Safety database · for QPPVs and pharmacovigilance consultancies

Pharmacovigilance you can prove.

Your cases, their deadlines and every change ever made to them, in one system that keeps the evidence. And the validation documentation an auditor asks for is written for you, and delivered ready to sign.

  • Turnkey — nothing to install
  • Hosted in the EU
  • Technical and validation support included

Vigila is in development, with launch estimated for September 2026.

The difference

The week an audit is announced.

Without

  • You assemble extracts by hand
  • Nobody can say who changed that field, or when
  • Deadlines live in a spreadsheet and in someone's head
  • The documentation gets written the week before

With Vigila

  • The auditor logs in and reads it
  • Every change already recorded, by the database
  • The clock runs by itself
  • The documentation has been signed since go-live

The product

What Vigila does.

Case entry

E2B(R3) structure. The form tells you which of the four validity criteria is still missing while you type.

Deadlines

Day 0 is computed, not remembered. A traffic-light board that sorts by what runs out first.

Full history

Old value, new value, who and when — recorded automatically, and nobody can edit it. Including us.

Approval

Approving a case asks for your password again, and records what the signature meant.

One client cannot see another

Separation built into the database itself, not promised by the application. Their auditor gets a read-only login of their own.

Listings and exports

Every figure clicks through to the cases behind it. Every export says who made it and when.

Turnkey

From contract to go-live.

1

We set it up

Your client organisations, users, timelines and product lists — configured, tested and handed over working.

2

We migrate your register

Your existing cases come across under a written protocol, with a report proving nothing was lost on the way.

3

You receive the documentation

Written, delivered for your signature, and brought up to date every time the system changes.

Your part is the one nobody can do for you: review, and sign.

Pricing

What it costs.

One setup fee and a flat monthly fee, per client. No per-case fees, no hourly billing — a busy quarter costs the same as a quiet one.

Setup — once
300€ / client

Paid once, on signing.

  • Your system configured
  • Your organisations and products loaded
  • Your people trained
  • The documentation pack
Migration — optional
+200€ once

Included with the annual plan.

  • From your E2B(R3) XML — your safety database's export, or EudraVigilance's
  • Unlimited cases migrated
  • Protocol and migration report
  • Checked case by case against your source
Subscription
500€ / month / client

Everything, me included.

  • Up to 1.000 cases a year, 10 users
  • Hosted in the European Union
  • Ten years of retention
  • Daily backups, restored every quarter
  • 99% availability in working hours
  • Maintenance and change control
  • Technical support — from the person who built it
  • Validation support — kept current, ready to sign
  • No minimum term — one month's notice
Recommended

6.000€ / year / client

  • Everything above, paid once on signing
  • The twelve months start the day you go live
  • Setup and migration, included

Sixty days to change your mind.

Sixty days of real use, not a trial. If it is not for you, everything you have paid is refunded. In full.

  • The setup and the migration too
  • Monthly or yearly, all of it

A client — a tenant, in the language of other vendors — is one marketing-authorisation holder whose cases you manage, with its own isolated space and its own users.

Support is part of the fee. The system and its validation documentation, never billed by the hour and never quoted afterwards as a separate project.

MedDRA is licensed by you, directly from the MSSO. It is not resold in the fee, and the system will not code without a current subscription of your own.

Fees are paid in advance, per client. Prices exclude VAT.

Your supplier

Didac Royo

Founder · software engineer

I build software for regulated environments — clinical trials and medical devices — and my name goes on the regulatory paperwork, not only on the code.

With Vigila, that is the person you talk to. No account manager, no ticket queue. And the question to ask any one-person supplier — what happens if he is not here next year? — has a written answer: the specification, the code and the evidence are built so that someone else can take them over, and that continuity can go into the contract.

Contact me

  • Co-founder / CTO at S4 Research (2009) and OPTretina (2014) Regulated software: hosting of electronic data capture (EDC) for clinical trials, and UPretina, software regulated as a medical device (MDSW).
  • Technical responsible person · PRRC · vigilance contact person The three regulatory roles of a medical-device software manufacturer (UPretina), registered with the AEMPS, the Spanish Agency for Medicines and Medical Devices. AEMPS
  • Expert programme in medical-device management Universidad Politécnica de Madrid. Regulation, risk analysis, quality systems, and the vigilance and post-market surveillance of medical devices. Programme details. Universidad Politécnica de Madrid
  • Industrial Engineer, computing specialisation Escola Tècnica Superior d'Enginyeria Industrial de Barcelona (ETSEIB), Universitat Politècnica de Catalunya. The pre-Bologna degree, recognised at master's level (EQF 7). Universitat Politècnica de Catalunya

FAQ

Frequently asked questions.

Doing the work

What happens to a narrative I rewrite?

Every wording is kept. Edits are audited like any other field, so the narrative as it stood before a change can be recovered — which matters, because the narrative is the part an assessor reads first and the part most often revised after medical review.

How do I know whether a reaction is expected?

The system holds each product's listed terms with an effective date and country, so the list you assess against is the one in force on the date of the reaction, not the one in force today — the distinction an assessor challenges.

The judgment stays yours, and it is recorded as one: expectedness is never stored without who decided it and why.

What happens when a follow-up arrives?

It becomes a new version linked to the previous one, with the chronology visible from the case. Significant new information opens a new 15-day clock from the date you received it, and the change of due date is recorded.

Two of us are editing the same case. What happens?

