Pharmaceutical and life sciences

SCADA Software for Pharmaceutical Manufacturing

Environmental monitoring, batch and the electronic record, from one platform.

Request an Evaluation See Part 11, requirement by requirement
In short

FrameworX is a SCADA and HMI platform used in pharmaceutical manufacturing for environmental monitoring in classified areas, batch and equipment supervision, and the electronic record that supports them. It includes the technical controls FDA 21 CFR Part 11 asks of a computerised system: individual authenticated accounts with LDAP, role-based access, electronic signatures with configurable meanings, and a secure audit trail written to SQL with server-side timestamps and configurable retention. Separate Development, Validation and Production execution profiles keep a validated environment intact while work continues, and published runtime files are read-only. Compliance is a property of your validated installation, not of a software product, so Tatsoft publishes the configuration guides rather than a compliance claim.

In a regulated plant, the record is part of the product

A pharmaceutical plant does not only have to make the product correctly. It has to be able to show, years later and to somebody who was not there, that it did. The batch record, the environmental data behind a sterile release, the audit trail of who changed what and when: these are not reporting by-products. They are what the product is released against.

That changes what the supervisory system is for. It has to collect continuously and lose nothing when a server or a network link fails, because a gap in the environmental record for a classified area is a gap in the release evidence. It has to attribute every action to a named person, and keep that attribution beyond the moment the person logs off. It has to let quality and production see the same data without either one being able to edit it. And it has to allow the plant to be modernised area by area, because taking a qualified system apart to replace it is a validation cost measured in months.

None of that is unusual engineering. What is unusual is that the evidence has to survive the audit, and that is a different design target from an efficient control system.

What FrameworX does in a regulated plant

Environmental monitoring in classified areas

Continuous collection of temperature, humidity, differential pressure and particle counts, with alarming on excursion, trending with annotations, and the archive that a sterile release is assessed against. Derived statistics such as mean kinetic temperature are built as custom calculations and historised alongside the measured values, rather than being rebuilt by hand for each report.

An audit trail you configure rather than inherit

The audit trail is written to a SQL database and captures the user, a server-side timestamp, the message and the originating condition. You choose which classes of event are audited: logon and logoff, display open and close, remote connections, tag changes, dataset save and load, operator actions, report saves and system warnings. Retention is set in days, so a seven-year retention is a configuration value rather than an add-on.

Electronic signatures with a stated meaning

Signature capture can be required on any individual control in a display, with a configurable session timeout after which the system prompts for the password again. The meaning of the signature is configured with it, so the record carries reviewed by, approved by, verified by or released by rather than an anonymous confirmation.

Individual accounts, and a policy that enforces them

Authentication through LDAP or the platform's own directory, with roles that separate administrator, supervisor, operator and read-only inspector. Password minimum length, history, minimum and maximum age, blocking after failed attempts, forced change at first login and automatic log-off after inactivity are policy settings, not scripts somebody has to maintain.

Development, Validation and Production kept apart

Execution Profiles hold three separate environments in one project, each with its own database connections and its own read-only module settings, so validation work does not run against production data and production does not inherit a development setting. Moving between them does not require editing the configuration by hand, which is the step that usually introduces the difference nobody documented.

A published runtime that cannot be edited in place

Build and Publish produces a read-only runtime file for production, with major and minor versioning. Alongside it, Track Changes keeps recent changes, configuration versions, cross-references and use counts, which is the raw material of a change-control record.

A complete record when a server or a link fails

Redundancy is available as a licensed option. In a hot-standby pair the standby server holds the solution loaded with its modules paused, receiving synchronisation from the active server, and takes over automatically in about a second without custom engineering. Separately, the historian's Store and Forward buffers readings when its storage destination is unreachable and writes them through when it returns, so the archive is continuous rather than carrying a hole where the interruption was.

Reports in the formats an inspector accepts

Scheduled and on-demand reports in PDF and XPS, combining historised values, operator-entered data, trend charts and signature information, saved to a path with a timestamp or triggered from a script. Printed copies are produced from the same report.

