Regulated & compliance software
Software for work that gets inspected.
We build document, training and compliance tools for pharma QA and GxP teams, where the output has to stand up to an auditor. Our co-founder is a practising Responsible Person with GMP Lead Auditor credentials, so the workflows start from how inspections actually run. The software drafts, checks and records; a qualified person decides.
What clients arrive with
- Writing and revising SOPs takes our QA team weeks per document.
- General AI tools invent regulation references we then have to check by hand.
- We need proof of who was trained on what, when, and whether they passed.
- Our data has to stay in the UK or EU.
- We want help from software without it pretending to be the qualified person.
What you get
- Document drafting grounded in verified references
- Policies, SOPs and work instructions drafted from a structured company profile and a curated reference set: EudraLex Volume 4, its Annexes 11, 15 and 16, ICH Q7, Q9 and Q10, MHRA and EU GDP guidance, 21 CFR 210 and 211, and ISO 9001. Output is an editable Word document, marked as a draft for qualified review.
- Training with completion evidence
- Course catalogues, video modules, quizzes with an 80% pass gate before the next module, certificates and an audit log, with Stripe Checkout for paid courses and managed enrolment for organisations.
- Deterministic compliance checks
- Rules that must always hold are written in code and tested, not left to a prompt. SwiftQMS refuses to generate when it cannot verify the daily limit, and never calls a document compliance-ready.
- Audit trails
- Logged events for enrolment, completion, quiz attempts, certificate issue, publication and resource downloads, exportable for an auditor. Training evidence is soft-deleted, so a removal never destroys the record.
- Data residency and retention
- UK or EU hosting for the database, storage and application, Anthropic's Zero Data Retention configuration for model calls, and organisation-scoped access enforced with row-level security.
- Documentation for your quality team
- Specifications, test evidence and a change record your QA function can use in its own computerised-system assessment.
How the work runs
Frame the regulation
Which regulations apply, who the qualified person is, and exactly what the software is allowed to state. These limits are written down before design starts.
Assemble the corpus and the rules
We assemble the reference set the AI may cite and encode the checks that must be deterministic, with a qualified reviewer signing off both.
Build with evidence
Every feature ships with tests, an audit trail entry and a line in the change record, so the evidence exists before anyone asks for it.
Qualified review and release
A subject-matter review of real outputs, then release with the disclaimers, access controls and data-handling settings confirmed.
How engagements start
- Discovery with a subject-matter review: regulations, users, data and the limits of what the software may say.
- Prototype to production in 4–8 weeks for a focused first module, such as drafting or training.
- Retained iteration as regulations and your procedures change.
Built with
Where each number comes from
Each figure names where it comes from.
- verified regulatory references SwiftQMS is permitted to cite
- 26
- Source: SwiftQMS: counted in the reference list our Responsible Person maintains
- quiz pass mark before a SwiftGxP learner can open the next module
- 80%
- Source: SwiftGxP: the pass mark set in the training platform's code
- guides held back until the RP signs them off
- 3
- Source: SwiftQMS: counted in the product's content. All three are still marked draft
The work behind it
Questions, answered
Something else on your mind? hello@swiftideas.com
Is the software GxP-validated?
Validation is your quality function's decision about your intended use, so we do not claim it for you. We build to support it: specifications, test evidence, audit trails, access controls and a change record your team can assess.
Can AI write our SOPs?
It can draft them. Drafts are built from your company profile and a verified set of references, and every output is marked as a draft for review by a qualified person before it enters your document system.
Where is our data held, and does the model provider keep it?
We host in the UK or EU and configure Anthropic's Zero Data Retention, under which inputs and outputs are not stored by the provider. Access is scoped to your organisation in the database.
Do you understand GMP, or just software?
Both. Our co-founder is a practising Responsible Person with GMP Lead Auditor credentials and designs the regulated workflows; the other founder engineers them.
Will the software replace our qualified person?
No. It drafts, checks and packages evidence for review by a qualified person. SwiftQMS leaves the reviewer and approver fields blank on purpose, and never fills a signature.

