Pharmaceutical quality assurance (GMP/GDP)
SwiftQMS
SOPs drafted in your QMS's own voice, then handed to a person.

The document is the hero, and it arrives stamped DRAFT with open reviewer comments. The page sells the review, not the automation.
Project facts
- Problem
- Generic AI tools invent regulatory citations and imply a document is compliant before a qualified person has approved it.
- Approach
- An assistant that drafts policies, SOPs and work instructions from one company profile, citing only references our Responsible Person has verified.
- Result
- The first version covers the full drafting loop. The waitlist opened on 29 September 2026, so there are no usage numbers yet.
- Client
- Swift Ideas (own product)
- Where
- UK and EU
- Year
- 2026
- Status
- In development
- Work
- AI software, Web platforms
- Visit
- www.swiftqms.com
Our role
Built with
Next.js 16 (App Router), React 19, TypeScript, Tailwind CSS v4, Anthropic SDK (Claude Sonnet 4, streaming), Supabase (Postgres, RLS, Auth, Storage), docx, pdf-parse, mammoth, Zod, Resend, Vercel
The problem
Small and mid-size pharma, biotech and distribution businesses run quality systems with one or two QA people. Most of their time goes on writing and rewriting controlled documents: quality policies, SOPs and work instructions that must agree with each other and with the licences the site holds.
Generic AI writing tools are the wrong shape for this. They invent regulatory citations, they write in no company's voice, and they imply the output is compliant. In a regulated business that last point is the dangerous one: a document is only fit for use once a qualified person has reviewed and approved it.
Our co-founder is a practising Responsible Person (RP/RPi) with GMP Lead Auditor credentials. The brief from her was narrow: speed up the blank page, never speed past the reviewer, and never cite anything she has not verified.
What we did
Phase 1 was built in April 2026 as a single Next.js app on Supabase in the EU. A user registers an organisation, completes the company profile once, then asks for a Policy, SOP or Work Instruction in plain language. The draft appears on screen as Claude writes it, can be refined with follow-up requests in the same conversation, and downloads as an editable Word file.
Every request is assembled from three layers: a curated knowledge base maintained by the RP, the stored company profile, and the user's brief with any reference document. The model is told to cite only from the verified reference set and to mark every output as a draft for review.
In September 2026 we rebuilt the public landing page around that position. It shows a fictional SOP specimen with blank signature lines and reviewer comments, a system map of the three inputs and the review gate, and a plain list of what the product will never do. Access is by waitlist while the application is finished.
What we considered
The decisions behind the build, with the reasoning and the evidence for each.
StrategyAn assistant, never a signatory
The product is positioned against the one claim a regulated buyer cannot accept: that software made a document compliant. The copy, the prompt and the output format all repeat the same limit, so the accountability stays with the named person.
- System prompt: 'You produce DRAFTS only' and 'Never claim that a document is compliance-ready, validated, or approved'
- Every generated header carries Version 'Draft v1' and Classification 'DRAFT — For Review Only'
- The generated document view carries a yellow DRAFT banner above the content
- Landing page lists four things SwiftQMS never does: claim compliance, approve or release a document, replace the RP, QP or QA reviewer, cite outside its reference set
AICitations from a closed, verified set
Invented citations are the fastest way to lose a QA team's trust, so the model never cites from memory. The RP-maintained reference file is loaded into the system prompt on every request, and the prompt forbids references outside it.
- src/regulatory-knowledge/references.md: 26 coded references across 7 families
- Families: EudraLex Vol. 4 Chapters 1 to 9, Annexes 11, 15 and 16, ICH Q7, Q9 and Q10, MHRA guidance, EU GDP 2013, FDA 21 CFR, ISO standards
- References are matched to the frameworks the company declared, so an EU-only site is not cited FDA rules
- Output structures are fixed per type: an SOP has nine sections from header block to revision log
- Uploaded reference text is capped at 10,000 characters before it enters the prompt
DataTell it about the operation once
Company context is what makes a draft sound like a real QMS rather than a template. It is captured in one structured questionnaire and injected into every later request, so nobody retypes their licences or numbering convention.
- 18 questions in 4 sections: Organisation Identity, Regulatory Framework, Products and Operations, QMS Maturity
- Autosave on a 500 ms debounce, with progress shown as 'Section X of 4' and a percentage
- Up to 3 supporting files of 10 MB each, PDF or DOCX, with text extracted by pdf-parse and mammoth
- The form warns users not to upload batch numbers, patient data, personnel records or formulation data
SecurityEach company's documents walled off, with EU hosting by default
Quality documents describe how a licensed site operates, so the database itself stops one organisation seeing another's, not just the application code. The organisation ID lives in the signed JWT and every RLS policy reads it from there.