Connectivity for pharmaceutical plants

A pharmaceutical site is rarely one generation of equipment. Qualified skids stay in service for decades, and the platform has to speak to what is installed rather than to what is current.

FrameworX includes more than 100 native connectors. The ones this sector reaches for:

  • OPC UA, client and server, for qualified skids and packaged equipment
  • Allen-Bradley (ControlLogix, MicroLogix, SLC, PLC5), Siemens S7, Modicon, Omron
  • Modbus TCP and RTU, for instruments and older skid controllers
  • BACnet, for the HVAC that holds the classification of a clean room
  • MQTT and Sparkplug B, both directions, with a built-in broker
  • SQL databases, for LIMS, MES and ERP integration
  • Historian, native to the platform, with a separate connector available for Canary if a site already runs one

Connectors are included in the license rather than sold per protocol, which matters on a site where a single new skid can otherwise trigger a procurement cycle.

Part 11, requirement by requirement

What the regulation asks of a computerised system, and the FrameworX feature that carries it. The full 27-item table, with the configuration steps, is published in the documentation.

What Part 11 requiresReferenceIn FrameworX
Validated system, per FDA and GAMP guidancePart 11Execution Profiles for Development, Validation and Production, plus Build and Publish
Password change at first accessPart 11Security policy setting
Electronic copies of records for review11.10(b)Reports saved as PDF and XPS
Printed copies for audit11.10(b)Printing from the same report
Records available for as long as needed11.10(c)Configurable retention
Archiving of generated data11.10(c)Historian module, native to the platform
Role-based access control11.10(d)Security module, roles and groups
Unique identification of each user11.10(d)Individual accounts, LDAP or platform directory
Minimum password length11.10(d)Policy setting, eight characters or more
Password expiry and reuse history11.10(d)Policy settings for age and history
Account blocking after failed attempts11.10(d)Policy setting for invalid attempts
Session timeout on inactivity11.10(d)Automatic log-off, inactivity and session duration
Audit trail of creation, change and deletion11.10(e)Audit trail in a SQL database
Electronic records cannot be deleted11.10(e)Alarm and database module configuration
Audit entries carry date, time, user and what changed11.10(e)User, timestamp, message and condition columns
Audit trail retained as long as the record11.10(e)Configurable retention in days
Timestamps taken from the server11.10(e)Server time enforced
Process actions captured in the audit trail11.10(e)Alarm and dataset modules
Monitoring of user activity11.10(e)Native to the platform
Audit trail reports, electronic and printed11.10(e)PDF and XPS report generation
Control of the sequence of operations11.10(f)Dataset module and scripting
Signature carries full name and signing time11.50(a)Electronic signature with user and timestamp
Signature carries the action it represents11.50(a3)Configurable signature meanings in audit messages
Signature shown in printed and electronic form11.50(b)Reports module
Signatures unique to one person11.100(a)Security module enforcement
Signature history kept after logoff11.200(a2)Datasets module
Signature bound to its record and not transferable11.200(a2)Security and datasets integration
Control actions taken by an AI agent are audited11.10(e)Custom Tool audit category, on by default. See below

Each line here maps to a configuration step in the FDA 21 CFR Part 11 configuration guide, which is public and does not require an account. The related security hardening guide and IEC 62443 configuration guide sit alongside it.

What we claim, and what we do not

A software product cannot make your installation compliant, and any vendor who says otherwise is describing something that does not exist.

There is no FDA approval for a SCADA platform. Part 11 compliance is a property of a validated computerised system in a specific plant, running a specific configuration, under specific procedures. It is assessed at the level of your solution, and it is yours.

What Tatsoft provides: the technical controls the regulation asks for, listed above and documented line by line; the configuration guides that show how to set them; and the validation documentation structure, from user requirements through installation, operational and performance qualification to the traceability matrix, that a qualification effort is built around.

What has been built on it: applications validated under 21 CFR Part 11 at solution level, in production, in regulated plants.

What we hold: a Veracode assessment at source-code level, carried out at the request of a pharmaceutical customer.

