Security & Compliance
Audit-Ready Evidence, Built Into Every Step.
Every controlled document follows a defined lifecycle with accountability, authorization, traceability, and evidence built into every step.
Compliance & standards
The document control practices NOMOS supports.
The controls that audits and quality systems commonly look for are part of how NOMOS works, not an add-on.
- Unique document identification
- Controlled revisions
- Approval with electronic signatures (SHA-256)
- Distribution and acknowledgement
- Complete audit trail
- Change control
- Retention and governance
- Data separation by plant, site or business unit
ISO 9001, clause 7.5.3
What the standard asks for, and where NOMOS supports it.
ISO 9001 requires documented information to be controlled. These are the four things clause 7.5.3 asks you to address, and the NOMOS features that support each one.
7.5.3.2 a)
Distribution, access, retrieval and use
- Controlled distribution to departments, groups or individuals
- Need-to-know access by role and by organizational unit
- Document library with search, and acknowledgement tracking
7.5.3.2 b)
Storage and preservation, including legibility
- One governed library for every controlled document and revision
- SHA-256 integrity and tamper evidence on signatures
7.5.3.2 c)
Control of changes
- Change requests with reason, severity and evidence
- Revision management with one Active version
- Multi-level approval with electronic signatures
7.5.3.2 d)
Retention and disposition
- Retention controls
- Previous revisions kept and marked Obsolete
- Complete activity history
Certification is earned by your organization's management system, not by software. NOMOS supports these practices; your auditor assesses how you use them.
Built for scrutiny
Designed for Regulated and Quality-Driven Environments.
Supports document control practices commonly required by:
ISO 9001
Quality management
GMP
Controlled documentation
Internal audits
and quality systems
Customer audits
and regulatory reviews
SHA-256
Integrity hash on every electronic signature
5 min
One-time passcode for every external link
365 days
Longest an external link can ever stay open
Electronic signatures
Every approval is signed, and every signature is evidence.
Signatures are tied to the signer's identity, the time, and the integrity of what was signed.
Drawn, typed or uploaded
Three ways to sign.
User identity and timestamp
Each signature records who signed and when.
SHA-256 integrity
Signatures are stored with a hash.
Tamper evidence
Changes after signing are evident.
Audit record
Every signature is part of the audit record.
Required on every decision
Approvals and rejections both require a signature.
Access & separation
Right access, always.
People see what they need to see, in the parts of the organization they belong to.
Unit-level data separation
Each plant, site, branch or business unit keeps separate governance and access on a shared platform.
Need-to-know access control
Visibility by role and by organizational unit.
Confidential classification
Documents can be classified as confidential.
Retention controls
Retention and governance for controlled records.
Controlled distribution
Control what employees receive.
Ensure employees have the latest approved documents and understand them.
Active document
The current approved revision
Department, group or individual
Assign recipients
Soft copy or numbered hard copy
Controlled distribution
Notification
Sent automatically
Read-and-understand questions
Must be completed first
Acknowledgement
Employee confirmation
Compliance record
Immutable record with timestamp
Distribution rules
- Only assigned recipients can acknowledge.
- Controlled-document questionnaires must be completed.
- Hard copies receive traceable copy numbers.
- Acknowledgement records become immutable.
Secure external sharing
Share externally without losing control.
Share with auditors, customers or suppliers. Share access, not uncontrolled copies.
Select document
Choose the document to share, inside NOMOS.
Secure share
Generate a secure link.
Email link
Send it to the external recipient.
One-time passcode
The recipient verifies with a passcode.
Permission-controlled access
View, download or print, as permitted.
Security and control
- Time-limited access
- Links expire. The maximum sharing period is 365 days.
- One-time passcode
- A 5-minute passcode with limited attempts.
- Authenticated session
- Sessions last 15 minutes.
- Immediate revocation
- Access can be withdrawn at any time.
- Access logging
- Every view, download and print is logged.
- IP and device information
- Recorded with each access for audit.
Govern Documents With Confidence.
Create, approve, distribute, change, share, and audit business-critical documents through one controlled enterprise platform.
Control · Compliance · Traceability