Our services for GxP software development
GxP software requires more than a strong interface. Our software engineers work directly with CSV specialists and your QA, IT and process teams. Requirements, risk-based design, data integrity, testing and operational handover form one shared Software Development Life Cycle (SDLC).
Reference: Access to web app in 270 hours – including validation evidence. Read the case story
AI supports our work when structuring specifications, drafting test cases, maintaining traceability and preparing documentation. It accelerates expert work, but it does not replace validation judgement or approved release decisions. Unvalidated AI tools do not make GxP decisions and are not introduced without control into critical decision paths.
Software with GxP in the design
Audit trails, roles, electronic signatures, data integrity and maintainable interfaces are derived from process risks instead of being added later.
Evidence built alongside the code
URS, specifications, risk analysis, tests, the traceability matrix and the validation report grow with the application under change control.
Established Excel or Access logic does not have to be discarded. We analyse rules, data and user journeys, then transfer suitable processes into a validatable web application. The Access to web app case story shows a delivered project. If Excel remains the appropriate solution, we also support spreadsheet validation.
Project pathfinder
Which next step fits your process?
Choose your starting point to reveal a focused recommendation and relevant detail pages.
Control before replacement
Assess criticality, formulas, access, versioning and frequency of change first. A validated spreadsheet can be appropriate while its scope and operation remain manageable.
Preserve the logic, reorganise the application
We retain business rules and the data model, separate legacy constraints from needed functions, and plan the web application and validation evidence together.
From process to product with risk in focus
We start with the user task, GxP risk, data flows and acceptance criteria. These inputs shape the architecture, software development plan and proportionate validation strategy.
Software development and validation in one lifecycle
In many projects software development delivers a release and CSV starts weeks later with empty protocols.
Specification, code, testing and release run in one SDLC with us, so every change has evidence immediately.
Testable URS, not a wish list
- URS with unambiguous acceptance criteria
- Requirements review with QA and subject matter experts
- Traceability IDs for every requirement
GxP controls built into the design
- Part 11 relevant controls in the design document
- Role model, audit trail, data integrity
- Technology stack chosen for maintenance and re-validation
Every change leaves a trail
- Documented SDLC aligned with GAMP 5
- Code review, unit and integration tests in CI
- Change control before merge: impact, approval, re-test
IQ, OQ and UAT with protocols
- Test protocols and reports per qualification phase
- System and performance tests where risk-based
- UAT with documented sign-off
Evidence grows with the build
- Validation plan, FS, risk analysis
- Test protocols and validation summary report
- Traceability matrix as a deliverable
Smooth production release
- User training and training records
- Operating and maintenance documentation
- Optional: validation manager through the lifecycle
Retrospective CSV
- Traceability reconstructed later
- Test gaps just before the audit
- Reactive change control
Parallel to the build
- Traceability IDs from sprint 1
- IQ/OQ during software development
- Every merge with impact assessment
Need clarity on your validation strategy?
Book an initial callOur Technology Expertise
What custom software development delivers
SDLC in GxP Context
The Software Development Life Cycle (SDLC) connects planning, software development, verification, operation and retirement. GAMP 5 provides risk-based guidance for this work. Depending on the system and validation strategy, deliverables include the URS, functional and technical specifications, risk analysis, implementation, tests, release and lifecycle documentation. Annex 11, Part 11 and data integrity controls are applied to the actual process and intended use.
cube one maps specification and test levels so that the relationship remains demonstrable. Agile software development is possible when documentation, reviews, change control, approvals and traceability remain controlled in every sprint.
FAQ: GxP Software Development
Regulatory background: PIC/S and GxP software
What it is: The Pharmaceutical Inspection Co-operation Scheme (PIC/S) is the cooperation of GMP inspectorates, meaning regulatory authorities, with its secretariat in Geneva. Only authorities are members; companies cannot join.
Where it comes from: In 1970 the EFTA states concluded the Pharmaceutical Inspection Convention (PIC) for mutual recognition of inspections. Because accession to the Convention was legally rigid, the more flexible Scheme was added in 1995. When people in GxP contexts say PIC/S today, they almost always mean this Scheme. The PIC/S GMP Guide is closely aligned with the EU GMP guidelines (EudraLex Volume 4).
Why it matters here: We build and validate software that runs in GMP environments, and those environments are the ones these inspectorates inspect. PIC/S participation carries harmonised authority expectations with it, including for computerised systems and data integrity. A German site supplying into a PIC/S participating country, or inspected there, therefore meets a shared inspection language rather than an in-house cube one standard. PIC/S is not a certification held by cube one.
cube one in-house developments
Purpose-built applications, each with its own symbol, from data migration and monitoring to pharmacovigilance and change control.
STREAM
SHA-256 hashed, audit-trailed migration of regulated data between laboratory systems.
In-house buildRADAR
GxP-aware monitoring of processes and infrastructure with actionable alerts.
In-house buildShiftconnector converter
Custom converter that maps shift-log data into the customer handover workflow.
In-house buildSoloVPE Report Mover
Automated, traceable movement of SoloVPE reports into the controlled repository.
In-house buildAuto Backup
Scheduled backup utility for laboratory PCs that cannot run a full backup suite.
In-house buildPUDEL
Purpose-built laboratory utility for controlled data handling in QC.
In-house buildPVA MEDPV
Category-5 application supporting pharmacovigilance documentation workflows.
In-house buildPVA Animal Health
Sibling Category-5 build for animal-health pharmacovigilance processes.
In-house buildSAM
Service-order-management tool: migration of an MS Access database onto a SQL Server.
In-house buildRMS
Reagent Management System: moving the data of an MS Excel spreadsheet onto a SQL Server.
In-house buildResource management tool
Internal application for managing resources and staff in GxP projects.
In-house buildAudit Dashboard
Dashboard that surfaces audit-trail and qualification status for inspection teams.
In-house buildChange Request Management
Category-5 change-request application with complete traceability of approvals.
In-house buildLicence server
In-house licence server for laboratory software that must not float unmanaged.
In-house buildSoluM AIMS
Data Handling Center that unifies several APIs and pushes information to eLabels.
In-house buildExcel overview Power App
Power App that replaces an uncontrolled Excel overview with an auditable surface.
In-house buildPower Automate
Documented Power Automate flows that move GxP records without silent side effects.
No matching system.
From custom software to the catalogue
Category 5 solutions that have proven themselves in GxP operations are presented on cube hub as standalone, detailed entries – each tool and software package with its use case, scope and deployment context. Prospective users can quickly see what fits their process and where they can adopt it. Customisation remains available at any time: at cube one, software is bespoke, even when the starting point is the catalogue.
Software development reference projects
Migrations, integrations and custom builds that stay in routine GxP use.
Software development
Access to web app
Legacy MS Access front end rebuilt as a multi-user web app with significantly reduced effort.
View case story
Software development
SoftMax Pro ↔ LabWare
Automated QC results from SoftMax Pro V7.2 and analysers into LabWare LIMS V8.
View case story
Software development
Resource planner
Server app with browser UI for staff hours, project allocation and tailored user management.
View case story