Trust, Security & Compliance
Built for regulated teams, and stated plainly.
Juncture handles pharma content, so its data, identity and compliance posture is written as fact, with the roadmap kept clearly separate. Inference runs on Azure OpenAI and your content is never used to train models. Multi-tenant SaaS on Azure with per-tenant isolation, an EU region available, SSO via Microsoft Entra, role-based access, and encryption in transit and at rest.
One thing up front, because it answers most of the questions below: Juncture works on promotional content, the approved label and public questions. It does not ingest patient data.
00/The posture at a glance
Everything a security review asks, in one view.
The questions a regulated buyer brings to a first call, answered as fact. Each card links to where it lives on this page. What is in place today, where Juncture provides the supporting controls and you validate, and what is still on the roadmap.
01/Data governance
Your content stays yours.
Juncture is built for regulated pharma teams, so the data posture is plain and stated as fact. Inference runs on Azure OpenAI and your content is never used to train models. Multi-tenant SaaS on Azure with per-tenant isolation, an EU region available, encryption in transit and at rest, and retention and deletion you control.
What crosses the boundary
Illustrative · fictional brand Varigel
Goes in
- Promotional content (the asset under review)
- The approved label and its source clauses
- Public, HCP-style questions for Answer Monitor
The Juncture engine
Inference on Azure OpenAI. Your content is never used to train a model.
Comes out
- A verdict on every claim, citing the controlling clause
- A time-stamped, tamper-evident audit trail
- Share of Answer across the AI engines, from public probes
Never crosses the boundary
- Patient records (PHI)
- Identifiable personal data (PII)
- Adverse-event case data
02/PHI and PII
No patient data, by design.
The cleanest way to handle patient data is never to take it. Juncture works on promotional content, the approved label and public questions. It does not ingest PHI or PII, so there is no patient data to govern, to leak or to delete.
What Juncture works on
Content, label, public questions.
- The promotional content you are about to review or have published.
- The approved label and the source clauses your claims must trace to.
- Public, HCP-style questions used to probe how AI engines answer about the brand.
What it never asks for
No PHI, no PII.
- Patient records or any protected health information (PHI).
- Identifiable personal data (PII) about patients.
- Proprietary content sent into a public model to be monitored.
Why this matters to your DPIA
Because Juncture handles promotional content and public questions, not patient data, the scope your privacy team has to assess is narrow and well defined. There is no special-category health data flowing through the system, and Answer Monitor probes the AI engines with public questions only, never with proprietary content.
03/Identity and access
Who gets in, and what they can do.
Access is wired to your identity provider and scoped to a role. SSO via Microsoft Entra with SAML and OIDC, role-based access control with three roles, and a named user behind every action.
Admin
Configures the workspace, manages users and roles, and sets the rules and stringency.
Contributor
Runs pre-checks, reviews findings and prepares assets, within the scope the admin sets.
Viewer
Reads checked assets, findings and the audit record, with no rights to change or sign off.
04/Compliance and validation
Where Juncture stands, in one view.
The questions a regulated buyer asks first, answered as fact, each with a clear status. What is in place today, where Juncture provides the supporting controls and you validate, and what is still on the roadmap. No status is overstated.
GDPR
GDPR compliant, with a data processing agreement available for customers.
Data isolation
Multi-tenant SaaS on Azure with per-tenant data isolation, and an EU region available.
No training on your content
Inference runs on Azure OpenAI. Your content is never used to train or improve a model.
Identity and access
SSO via Microsoft Entra (SAML and OIDC) and role-based access control: admin, contributor, viewer.
Audit trail and e-signature
Time-stamped, tamper-evident audit trail and e-signature sign-off, attributed to a named user.
21 CFR Part 11
Juncture provides the supporting technical controls. It is decision support, not a validated GxP system of record. You validate it for Part 11 use under your own SOPs.
SOC 2
In progress, on the roadmap, not yet complete. Juncture does not hold a SOC 2 report today.
The line on Part 11, stated plainly
Juncture provides the supporting technical controls for 21 CFR Part 11: a time-stamped, tamper-evident audit trail, e-signature sign-off and access control. It is decision support that backs the human reviewer, not a validated GxP system of record. Your quality team validates the system for Part 11 use under your own SOPs, inside your own quality framework, and keeps the validation evidence. We do not describe Juncture as Part 11 compliant or Part 11 validated, because that determination is yours to make and to own.
05/Part 11 controls
The three controls, up close.
Here are the supporting technical controls for 21 CFR Part 11, in detail: a time-stamped, tamper-evident audit trail, e-signature sign-off, and role-based access control. Juncture provides them; you validate the system for Part 11 use under your own SOPs.
Audit trail
Time-stamped and tamper-evident.
Every check, change and decision is recorded with who did it and when. The trail is the record a reviewer relies on, and it cannot be quietly edited after the fact.
E-signature
Sign-off attributed to a person.
An approval is captured as an electronic signature bound to a named user. The sign-off is on the record next to the asset it cleared.
Access control
The right people, the right rights.
Role-based access control limits who can review, approve and sign. Signing authority is scoped to the roles you assign, so accountability is clear.
How the handoff works
These controls are how Juncture backs your reviewer with a defensible record. They do not make Juncture a GxP system of record. Your quality team takes these controls, validates the system for Part 11 use under your own SOPs, runs it inside your own quality framework, and keeps the validation evidence. The accountable sign-off stays with your people.
