Skip to content

Security & Compliance

Audit-Ready Evidence, Built Into Every Step.

Every controlled document follows a defined lifecycle with accountability, authorization, traceability, and evidence built into every step.

Compliance & standards

The document control practices NOMOS supports.

The controls that audits and quality systems commonly look for are part of how NOMOS works, not an add-on.

  • Unique document identification
  • Controlled revisions
  • Approval with electronic signatures (SHA-256)
  • Distribution and acknowledgement
  • Complete audit trail
  • Change control
  • Retention and governance
  • Data separation by plant, site or business unit

ISO 9001, clause 7.5.3

What the standard asks for, and where NOMOS supports it.

ISO 9001 requires documented information to be controlled. These are the four things clause 7.5.3 asks you to address, and the NOMOS features that support each one.

7.5.3.2 a)

Distribution, access, retrieval and use

  • Controlled distribution to departments, groups or individuals
  • Need-to-know access by role and by organizational unit
  • Document library with search, and acknowledgement tracking

7.5.3.2 b)

Storage and preservation, including legibility

  • One governed library for every controlled document and revision
  • SHA-256 integrity and tamper evidence on signatures

7.5.3.2 c)

Control of changes

  • Change requests with reason, severity and evidence
  • Revision management with one Active version
  • Multi-level approval with electronic signatures

7.5.3.2 d)

Retention and disposition

  • Retention controls
  • Previous revisions kept and marked Obsolete
  • Complete activity history

Certification is earned by your organization's management system, not by software. NOMOS supports these practices; your auditor assesses how you use them.

Built for scrutiny

Designed for Regulated and Quality-Driven Environments.

Supports document control practices commonly required by:

How NOMOS maps to ISO 9001, clause 7.5.3

ISO 9001

Quality management

GMP

Controlled documentation

Internal audits

and quality systems

Customer audits

and regulatory reviews

SHA-256

Integrity hash on every electronic signature

5 min

One-time passcode for every external link

365 days

Longest an external link can ever stay open

Electronic signatures

Every approval is signed, and every signature is evidence.

Signatures are tied to the signer's identity, the time, and the integrity of what was signed.

Drawn, typed or uploaded

Three ways to sign.

User identity and timestamp

Each signature records who signed and when.

SHA-256 integrity

Signatures are stored with a hash.

Tamper evidence

Changes after signing are evident.

Audit record

Every signature is part of the audit record.

Required on every decision

Approvals and rejections both require a signature.

Access & separation

Right access, always.

People see what they need to see, in the parts of the organization they belong to.

Unit-level data separation

Each plant, site, branch or business unit keeps separate governance and access on a shared platform.

Need-to-know access control

Visibility by role and by organizational unit.

Confidential classification

Documents can be classified as confidential.

Retention controls

Retention and governance for controlled records.

Controlled distribution

Control what employees receive.

Ensure employees have the latest approved documents and understand them.

  1. Active document

    The current approved revision

  2. Department, group or individual

    Assign recipients

  3. Soft copy or numbered hard copy

    Controlled distribution

  4. Notification

    Sent automatically

  5. Read-and-understand questions

    Must be completed first

  6. Acknowledgement

    Employee confirmation

  7. Compliance record

    Immutable record with timestamp

Distribution rules

  • Only assigned recipients can acknowledge.
  • Controlled-document questionnaires must be completed.
  • Hard copies receive traceable copy numbers.
  • Acknowledgement records become immutable.

Secure external sharing

Share externally without losing control.

Share with auditors, customers or suppliers. Share access, not uncontrolled copies.

  1. Select document

    Choose the document to share, inside NOMOS.

  2. Secure share

    Generate a secure link.

  3. Email link

    Send it to the external recipient.

  4. One-time passcode

    The recipient verifies with a passcode.

  5. Permission-controlled access

    View, download or print, as permitted.

Security and control

Time-limited access
Links expire. The maximum sharing period is 365 days.
One-time passcode
A 5-minute passcode with limited attempts.
Authenticated session
Sessions last 15 minutes.
Immediate revocation
Access can be withdrawn at any time.
Access logging
Every view, download and print is logged.
IP and device information
Recorded with each access for audit.

Govern Documents With Confidence.

Create, approve, distribute, change, share, and audit business-critical documents through one controlled enterprise platform.

Request a Demonstration

Control · Compliance · Traceability