The second save is rejected, and you are shown what changed while you were editing. Nothing is ever overwritten silently — a quietly lost edit is the kind of thing you only discover during an audit.

Can it follow our procedure rather than yours?

Yes. The stages, who may move a case between them, and a separate route per case type are all configurable. Reporting timelines and warning thresholds are yours to set, without asking us for a change.

What about the source documents?

CIOMS forms, the original email, clinical reports — attached and classified on upload, so you can list the cases with no source document instead of finding out during the audit. Encrypted, hashed, and opening one is itself recorded.

Deadlines, evidence and audits

Can I prove we met the deadlines?

A compliance report per period and per client lists what was on time, what was late and what is pending. Per case, the single PDF below carries the whole state history — when it entered each stage and who moved it on.

What do I actually hand an auditor?

A single PDF per case with the data, the state history and the audit trail together. Any listing, carrying a header with who produced it, when, the filters and an export identifier. That identifier sits in the audit trail, so the file in their hands ties back to the moment it was generated.

Plus the user access listing — role, organisations, last access — which is what they ask for when they check your periodic access review.

What roles does it come with?

Five, and the boundaries between them are the point — separation of duties is one of the first things an auditor checks:

  • Data entry — creates and edits draft cases.
  • Reviewer — reviews, approves, or returns a case with comments.
  • PV responsible / QPPV — locks and unlocks with a reason, sets the timelines, sees the metrics.
  • Auditor — read-only over cases and the full audit trail, with export. This is the login your client's auditor gets.
  • Administrator — manages users and configuration, and cannot edit case data.

And no role — the administrator included — can modify the audit trail.

Who is allowed to approve, and how is that proven?

Permissions go by role, so someone entering cases cannot approve one. Approval asks for the password again and records the signatory, the time and what the signature meant. Each signature is tied to the exact content that was signed: if the record is altered afterwards, the system shows that the signature no longer matches.

Is it already validated?

No — and be careful with any vendor who claims theirs is. Validation is demonstrated for one specific installation, with your users and your procedures. A claim made about the product in general glosses over the part that lands on your desk.

What Vigila does is produce the evidence as it is built: every requirement has a permanent identifier, every test names the requirement it proves, and the traceability matrix comes out of the system itself — not written by hand afterwards.

What does validation support include?

The documentation written and sent to you to review, approve and sign — and brought up to date whenever the system changes. Help drafting your own validation procedure and the procedures that cover the use of the system. The answers when a client audits me as your supplier. And the evidence itself when an auditor asks for it.

It is validation of the system, not regulatory advice: your case assessments, your submissions and your pharmacovigilance procedures stay yours.

It is in the monthly fee. No ticket, no hourly invoice.

How much of this lands on me?

Configuration, migration, documentation and upkeep are mine. Yours is what only you can do: approving the requirements, signing what you sign, and running the acceptance testing with your own people. A supplier who offers to sign your procedures for you is selling you a future finding.

Data, security and continuity

Can it separate my clients properly?

Yes — it is what Vigila was designed for, not an option bolted on. Separation is built into the database itself, so a user assigned to one client cannot reach another's cases by any route, including editing an identifier in the address bar.

Where is my data?

In the European Union, only. Adverse-reaction data is special-category health data and is treated that way: encrypted in transit and at rest, encrypted attachments, no personal data in technical logs, a data-processing agreement, no transfer outside the EU.

What if something breaks?

A full copy every day and a further copy every four hours, stored encrypted and away from the main system. At most four hours of data at risk, and back in service within eight hours.

Backups are regularly restored into a separate test environment, and the result is reported automatically — a backup nobody has ever restored is a claim, not a control.

What if I want to leave?

You leave. The monthly plan has no minimum term — one month's notice, whenever you want. You take everything — cases, attachments and the full history — in an open format, per client. Built in rather than negotiated, because being able to leave is what makes staying a decision.

Scope and timing

Does it do MedDRA coding and E2B(R3) files?

Both. You code reactions against MedDRA, and Vigila builds the E2B(R3) file for you to upload — checked against the conformance rules before you get it, so a missing element turns up here rather than in a rejection notice. What it does not do is transmit: the file leaves through a person, which at these volumes is what the EMA expects anyway.

MedDRA you license yourself, directly from the MSSO. It is not resold here and not included in the price — the fee is set on your own annual revenue, and regulators and non-profits pay nothing. Give us the subscription reference and it is re-checked once a year. If it ever lapses, coding stops and nothing else does: your cases stay readable and exportable, because an unpaid subscription must never make a safety record illegible.

Do I need a gateway to EudraVigilance?

For the volumes Vigila is priced for — up to 1.000 cases a year per client — no. Exporting the XML and uploading it through EVWEB or EVPOST is what the EMA itself expects from small and medium organisations, and skipping the gateway removes the most expensive piece of the usual project.

If you handle more than that, say so on the first call and you will get a straight answer on whether Vigila fits you at all.

Does it cover cosmetics or medical devices?

Vigila is pharmacovigilance — medicines, human use. The structure is not hostile to the others, but claiming them today would be exactly the kind of overclaim this page warns you about.

When can I have it?

Launch is estimated for September 2026. If your own deadline is earlier or later — a contract, an audit, a client start date — tell me and you get a straight answer against it.

Next step

If it fits, this is how we start.

Write to me and we set a start date. The sixty-day guarantee covers the rest: if it does not work out, everything you have paid comes back, setup included.

Email me to start

Nothing at this stage needs case data, patient data or client documents — and none of those should be sent by email.