Every module, no slice

A complete quality system, not a feature list.

Reeve ships with the modules a regulated manufacturer needs out of the box - and the compliance plumbing wired through every one of them. Here's the full inventory.

Document control & change

Controlled documents, change orders, and a standards library map directly to your quality manual's procedural backbone.

Controlled documents / SOPs

Versioning, distribution, acknowledgement tracking, and e-signed approval. Renderable forms, paper-friendly templates, and write-once (WORM) retention on approved revisions.

Document types & auto-numbering

Document types with module-level numbering. SOP-0042, NC-0118, CAPA-0073 - consistent identifiers across modules.

Change orders (DCOs)

Significance consideration, justified approval, and propagation of approved versions into the distribution list. Bumps tracked at minor or major granularity.

Standards library

Track ISO, FDA, and EU MDR clauses; link audit findings, SOPs, and risk controls to the standards they implement.

Quality events

The day-to-day of a quality system: deviations, dispositions, root cause, corrective action, and audit findings - all with e-signed transitions.

CAPAs

Root-cause analysis, corrective and preventive actions with owners and due dates, effectiveness verification, and an e-signed close.

Non-conformances

Containment, investigation, and disposition with linked supplier or production source. Spawns CAPAs and SCAR responses with a single click.

Material Review Board

MRB workflow for disposition of non-conforming material - reject, rework, use-as-is, or scrap, with required signatures on the path you pick.

Internal & supplier audits

Audit plans, checklists tied to the standards library, findings classification (major / minor / observation), and sign-off with reviewer e-signatures.

Customer feedback & vigilance

Public eIFU forms for problem reports, vigilance (MDR Art. 87 / 21 CFR 803), customer feedback (ISO 13485 §8.2.1), and clinical questions - all funnel into the internal queues.

Field-safety notices & FSCAs

Author, e-sign, and broadcast FSNs with a delivery ledger and unsubscribe tokens; release FSCA notifications to the authority before broadcast gates open.

People & competency

Who's qualified to do what, who's trained on what, who signed what. ISO 13485 §6.2 has its own opinions and Reeve respects them.

Employees

Headcount with hire / leave dates, departments, and per-employee training history.

Job roles

ISO §6.2 competency profiles per role, with the required SOPs, trainings, and qualifications spelled out.

Trainings & quizzes

Training plans, attendance tracking, optional quiz questions with attempts and pass thresholds, and acknowledgement signatures.

External personnel

Contractors and auditors with NDA / consent tracking, plus token-based e-sign for external signers.

Departments

Org hierarchy used by access control, role assignment, and training scope.

Suppliers, purchasing & customers

Approved supplier register, periodic re-evaluation, certificate uploads, and the supporting purchasing + customer records.

Approved supplier register

Identity, contact, status (pending / approved / conditional / suspended / disqualified) with audit-trail-backed status transitions.

Supplier evaluations

Per-cycle scoring across quality, delivery, regulatory, and financial; configurable outcome thresholds; e-signed approval; recommendation that can be applied to flip supplier status.

Supplier portal (token-link)

Single-use, purpose-bound URLs for SCAR responses, periodic re-evaluation self-scorecards, and certificate / document uploads.

Purchased items & inspection

Catalog of purchased items per supplier, incoming-inspection records, and the NC + CAPA flows that spawn from failed inspections.

Customers & registration

Customer master, public product registration (PMS-feeding), and the FSN subscription / unsubscribe pipeline.

Risk

ISO 14971 risk management as a first-class module - not a spreadsheet on a SharePoint.

Risk files

Per-product or per-process risk files with hazard library, structured Q&A, and version-controlled review cycles.

Hazard library

A managed library of hazards, hazardous situations, harms, and severity / probability scales feeding every risk file.

E-signed release

Risk-file revisions go through reviewer + approver e-signatures before they become the current effective version.

Platform & administration

The platform layer: workflows, access control, isolation, numbering. The plumbing every module depends on.

Configurable approval workflows

A configurable approval workflow per module - its statuses, transitions, and which steps require a signature or a reason. Separation of duties enforced where it matters.

Role-based access & invitations

Admin, Manager, User, and Viewer roles with per-module permissions. The system enforces them server-side; the interface only ever shows what a user is allowed to do.

Company profile & branding

Company profile, branding, locale, timezone, and an enabled-modules switch. Your data is fully isolated from every other company.

Per-module numbering

Stable, gap-free identifiers per module (SOP-NNNN, CAPA-NNNN, etc.) - automatically assigned and never reused.

Cross-cutting

Compliance capabilities

The platform layer your auditor will spend the most time on. Wired through every module - not bolted onto specific ones.

21 CFR Part 11 e-signatures

Re-authentication + reason-for-change capture on every regulated transition. Three signature modes: internal (Cognito + TOTP), token-link for external signers, and paper-scan upload with attesting signer.

Immutable audit trail

Append-only audit log on every write - IP, user-agent, before / after data, changed fields, and the user. The trail is the source of truth for inspections.

WORM / write-once retention

Approved controlled-document files are locked under write-once retention for the configured window, so an approved revision cannot be silently overwritten or deleted.

Role-based access control

Four standing roles (Admin / Manager / User / Viewer) with per-module permissions. Manager scope is bounded to their own department; Viewer is read-only with no exceptions.

Configurable approval workflows

Each module defines its own state machine + transitions. Separation-of-duties checks (e.g. approver ≠ author) are first-class properties of a transition, not afterthoughts.

Complete data isolation

Every company's data is fully separated from every other's, enforced in two independent layers so a single failure can't cross the boundary. Your records are yours alone.

Audit-ready, day one

Pick a module to explore - or jump straight in and create your company workspace.