- org_id stored in Supabase app_metadata at registration, checked by RLS via auth.jwt()
- RLS enabled on all 9 tables, from organisations to generation_requests
- Supabase project in eu-west-1 (Ireland), app on Vercel
- Designed for Anthropic's Zero Data Retention configuration, a Phase 1 requirement in the spec
- Uploads go to a private, organisation-scoped storage bucket
InfrastructureA daily limit that refuses when in doubt
Drafting is the only expensive action, so each organisation's daily count is checked before a draft starts. If the usage count cannot be read, the request is refused rather than allowed through unmetered.
- 50 generations per organisation per day, counted from generation_requests
- A failed count query returns 'Unable to verify generation limit' instead of generating
- Every request records a prompt hash, token count and model for the admin analytics view
- Drafts stream to the browser through the Anthropic streaming API, then save with version history
ShowHide the other 3 decisions
DesignNight sky for the product, paper for the document
The landing page separates two materials. The product lives in a deep navy space with violet light; the documents it produces sit on warm paper with serif headings and monospaced document numbers, because that is what a controlled document looks like on a QA desk.
- Background #080a18 with primary violet #6e50ff and accent #8f7cff
- Paper #f5f2ea, rail #ebe7dc, rule #d6d0c0 and ink #16182e for every document specimen
- Refusals use a separate soft red #ff8f9c so 'never will' reads differently from 'does'
- The hero specimen is captioned as illustrative: the company and procedure are fictional
MotionScroll animation, with a complete still version for anyone who turns motion off
The page uses slowly shifting stars, a drifting review orbit, a scrolling strip of regulatory frameworks and sections that appear in stages. Each has a reduced-motion branch that leaves the content complete and static rather than half-revealed.
- prefers-reduced-motion checked in CSS and in 4 components: parallax, review orbit, waitlist stage and the reveal observer
- The 48-second frameworks marquee pauses on hover and becomes a wrapped, centred list under reduced motion
- Smooth scrolling is switched off under reduced motion; scroll-padding-top of 5rem keeps anchors clear of the nav
- Focus rings are a 2 px #c7c3ff outline with a 3 px offset on the dark ground
SearchGuides that cannot publish with an open question
Regulatory content written by a developer and not checked by the RP is a liability. Guides are written as typed content with a status, render only on preview deployments while in draft, and the build throws if a guide marked published is not ready.
- 3 guides drafted: SOP versus work instruction, temperature excursion SOP, document control under EU GMP Chapter 4
- assertPublishable() fails the build on a missing author, an empty section, or a '[TO CONFIRM: ...]' placeholder
- The sitemap lists published guides and legal pages only
- JSON-LD graph with Organization and SoftwareApplication; IndexNow key file in place
Colour and type
- Deep space#080A18Page background and theme colour
- Card#101331Panels, inputs and the system map
- Violet#6E50FFPrimary actions and the SwiftQMS mark
- Lilac#8F7CFFAccent, focus ring base and selection
- Muted#A4A7C8Secondary text on dark
- Paper#F5F2EADocument specimens and the hierarchy section
- Ink#16182EText on paper
- Refusal#FF8F9CThe 'never will' column marks
Temperature excursion management in transit
Loaded in normal and italic. The italic carries the one emphasised word in the hero ('your'), so the serif does the persuading without a second colour.
Eighteen questions in four sections capture your licences.
A neutral grotesque for everything the user operates, kept apart from the serif that marks a document.
SOP-QA-014 · rev 0.1 · EU-GDP-2013
Document control reads as data, as it does in a real QMS register.
The build, screen by screen








By the numbers
- profile questions, answered once
- 18
- Source: The product specification, and counted in the built questionnaire
- verified regulatory references the model may cite
- 26
- Source: Counted in the reference list our Responsible Person maintains
- drafts per organisation per day, refused if usage cannot be checked
- 50
- Source: The limit set in the product's code
- guides held back until the RP signs them off
- 3
- Source: Counted in the product's content. All three are still marked draft
Where it landed
The Phase 1 application covers the full loop in the spec: registration, the 18-question profile, live drafting of all three document types, follow-up refinement, Word (.docx) export and a per-organisation library. The public landing page and waitlist went live on 29 September 2026.
SwiftQMS is not open to users yet, so there are no usage numbers to report. The next steps are confirming at account level that Anthropic keeps no data (its Zero Data Retention arrangement), having the RP sign off the first guides, and opening access to the waitlist in small groups.
The pattern carries to any regulated drafting problem: a closed knowledge base owned by a qualified person, context captured once, drafts that appear as they are written, and a product that is explicit about the decision it will not make.