Skip to content

Trust, Security & Compliance

Built for regulated teams, and stated plainly.

Juncture handles pharma content, so its data, identity and compliance posture is written as fact, with the roadmap kept clearly separate. Inference runs on Azure OpenAI and your content is never used to train models. Multi-tenant SaaS on Azure with per-tenant isolation, an EU region available, SSO via Microsoft Entra, role-based access, and encryption in transit and at rest.

One thing up front, because it answers most of the questions below: Juncture works on promotional content, the approved label and public questions. It does not ingest patient data.

00/The posture at a glance

Everything a security review asks, in one view.

The questions a regulated buyer brings to a first call, answered as fact. Each card links to where it lives on this page. What is in place today, where Juncture provides the supporting controls and you validate, and what is still on the roadmap.

01/Data governance

Your content stays yours.

Juncture is built for regulated pharma teams, so the data posture is plain and stated as fact. Inference runs on Azure OpenAI and your content is never used to train models. Multi-tenant SaaS on Azure with per-tenant isolation, an EU region available, encryption in transit and at rest, and retention and deletion you control.

What crosses the boundary

Illustrative · fictional brand Varigel

Goes in

  • Promotional content (the asset under review)
  • The approved label and its source clauses
  • Public, HCP-style questions for Answer Monitor

The Juncture engine

Inference on Azure OpenAI. Your content is never used to train a model.

Comes out

  • A verdict on every claim, citing the controlling clause
  • A time-stamped, tamper-evident audit trail
  • Share of Answer across the AI engines, from public probes

Never crosses the boundary

  • Patient records (PHI)
  • Identifiable personal data (PII)
  • Adverse-event case data
Illustrative data path, fictional brand Varigel. Juncture works on promotional content, the approved label and public questions. It does not ingest patient data.
Inference
Runs on Azure OpenAI (GPT-class). Your content is never used to train or improve any model, ours or a shared one.
Tenancy
Multi-tenant SaaS on Microsoft Azure, with per-tenant data isolation so one customer can never see another customer's content.
Data residency
An EU region is available for customers who require their data to stay in the EU.
Encryption
Encrypted in transit and at rest, end to end, on the platform and in storage.
Retention and deletion
Your content stays yours. You control retention, and we delete it on request.
Privacy and the DPA
GDPR compliant, with a data processing agreement available for customers who need one in place.
Audit logs
Access and activity are recorded in time-stamped, tamper-evident audit logs, attributed to a named user.
No model lock-in of your data
Probes for Answer Monitor use only public questions. No proprietary content is sent into a model to be monitored.

02/PHI and PII

No patient data, by design.

The cleanest way to handle patient data is never to take it. Juncture works on promotional content, the approved label and public questions. It does not ingest PHI or PII, so there is no patient data to govern, to leak or to delete.

What Juncture works on

Content, label, public questions.

  • The promotional content you are about to review or have published.
  • The approved label and the source clauses your claims must trace to.
  • Public, HCP-style questions used to probe how AI engines answer about the brand.

What it never asks for

No PHI, no PII.

  • Patient records or any protected health information (PHI).
  • Identifiable personal data (PII) about patients.
  • Proprietary content sent into a public model to be monitored.

Why this matters to your DPIA

Because Juncture handles promotional content and public questions, not patient data, the scope your privacy team has to assess is narrow and well defined. There is no special-category health data flowing through the system, and Answer Monitor probes the AI engines with public questions only, never with proprietary content.

03/Identity and access

Who gets in, and what they can do.

Access is wired to your identity provider and scoped to a role. SSO via Microsoft Entra with SAML and OIDC, role-based access control with three roles, and a named user behind every action.

Single sign-on
SSO via Microsoft Entra, supporting SAML and OIDC, so access is governed by your identity provider, not a separate password.
Access control
Role-based access control with three roles: admin, contributor and viewer.
Least privilege
Each person sees only what their role allows, and sign-off is restricted to the roles you assign it to.
Accountability
Every change and every approval is attributed to a named user in the audit trail.

