Electronic Signature Software
Not every e-signature product is a Part 11 e-signature product. Consumer signature tools are optimised for convenience; Part 11 requires the opposite — re-authentication, meaning, reason, and non-repudiation. cGen's e-signature engine is built for controlled GxP records.
The user re-enters credentials on every signature event — not just at session start, and not "remember me for 24 hours."
Authored, Reviewed, Approved, Witnessed, Rejected — the meaning is explicit and travels with the printed record.
MFA on the signature event, not just the login. A stolen session cannot sign a controlled record.
21 CFR Part 11 §11.200 defines the requirements for electronic signatures based on biometrics and non-biometrics. In non-biometric practice — which covers ~99% of GxP e-signature use — the signature must consist of at least two distinct identification components (typically an identification code and a password), and the first signature in a continuous controlled session must use both while subsequent signatures in the same session may use only one.
On top of these baseline requirements, defensible e-signature practice today expects MFA on the signature event and a documented meaning attached to each signature. cGen implements both.
DocuSign, Adobe Sign, and their peers are excellent for consumer contracts and HR paperwork. They are not designed for GxP-controlled records. Specifically:
How cGen fits
cGen's e-signature engine sits inside the GxP record layer, not on top of it. Every signature is bound to a specific version of a specific controlled record, with a hash of the record content and the signature event captured in the same audit-trail entry. Rebinding is impossible without breaking the chain.
FAQ
We value your privacy
We use analytics cookies to understand how you use our site. No advertising or tracking cookies.