Services

Software development specialized for regulated environments

cube one combines AI-assisted software development and Computer System Validation from a single source. For regulated processes in pharma, chemicals, biotech, medical technology and other GxP environments, we deliver custom applications whose requirements, code, tests and approvals fit together from the start.

Our services for GxP software development

GxP software requires more than a strong interface. Our software engineers work directly with CSV specialists and your QA, IT and process teams. Requirements, risk-based design, data integrity, testing and operational handover form one shared Software Development Life Cycle (SDLC).

Reference: Access to web app in 270 hours – including validation evidence. Read the case story

AI supports our work when structuring specifications, drafting test cases, maintaining traceability and preparing documentation. It accelerates expert work, but it does not replace validation judgement or approved release decisions. Unvalidated AI tools do not make GxP decisions and are not introduced without control into critical decision paths.

Engineering

Software with GxP in the design

Audit trails, roles, electronic signatures, data integrity and maintainable interfaces are derived from process risks instead of being added later.

Validation

Evidence built alongside the code

URS, specifications, risk analysis, tests, the traceability matrix and the validation report grow with the application under change control.

Established Excel or Access logic does not have to be discarded. We analyse rules, data and user journeys, then transfer suitable processes into a validatable web application. The Access to web app case story shows a delivered project. If Excel remains the appropriate solution, we also support spreadsheet validation.

Project pathfinder

Which next step fits your process?

Choose your starting point to reveal a focused recommendation and relevant detail pages.

From process to product with risk in focus

We start with the user task, GxP risk, data flows and acceptance criteria. These inputs shape the architecture, software development plan and proportionate validation strategy.

Software development and validation in one lifecycle

In many projects software development delivers a release and CSV starts weeks later with empty protocols.

Specification, code, testing and release run in one SDLC with us, so every change has evidence immediately.

Phase 1 · Requirements

Testable URS, not a wish list

  • URS with unambiguous acceptance criteria
  • Requirements review with QA and subject matter experts
  • Traceability IDs for every requirement
Phase 2 · Design

GxP controls built into the design

  • Part 11 relevant controls in the design document
  • Role model, audit trail, data integrity
  • Technology stack chosen for maintenance and re-validation
Phase 3 · Software development

Every change leaves a trail

  • Documented SDLC aligned with GAMP 5
  • Code review, unit and integration tests in CI
  • Change control before merge: impact, approval, re-test
Phase 4 · Verification

IQ, OQ and UAT with protocols

  • Test protocols and reports per qualification phase
  • System and performance tests where risk-based
  • UAT with documented sign-off
Phase 5 · Validation file

Evidence grows with the build

  • Validation plan, FS, risk analysis
  • Test protocols and validation summary report
  • Traceability matrix as a deliverable
Phase 6 · Operations

Smooth production release

  • User training and training records
  • Operating and maintenance documentation
  • Optional: validation manager through the lifecycle

Retrospective CSV

  • Traceability reconstructed later
  • Test gaps just before the audit
  • Reactive change control

Parallel to the build

  • Traceability IDs from sprint 1
  • IQ/OQ during software development
  • Every merge with impact assessment

Need clarity on your validation strategy?

Book an initial call

Our Technology Expertise

Web applications
Python, JavaScript/TypeScript and REST APIs for validatable browser apps.
Desktop applications
Windows clients for laboratory PCs and isolated operating environments.
Database solutions
SQL Server, PostgreSQL and SQLite with GxP-ready structure and access control.
System integrations
Laboratory instruments, LIMS, MES and ERP through documented interfaces.
Reporting and analytics
Dashboards and evaluations with traceable data lineage.
Workflow automation
Process chains with approvals, roles and audit trail in the design.
Complex Excel development
Multi-sheet workbooks, formulas, macros and interfaces – structured, versioned and documented for validation.
Access databases
Development, migration and modernisation of established MS Access applications in GxP environments.
VBA development
Automation, form logic and Office integration with controlled change documentation.
AI-supported IDE usage
Modern development environments such as Cursor in daily work – used under clear rules, versioned and with traceable code provenance for GxP projects.

What custom software development delivers

Risk-based evidence
Part 11, Annex 11, GAMP 5 and PIC/S expectations mapped in scope.
Traceability matrix
From the URS through design and code to test cases, handed over as a matrix.
Roles and audit trail
User management and traceability built into the design, not added later.
No licence overhead
Functions for your processes only, without COTS modules you never use.
Operations and evolution
Handover with operating docs; further development under change control.

SDLC in GxP Context

The Software Development Life Cycle (SDLC) connects planning, software development, verification, operation and retirement. GAMP 5 provides risk-based guidance for this work. Depending on the system and validation strategy, deliverables include the URS, functional and technical specifications, risk analysis, implementation, tests, release and lifecycle documentation. Annex 11, Part 11 and data integrity controls are applied to the actual process and intended use.

cube one maps specification and test levels so that the relationship remains demonstrable. Agile software development is possible when documentation, reviews, change control, approvals and traceability remain controlled in every sprint.


