements.

✓ What qTrace covers

  • Princ. 9.2–9.5Reliable results: systems fit for purpose (9.2), computerised systems GCP-aligned (9.3), record integrity and traceability (9.4), essential records retained and accessible for audit (9.5) — the core mission of qTrace for QuPath image analysis
  • §3.16.1(e)Documented processes for data integrity across the full data life cycle (see §4.2) — ActionLogger → .qtrace → GitBridge → Supabase chain covers capture, audit trail, corrections, retention, and access
  • §3.16.1(i–j)Changes to investigator data must be documented with justification; corrections supported by source records — append-only git prevents silent overwrites; Dashboard Card 7 attributes each correction to its operator with timestamp
  • §3.16.1(l)No exclusive control of data to prevent undetectable changes — git distributed architecture + Bitcoin Proof of Prior Existence make retroactive modification detectable independently of who controls the server
  • §3.16.3(a)Essential records retained per regulatory requirements — git local (permanent, no expiry) + Supabase off-site; open JSON format readable without qTrace in 15 years; no proprietary lock-in
  • §3.16.4(a)Direct access to source records for monitoring, audits, and regulatory inspection — batch ZIP export + Dashboard search + plain-text JSON readable without any software dependency
  • §4.2.1(b)Data directly captured in a computerised system accompanied by relevant metadata — .qtrace co-captures operator, timestamp, QuPath version, extension list, classifier SHA-256 hash, and all parameters alongside each workflow step
  • §4.2.2(a)(i–iii)Audit trail: user access logs (i), initial entry + all changes documented (ii), workflow actions recorded in addition to data changes (iii) — ActionLogger + append-only git satisfy all three sub-requirements
  • §4.2.2(b–d)Audit trails not disabled or modified; interpretable and support review; date-time unambiguous — git append-only is a structural guarantee, not a policy; ISO 8601 UTC timestamps throughout
  • §4.2.4Data corrections attributed to the correcting person, justified, supported by source records — Dashboard Card 7: correction operator (KYC-locked), timestamp, and original record all preserved in append-only history
  • §4.2.7Trial data and metadata archived for retrieval and readability, protected from alteration throughout retention period — git SHA-1 hashing + Supabase off-site + Bitcoin Proof of Prior Existence for validation stamps
  • §4.3.3(c–d)Adequate backup; procedures for backup and disaster recovery to prevent data loss — Cloud Workspace Push provides off-site Supabase backup; local git remains available without network access

⬜ Remains with your laboratory

  • §2.12Investigator source records for trial participants (medical records, case report forms, adverse event logs) — clinical participant records outside the QuPath analysis workflow
  • §4.1Blinding safeguards in data governance (randomisation codes, treatment unblinding procedures) — not applicable to pathological image analysis workflows
  • §4.3.2 / 4.3.4Personnel training on computerised systems + full system validation (IQ/OQ/PQ, CSV per GAMP 5) — laboratory and sponsor obligations; qTrace is the audit tool, not the validation subject
  • §3.16.2Statistical programming, analysis plan QC, and traceability of data transformations for final analysis — sponsor/biostatistician obligation
  • §3.13Safety assessment, adverse event reporting, and SUSAR pharmacovigilance — sponsor obligation
  • §1 / §2.8IRB/IEC submissions, ethical approvals, and informed consent procedures — institutional and sponsor/investigator obligations

Formulation: “qTrace supports ICH E6(R3) GCP compliance for digital image analysis records in clinical trials” — addressing §3.16.1 (data integrity), §3.16.3–4 (retention and access), §4.2.2 (audit trail), §4.2.4 (corrections), and §4.2.7 (retention protection), aligned with Principles 9.2–9.5. Scoped to the QuPath image analysis workflow; clinical source records, informed consent, safety reporting, and system validation remain with the investigator/sponsor.

Sources

  • ICH E6(R3) — Integrated Addendum to ICH E6(R1): Guideline for Good Clinical Practice · Step 4, adopted 06 January 2025 — database.ich.org

qTrace is a compliance tool, not a compliance programme

No single software product can make a laboratory fully compliant with any of these regulations. Compliance requires a combination of validated tools, qualified personnel, written procedures, and organisational governance. qTrace handles the data-integrity and audit-trail layer so your team can focus on the rest.