Phase 1 in development • TOTP MFA required for every sign-in

Enterprise Quality & Compliance Management System

Built toward SOC 2 Type II and ISO 27001 programs. Not certified yet.

Local invite enrollment, password policy, TOTP MFA, session idle/absolute limits, and server-side RBAC. Document registers and WORM evidence storage are not live yet.

What is live today

No production certification claims • Sign-in required for application data
MFA
TOTP
Required for every user
Idle session
15 min
Absolute limit 12 hours
Lockout
5 / 15
Failures, then 15 minutes
SSO / WORM
No
Not implemented

Target frameworks (not a certification claim)

AICPA SOC 2 Type II
ISO/IEC 27001:2022
GDPR & Privacy Frameworks
21 CFR Part 11 Electronic Records

Core Compliance Architecture

Roadmap capabilities. Only authentication and RBAC are implemented in this build.

Controlled Document Governance Planned

Planned document lifecycle (Draft → Review → Approved → Effective → Superseded), versioning, and PDF snapshots. Not available in this build.

SOC 2 Controls Library & Mapping Planned

Planned control-to-policy mapping and evidence gap views. The 104-control library is not seeded in this build.

Authentication audit log

Login success and failure, MFA failure, lockout, and TOTP re-enrollment are written to auth_audit_events. This is not WORM object-lock storage and has no hash chain.

Workforce Sign-offs & Training Planned

Planned acknowledgement campaigns and role-based training. Not available in this build.

Restricted Enterprise Compliance Gateway

Access uses local invite enrollment, password, and TOTP MFA. SSO (SAML/OIDC) is not implemented. Failed and successful sign-in events are stored in the authentication audit log.

• TOTP MFA• Session idle 15 min / absolute 12 h• Account lockout 5 / 15 min
P
P-Product eQMS• SDS-EQMS-001 v0.2

© 2026 P-Product Inc. All rights reserved.