Features
Large QMS platforms offer these controls at enterprise prices. Hemeralis offers the same controls, and a company without a validation team can set them up.
Tamper-evident audit trail
Every change records who, what, when, before and after. Each entry is cryptographically chained to the one before it, and the chain can be checked at any time.
The audit trail cannot be edited
The database account the software uses has no permission to change or delete an entry. The database enforces this, not the software.
Electronic signatures
The signer types their password again, and that second login is the second factor. The name, the meaning they accepted and the license they held are all recorded at that moment.
One signature, one action
A signature is created for one action on one record and used up by it. It cannot be reused, and a second attempt is refused.
The compliance export
One click produces the full regulatory copy of a record: the record, its complete audit trail, its signatures with their meanings, and a list of every attached file.
Printed records
Any record prints as a formal document: identified, attributed, and stating the time zone it was printed in, because 14:32 on its own does not identify a moment.
Nothing is ever deleted
No license level can delete a record, not even the system administrator, and the software contains no code that could.
Signing an approval
The signer chooses the meaning, then types their password again. The meaning they accepted, their name and the license they held are recorded at that moment and cannot be changed afterwards.
The audit trail
Each entry names the person, the action, the status before and after, and the approval it belongs to. Entries are chained to one another and cannot be edited.
Segregation of duties
The person who creates a record is not shown the button that approves it. One person cannot complete a quality event alone.
Who may perform each action
Each action names the person who may perform it: the assignee, the QA approver, the record owner. Everyone else does not see the button, and the server refuses them if they try.
Fields lock by status
A record under review is frozen: its wording, its dates, its severity. Which fields lock in which status is a setting, not something built into the software.
One person keeps one field
On a frozen record, the one person the workflow is waiting for keeps exactly the field they are asked for, and nobody else does. A record that nobody can change could never move forward.
Parallel approvals
A change plan can name as many approvers as it needs, each one required or optional, and they sign in parallel. Quality is shown nothing until the group has finished, and signs last.
The workflow shown on the record
Every record shows its own steps and where it currently stands, next to the actions available to the person looking at it.
Linked records are controlled
Which linked records may be created, and in which status, is checked on the server. A record cannot be closed while a linked record it depends on is still open.
Due dates move only by request
Once a due date is locked it can move in one way only: a request that is justified, approved and signed by somebody else. Nobody edits a date directly.
Every rejection states a reason
A rejection or a cancellation requires a signature and a written reason, and the record returns to a status where the mistake can actually be corrected.
Approvals in order
Two people are asked at the same time, one required and one optional. Quality is the second step and is shown nothing until the first one finishes.
Where the record stands
Every record shows its own steps and the point it has reached. The action beside it is the one this person may perform; somebody else sees a different set, or none.
In most quality systems every line below is a change request to the supplier, a quotation and a wait. In Hemeralis your own administrator changes them, and every change is recorded with who made it and when.
The forms
Which fields appear, in what order, and on which of the screen, the printed record and the export.
What is mandatory, and when
Which fields must be filled to create a record, and which must be filled at each approval.
Locked statuses
Which fields freeze in which status, and which single person keeps an exception to that.
The workflow itself
Every status, every action, every button, who may press it, and which linked records a status allows.
Controlled vocabularies
Every list and its values, including lists where one answer narrows the choices in the next.
The wording, in every language
Every label and every help text. If you want a field to read “CAPA Responsible” instead of “Owner”, you change it yourself.
Rules between fields
An end date after a start date. A check date that is not in the future. A requested date later than the one it replaces.
Default values
What a new record is filled in with before anybody types, including dates counted from the day it is created.
Versioned settings
Change a rule today and yesterday’s records keep the rule they were created under, which is what an auditor comparing a record with your procedure needs to see.
Five levels of access control
License level, functional role, involvement in the record, workflow status, and the named person. All five are settings in your own database.
Only the people involved
Only the person who created a record, the person it is assigned to, and its named approver may edit it. An administrator has no general right to edit records.
The Light User license
For the people a quality system depends on but who do not run it: the supervisor answering a finding, the engineer completing an action. They can be given a record and sign for it, and cannot create one.
Functional roles
Only somebody with the Auditor role may create an audit or be named on one. Every time a role is given or taken away it is written to your audit trail, so an access review can be answered from the system.
Record reassignment
When somebody leaves, an administrator moves their open records in one recorded action. Nothing is left stuck, and the original author never changes.
A real account for each person
Sign-in runs on Amazon Cognito: no shared accounts, one central password policy, and every license belongs to somebody who can actually sign.
Every file gets a checksum
Files are checksummed when they arrive and stored unchanged. The software cannot alter a stored file’s name, checksum or size, and cannot delete one.
Files cannot be removed after approval
Once a record is approved, its files are part of what was approved. A file that was taken off earlier stays in the list, marked, with who removed it and why.
37 file formats, including drawings
STEP, IGES, DWG, DXF and STL alongside the usual office formats. A quality system should store a drawing as it is, not refuse it for not being a PDF.
A list of every attached file
The compliance export lists every file with its full checksum, so an inspector can compare the export with a copy of the file and see that the two match.
Documents are read on screen
A controlled document opens in the browser. No download, no plugin, no viewer to install. The copy a person reads is the copy the system holds, and it is always the version in force.
The version approved is the version read
The PDF an approver saw is stored as approved and never generated again. What a reader opens months later is that same file, not a fresh conversion of the source that nobody checked.
A notification center
The notification center tells the right person as soon as a record needs them: assigned to them, waiting for their decision, returned for correction, or coming due.
My open records
One screen covering every kind of record and every way a person can be involved: assigned to them, created by them, or waiting for their approval.
A diagram of every process you run
An administration screen draws each of your workflows from the settings that are actually in use, so what you show an auditor is what the system applies.
Five languages throughout
English, Spanish, German, French and Dutch across the screens, the workflow buttons, the list values, the meaning of each signature and the printed documents.
A separate database for each customer
Your data sits in its own database area, identified from your signed sign-in on every request. There is no part of the software that reads across customers.
Nothing to install
Hosted in Frankfurt. No servers to buy, no IT department needed, and updates and migrations are ours to run.
The same dialog, in German
Not only the buttons. The meaning the signer accepts is translated too, which is the part that becomes the legal record.
And in French
The same record, the same approval, the same meaning — in the language the person signing actually reads.
Send us your question.