06/Your responsibility vs ours
Decision support, not a sign-off.
Juncture is decision support. It backs your reviewers with a checked asset and a clear record. It does not replace the required regulatory, medical or legal review, and the accountable decision stays with the people who sign it.
What Juncture does
Ours.
- Pre-check an asset against the approved label and cite the clause behind every verdict.
- Provide the technical controls: audit trail, e-signature sign-off, and role-based access.
- Monitor how AI engines answer about your brand and flag drift against the label.
- Sit as a pre-MLR pre-check layer that complements your MLR system of record. It does not replace it.
What stays with you
Yours.
- The accountable regulatory, medical and legal review. Juncture supports it, it does not replace it.
- The final approval decision, made by your named reviewers under your SOPs.
- Validating the system for Part 11 use and keeping your own validation evidence.
07/On the roadmap
In progress, not yet shipped.
The items below are roadmap commitments, not current facts. We list them here, clearly separated from what Juncture provides today, so there is never any doubt about which is which.
SOC 2
We are working toward a SOC 2 examination. It is not complete, and Juncture does not hold a SOC 2 report today. We will say so here when it does.
Veeva Vault connector
A live connector to route a cleared asset and its record straight into Veeva Vault PromoMats is in development. It is not yet generally available. Today you attach the exported report manually.
DAM and asset-registry pull
An automated pull from a DAM or asset registry, so approved visuals and assets flow in without a manual upload, is on the roadmap and not yet shipped.
Public API
A public API to wire Juncture into your own systems is planned. Until it ships, ingestion is via the supported uploads and library imports available today.
OpenEvidence integration
An OpenEvidence integration is a planned, roadmap item. OpenEvidence is not one of the AI engines Answer Monitor watches today.
Further certifications
Any additional certifications or attestations we pursue will be listed here as planned or in progress until they are issued. We do not claim a certification before it exists.
Enterprise-ready · for procurement
- SSO via Microsoft Entra
- SAML and OIDC
- Role-based access control
- Encryption in transit and at rest
- Customer-controlled retention
- No customer content used to train models
- EU region available
- DPA available
08/Trust questions
Questions about trust and security
Plain answers to what a security and quality team asks before they bring Juncture in.
- Is my content used to train AI models?
- No. Your content is never used to train models. Inference runs on Azure OpenAI, and your data is not used to train or improve any shared model.
- How does Juncture handle data and security?
- Inference runs on Azure OpenAI and your content is never used to train models. Juncture is multi-tenant SaaS on Azure with per-tenant data isolation, an EU region available, encryption in transit and at rest, time-stamped tamper-evident audit logs, and customer-controlled retention and deletion. It is GDPR compliant, a DPA is available, and access is via SSO through Microsoft Entra with role-based access control.
- Does Juncture ingest patient data, PHI or PII?
- No. Juncture works on promotional content, the approved label, and public HCP-style questions. It does not ingest patient data, so there is no PHI or PII flowing through the system. Answer Monitor probes the AI engines with public questions only, never with proprietary content. The cleanest way to handle patient data is never to take it.
- Is my data isolated from other customers, and can I keep it in the EU?
- Yes. Juncture is multi-tenant SaaS on Microsoft Azure with per-tenant data isolation, so one customer can never see another customer content. An EU region is available for customers who require their data to stay in the EU. You control retention, and we delete your content on request.
- How does Juncture handle identity and access?
- Access is governed by your identity provider. Juncture supports SSO via Microsoft Entra with SAML and OIDC, and role-based access control with three roles: admin, contributor and viewer. Sign-off is restricted to the roles you assign, and every change and approval is attributed to a named user in the audit trail.
- Is Juncture 21 CFR Part 11 compliant?
- Juncture provides the technical controls for 21 CFR Part 11: a time-stamped, tamper-evident audit trail, e-signature sign-off, and role-based access control. You validate it for Part 11 use under your own SOPs. We do not describe Juncture as Part 11 compliant or Part 11 validated, because that determination belongs to the customer.
- Is Juncture a validated GxP system of record?
- No. Juncture is decision support that backs the human reviewer with a checked asset, a clear shortlist and a defensible record. It provides the supporting technical controls for Part 11, but it is not a validated GxP system of record. It is a pre-MLR pre-check layer that complements your MLR system of record, such as Veeva PromoMats or Vault, and does not replace it. You validate Juncture for Part 11 use inside your own quality framework.
- Do you have SOC 2 or a live Veeva Vault connector?
- Not yet. SOC 2 is in progress and not yet complete, and Juncture does not hold a SOC 2 report today. A live Veeva Vault connector, a DAM or asset-registry pull, a public API and an OpenEvidence integration are on the roadmap, not shipped. We list roadmap items separately from what Juncture provides today.
- Does Juncture replace MLR or regulatory review?
- No. Juncture is decision support. It backs your reviewers with a checked asset, a clear shortlist and a defensible record. The required regulatory, medical and legal review, and the accountable sign-off, stay with the people who own them and your own system of record.
Bring it to your security team
See the controls on your own asset.
Bring an asset and a brand. We will walk your team through the audit trail, the sign-off, the access model and the data path, on a live pre-check.