Admin

Configures the workspace, manages users and roles, and sets the rules and stringency.

Contributor

Runs pre-checks, reviews findings and prepares assets, within the scope the admin sets.

Viewer

Reads checked assets, findings and the audit record, with no rights to change or sign off.

04/Compliance and validation

Where Juncture stands, in one view.

The questions a regulated buyer asks first, answered as fact, each with a clear status. What is in place today, where Juncture provides the supporting controls and you validate, and what is still on the roadmap. No status is overstated.

StatusAvailable todaySupporting controls, you validateOn the roadmap

GDPR

GDPR compliant, with a data processing agreement available for customers.

Available today

Data isolation

Multi-tenant SaaS on Azure with per-tenant data isolation, and an EU region available.

Available today

No training on your content

Inference runs on Azure OpenAI. Your content is never used to train or improve a model.

Available today

Identity and access

SSO via Microsoft Entra (SAML and OIDC) and role-based access control: admin, contributor, viewer.

Available today

Audit trail and e-signature

Time-stamped, tamper-evident audit trail and e-signature sign-off, attributed to a named user.

Available today

21 CFR Part 11

Juncture provides the supporting technical controls. It is decision support, not a validated GxP system of record. You validate it for Part 11 use under your own SOPs.

Supporting controls

SOC 2

In progress, on the roadmap, not yet complete. Juncture does not hold a SOC 2 report today.

On the roadmap

The line on Part 11, stated plainly

Juncture provides the supporting technical controls for 21 CFR Part 11: a time-stamped, tamper-evident audit trail, e-signature sign-off and access control. It is decision support that backs the human reviewer, not a validated GxP system of record. Your quality team validates the system for Part 11 use under your own SOPs, inside your own quality framework, and keeps the validation evidence. We do not describe Juncture as Part 11 compliant or Part 11 validated, because that determination is yours to make and to own.

05/Part 11 controls

The three controls, up close.

Here are the supporting technical controls for 21 CFR Part 11, in detail: a time-stamped, tamper-evident audit trail, e-signature sign-off, and role-based access control. Juncture provides them; you validate the system for Part 11 use under your own SOPs.

Audit trail

Time-stamped and tamper-evident.

Every check, change and decision is recorded with who did it and when. The trail is the record a reviewer relies on, and it cannot be quietly edited after the fact.

E-signature

Sign-off attributed to a person.

An approval is captured as an electronic signature bound to a named user. The sign-off is on the record next to the asset it cleared.

Access control

The right people, the right rights.

Role-based access control limits who can review, approve and sign. Signing authority is scoped to the roles you assign, so accountability is clear.

How the handoff works

These controls are how Juncture backs your reviewer with a defensible record. They do not make Juncture a GxP system of record. Your quality team takes these controls, validates the system for Part 11 use under your own SOPs, runs it inside your own quality framework, and keeps the validation evidence. The accountable sign-off stays with your people.

06/Your responsibility vs ours

Decision support, not a sign-off.

Juncture is decision support. It backs your reviewers with a checked asset and a clear record. It does not replace the required regulatory, medical or legal review, and the accountable decision stays with the people who sign it.

What Juncture does

Ours.

  • Pre-check an asset against the approved label and cite the clause behind every verdict.
  • Provide the technical controls: audit trail, e-signature sign-off, and role-based access.
  • Monitor how AI engines answer about your brand and flag drift against the label.
  • Sit as a pre-MLR pre-check layer that complements your MLR system of record. It does not replace it.

What stays with you

Yours.

  • The accountable regulatory, medical and legal review. Juncture supports it, it does not replace it.
  • The final approval decision, made by your named reviewers under your SOPs.
  • Validating the system for Part 11 use and keeping your own validation evidence.

07/On the roadmap

In progress, not yet shipped.

The items below are roadmap commitments, not current facts. We list them here, clearly separated from what Juncture provides today, so there is never any doubt about which is which.

In progress

SOC 2

We are working toward a SOC 2 examination. It is not complete, and Juncture does not hold a SOC 2 report today. We will say so here when it does.

