Enterprise Security and SSO — Part 11 Controls on Azure


Security

Security your IT and quality teams can review

Single sign-on with your identity provider, access denied by default and granted per role and per dossier, each customer’s data in its own database, and a Part 11 audit trail — hosted on SOC 2 Type II certified Microsoft Azure infrastructure.

Access
Why can this user see this dossier?
Decided by the system on every request
Sign-inMicrosoft Entra ID single sign-on
Verified
RoleRegulatory Publisher
Granted
Dossier accessGranted through group membership
Granted
Another customer’s dataSeparate database
Unreachable
No access unless it has been granted.
The problem

Security reviews ask the same questions — have the answers ready

Where is our data, who else is on the system, how do people sign in, who can see what, and what is recorded? A regulatory platform should answer those clearly and in the product, not in a slide.

DnXT is built so the answers are short.

Who it is for

Built for the people who own the outcome

IT and security

Integrate sign-in with your identity provider and review how access is enforced.

Quality and validation

Verify Part 11 controls in the system with your configuration.

Regulatory leadership

Give partners and auditors access to exactly what they need.

Capabilities

Controls

Single sign-on

Microsoft Entra ID and Okta; LDAP where needed.

Access denied by default

Roles grant features; access to each dossier is granted separately, including through group rules.

Separate customer data

Each customer’s data is held in its own database.

Part 11 audit trail

Who did what and when, recorded for actions across the products.

Electronic signatures

Signatures record the signer, time and meaning, for internal and external signers.

Hosting

Hosted on SOC 2 Type II certified Microsoft Azure infrastructure; sessions time out and traffic is encrypted.

Design decisions

Principles

Deny by default

No access without a grant — including for administrators.

Decided by the system

Access is enforced on every request, not by the screen a user happens to see.

One customer, one database

Separation is structural, not a filter.

Evidence in the product

Audit trail and signatures can be shown to an inspector directly.

Questions

Frequently asked

Does DnXT hold its own SOC 2 report?

DnXT is hosted on SOC 2 Type II certified Microsoft Azure infrastructure.

Which identity providers are supported?

Microsoft Entra ID and Okta for single sign-on, and LDAP.

Bring your security questionnaire

We will walk your IT and quality teams through the controls in the product.