FAQ: GxP Software Development

How does cube one use AI in GxP software projects?
AI assists with specification drafts, test case ideas, traceability and documentation. Experts review the output and make every quality-relevant decision. Unvalidated AI tools replace neither risk assessment, validation judgement nor release approval.
What is the Software Development Lifecycle (SDLC) in GxP?
The GxP SDLC is a structured process covering all phases of software development: requirements definition, design, coding, testing, deployment, operation, and retirement. Each phase must be documented, reviewed, and approved. This ensures that software is developed systematically and that the validation evidence is complete and traceable.
How long does a GxP software development project typically take?
Duration depends heavily on the complexity of the requirements. Simple utility tools might take 2 to 3 months from requirements to validated delivery. Complex enterprise applications integrating multiple systems typically take 6 to 18 months. We provide detailed project plans with milestones from the outset.
Can cube one maintain and enhance software it has developed after go-live?
Yes. We offer long-term support and enhancement contracts that include change control management, impact assessments, re-validation when required, and ongoing technical support. Continuity of knowledge is a key advantage of working with the original software development team.
Regulatory background: PIC/S and GxP software

What it is: The Pharmaceutical Inspection Co-operation Scheme (PIC/S) is the cooperation of GMP inspectorates, meaning regulatory authorities, with its secretariat in Geneva. Only authorities are members; companies cannot join.

Where it comes from: In 1970 the EFTA states concluded the Pharmaceutical Inspection Convention (PIC) for mutual recognition of inspections. Because accession to the Convention was legally rigid, the more flexible Scheme was added in 1995. When people in GxP contexts say PIC/S today, they almost always mean this Scheme. The PIC/S GMP Guide is closely aligned with the EU GMP guidelines (EudraLex Volume 4).

Why it matters here: We build and validate software that runs in GMP environments, and those environments are the ones these inspectorates inspect. PIC/S participation carries harmonised authority expectations with it, including for computerised systems and data integrity. A German site supplying into a PIC/S participating country, or inspected there, therefore meets a shared inspection language rather than an in-house cube one standard. PIC/S is not a certification held by cube one.

cube one in-house developments

Purpose-built applications, each with its own symbol, from data migration and monitoring to pharmacovigilance and change control.

In-house build

STREAM

GxP data migration

SHA-256 hashed, audit-trailed migration of regulated data between laboratory systems.

In-house build

RADAR

System monitoring

GxP-aware monitoring of processes and infrastructure with actionable alerts.

In-house build

Shiftconnector converter

Shift handover

Custom converter that maps shift-log data into the customer handover workflow.

In-house build

SoloVPE Report Mover

Spectroscopy reports

Automated, traceable movement of SoloVPE reports into the controlled repository.

In-house build

Auto Backup

Instrument PCs

Scheduled backup utility for laboratory PCs that cannot run a full backup suite.

In-house build

PUDEL

Lab data utility

Purpose-built laboratory utility for controlled data handling in QC.

In-house build

PVA MEDPV

Pharmacovigilance

Category-5 application supporting pharmacovigilance documentation workflows.

In-house build

PVA Animal Health

Veterinary PV

Sibling Category-5 build for animal-health pharmacovigilance processes.

In-house build

SAM

Service order management

Service-order-management tool: migration of an MS Access database onto a SQL Server.

In-house build

RMS

Reagent Management System

Reagent Management System: moving the data of an MS Excel spreadsheet onto a SQL Server.

In-house build

Resource management tool

Staff / capacity

Internal application for managing resources and staff in GxP projects.

In-house build

Audit Dashboard

Inspection view

Dashboard that surfaces audit-trail and qualification status for inspection teams.

In-house build

Change Request Management

Controlled change

Category-5 change-request application with complete traceability of approvals.

In-house build

Licence server

Controlled licensing

In-house licence server for laboratory software that must not float unmanaged.

In-house build

SoluM AIMS

Data Handling Center

Data Handling Center that unifies several APIs and pushes information to eLabels.

In-house build

Excel overview Power App

Power Platform

Power App that replaces an uncontrolled Excel overview with an auditable surface.

In-house build

Power Automate

GxP-aware flows

Documented Power Automate flows that move GxP records without silent side effects.

Two cube hub consultants working enthusiastically at two monitors showing the cube hub logo

From custom software to the catalogue

Category 5 solutions that have proven themselves in GxP operations are presented on cube hub as standalone, detailed entries – each tool and software package with its use case, scope and deployment context. Prospective users can quickly see what fits their process and where they can adopt it. Customisation remains available at any time: at cube one, software is bespoke, even when the starting point is the catalogue.

Ready to develop your GxP software solution?

Let our experts advise you. We have 14 years of experience in GxP Life Science software development.