In development

Veeva Vault connector

A live connector to route a cleared asset and its record straight into Veeva Vault PromoMats is in development. It is not yet generally available. Today you attach the exported report manually.

In development

DAM and asset-registry pull

An automated pull from a DAM or asset registry, so approved visuals and assets flow in without a manual upload, is on the roadmap and not yet shipped.

Planned

Public API

A public API to wire Juncture into your own systems is planned. Until it ships, ingestion is via the supported uploads and library imports available today.

Planned

OpenEvidence integration

An OpenEvidence integration is a planned, roadmap item. OpenEvidence is not one of the AI engines Answer Monitor watches today.

Planned

Further certifications

Any additional certifications or attestations we pursue will be listed here as planned or in progress until they are issued. We do not claim a certification before it exists.

Enterprise-ready · for procurement

  • SSO via Microsoft Entra
  • SAML and OIDC
  • Role-based access control
  • Encryption in transit and at rest
  • Customer-controlled retention
  • No customer content used to train models
  • EU region available
  • DPA available

08/Trust questions

Questions about trust and security

Plain answers to what a security and quality team asks before they bring Juncture in.

Is my content used to train AI models?
No. Your content is never used to train models. Inference runs on Azure OpenAI, and your data is not used to train or improve any shared model.
How does Juncture handle data and security?
Inference runs on Azure OpenAI and your content is never used to train models. Juncture is multi-tenant SaaS on Azure with per-tenant data isolation, an EU region available, encryption in transit and at rest, time-stamped tamper-evident audit logs, and customer-controlled retention and deletion. It is GDPR compliant, a DPA is available, and access is via SSO through Microsoft Entra with role-based access control.
Does Juncture ingest patient data, PHI or PII?
No. Juncture works on promotional content, the approved label, and public HCP-style questions. It does not ingest patient data, so there is no PHI or PII flowing through the system. Answer Monitor probes the AI engines with public questions only, never with proprietary content. The cleanest way to handle patient data is never to take it.
Is my data isolated from other customers, and can I keep it in the EU?
Yes. Juncture is multi-tenant SaaS on Microsoft Azure with per-tenant data isolation, so one customer can never see another customer content. An EU region is available for customers who require their data to stay in the EU. You control retention, and we delete your content on request.
How does Juncture handle identity and access?
Access is governed by your identity provider. Juncture supports SSO via Microsoft Entra with SAML and OIDC, and role-based access control with three roles: admin, contributor and viewer. Sign-off is restricted to the roles you assign, and every change and approval is attributed to a named user in the audit trail.
Is Juncture 21 CFR Part 11 compliant?
Juncture provides the technical controls for 21 CFR Part 11: a time-stamped, tamper-evident audit trail, e-signature sign-off, and role-based access control. You validate it for Part 11 use under your own SOPs. We do not describe Juncture as Part 11 compliant or Part 11 validated, because that determination belongs to the customer.
Is Juncture a validated GxP system of record?
No. Juncture is decision support that backs the human reviewer with a checked asset, a clear shortlist and a defensible record. It provides the supporting technical controls for Part 11, but it is not a validated GxP system of record. It is a pre-MLR pre-check layer that complements your MLR system of record, such as Veeva PromoMats or Vault, and does not replace it. You validate Juncture for Part 11 use inside your own quality framework.
Do you have SOC 2 or a live Veeva Vault connector?
Not yet. SOC 2 is in progress and not yet complete, and Juncture does not hold a SOC 2 report today. A live Veeva Vault connector, a DAM or asset-registry pull, a public API and an OpenEvidence integration are on the roadmap, not shipped. We list roadmap items separately from what Juncture provides today.
Does Juncture replace MLR or regulatory review?
No. Juncture is decision support. It backs your reviewers with a checked asset, a clear shortlist and a defensible record. The required regulatory, medical and legal review, and the accountable sign-off, stay with the people who own them and your own system of record.

Bring it to your security team

See the controls on your own asset.

Bring an asset and a brand. We will walk your team through the audit trail, the sign-off, the access model and the data path, on a live pre-check.