R-019-002 External software list
External software list
| Software type | Name | Risk Class | Risk Justification | Performance | Validation activities |
|---|---|---|---|---|---|
| Operative system | MACos | Non-risked | Infrastructure software; no direct impact on product quality or patient safety | Not modifiable. Previous experience endorsed. | This software has been tested by the state of the art and global users. Extra validation activities are not required. It is automatically validated. |
| Operative system | Ubuntu | Non-risked | Infrastructure software; no direct impact on product quality or patient safety | Not modifiable. Previous experience endorsed. | This software has been tested by the state of the art and global users. Extra validation activities are not required. It is automatically validated. |
| Commercial application | Google Workspace | Non-risked | General business operations (email, documents); no impact on medical device quality per FDA CSA Draft | According to the Draft of Computer software assurance CFR- FDA, software intended for management of general business processes or operations, such as email o accounting applications are not considered to be used as part of production or the quality system. | Not required |
| Commercial application | Atlassian | Non-high-risk | QMS tool for project/issue tracking; indirect quality impact through process management | Not modifiable but it is configurable. | It requires a functional test with specific operations related to the affected processes and their applicable requirements, according to the specific test plan documented in the R-019-001 Software validation report_Atlassian. |
| Commercial application | Factorial | Non-risked | HR management tool; no impact on product quality or patient safety | Not modifiable but it is configurable. Included within the application its own electronic signature system (Signaturit) compliant to 21 CFR part 11. | This software has been tested by the state of the art and global users. Extra validation activities are not required. It is automatically validated. |
| Commercial application | eSIGN | Non-high-risk | Electronic signature for QMS documents; supports document control integrity | Not modifiable | This software has been tested by the state of the art and global users. Extra validation activities are not required. It is automatically validated. |
| Commercial application | Hubspot | Non-high-risk | CRM and customer communication; supports post-market surveillance and complaint handling processes | Not modifiable but it is configurable | This software has been tested by state-of-the-art and global users, but it requires a simple validation process according to the specific test plan documented at the R-019-001 Software validation report_Hubspot. |
| Commercial application | Visual Studio Code | Non-risked | Code editor tool; no direct impact on product quality (code itself is validated separately) | Not modifiable but it is configurable | This software has been tested by the state of the art and global users. Extra validation activities are not required. It is automatically validated. |
| Commercial application | GitHub (Microsoft) | Non-high-risk | Version control and code repository; critical for design history and traceability | Not modifiable but it is configurable. We have configured the electronic signature system GPG (GNU Privacy Guard) to comply with 21 CFR part 11. | This software has been tested by the state of the art and global users but it requires a simple validation process according to the specific test plan documented at the R-019-001 Software validation report__GitHub_GPG key signature. |
| Commercial application | CVAT | Non-high-risk | Annotation tool for AI training data; affects training data quality for medical device AI | Not modifiable but it is configurable | This software has been tested by the state of the art and global users but it requires a simple validation process according to the specific test plan documented at the R-019-001 Software validation report__CVAT. |
| Commercial application | Docker | Non-high-risk | Container platform for development and deployment; affects build reproducibility | Not modifiable but it is configurable | This software has been tested by the state of the art and global users but it requires a simple validation process according to the specific test plan documented at the R-019-001 Software validation report__Docker. |
Signature meaning
The signatures for the approval process of this document can be found in the verified commits at the repository for the QMS. As a reference, the team members who are expected to participate in this document and their roles in the approval process, as defined in Annex I Responsibility Matrix of the GP-001, are:
- Author: Team members involved
- Reviewer: JD-003, JD-004
- Approver: JD-001