We do not claim that FrameworX is certified for 21 CFR Part 11, approved by the FDA, or compliant on installation. Those claims would not survive the first question from a data integrity specialist, and they are not true.

AI in a regulated plant, and how it stays in the record

The question a regulated plant asks about AI is not whether it is useful. It is what happens to the record when a model acts.

FrameworX is AI-Native by architecture. Model Context Protocol servers for the Designer, the Console and the Runtime, plus an in-process AI agent spine, released and supported in FrameworX 10.1.5, connect an AI model of your choosing to the engineering project and to the running solution. An engineer can describe a display, a report or an alarm set and have it built, reviewing and approving every change before it runs.

The part that matters here is what the platform does when an agent acts on a running system. FrameworX 10.1.5 adds a dedicated audit category for AI-driven control actions. When an external AI client invokes a Custom Tool that your solution author wrote, the platform emits an audit row carrying the tool name, the full arguments, the caller chain, the connected user and the result status. Read-only queries are not logged, because reading a value is not a regulated control action; executing a Custom Tool is, under 11.10(e). The audit gate is a setting in the alarm module's global settings, and it is on by default.

The design point underneath it is that an AI client does not get open access to your tags. Solution authors write Custom Tools in .NET that expose exactly the operations they intend, with validation in their own code, so the model asks for the current differential pressure in Suite 2 rather than being handed the tag database. What the model can do is what somebody deliberately wrote and what your role model permits.

The model runs where you decide. FrameworX ships no model and no model weights. It connects over an OpenAI-compatible endpoint to a model you run, on a separate networked machine of your own, or to a hosted one. The model host is deliberately not the FrameworX server: the two are separate machines, which keeps model workload off the supervisory server and keeps the boundary between them explicit. Once the model is on that host it needs no internet connection, so a plant that will not send process data outside its own network can run the whole thing inside it.

Batch, and the equipment model underneath it

A batch record is only as good as the equipment model it is written against. If the system does not know that a mixer belongs to a process cell that belongs to an area, the batch context has to be reassembled by hand every time somebody asks a question about it.

FrameworX models equipment to the ISA-88 hierarchy, from enterprise through site, area, process cell and unit to equipment module, and carries a live batch and its operations against that structure. The reference model is imported from a standard ontology file rather than rebuilt by hand, and the namespace materialises the typed objects and tags from it. Operator displays then drill from a plant overview into a cell schematic and into an individual unit, and the batch context follows.

A worked wet-granulation example, with a mixer and a reactor under a process cell and a batch executing two operations, ships with FrameworX 10.1.5 and is documented publicly. It includes a server-side anomaly monitor that asks the local model for a short narrative when a monitored value crosses its threshold, and pins that narrative to the alarm and to the trend chart, so a shift handover three hours later still sees what happened and why rather than an unexplained excursion.

The same pattern applies to any reference model a site already uses, ISA-95 or a corporate asset model included.

In production

Hikma Pharmaceuticals, sterile environmental monitoring

Hikma replaced a closed graphic chart recorder system whose data sat in a proprietary structure and needed a separate product to read. The requirement was a validated system for monitoring, alarming, trending and reporting environmental sensors in sterile areas, subject to Part 11 controls including audit trails, password policy and electronic record verification with signatures.

FrameworX was selected for its integrated historian, the Part 11 technical controls, the open .NET scripting environment, trending with custom calculations and statistics including mean kinetic temperature, a client-server model that made remote access economical, redundancy, and native drivers that avoided hardware vendor lock-in. The result replaced physical chart recorders with electronic records, opened the recorded data to quality and planning through SQL and historian APIs and to other systems through OPC UA and MQTT, and produced the reports in PDF and XPS.

"FrameworX easily and cost effectively allowed us to handle many use cases and requirements that are hard and/or expensive to implement with other SCADA packages. It also contains multiple tools and interfaces for creating a modern flexible and open architecture system. The SCADA world is not just about working with PLC/Controllers anymore. FrameworX is built to integrate information from smart sensors, MES, ERP, and cloud. With its native .NET scripting, built-in drivers and data connectors, it allowed us to accomplish this without the need for third-party add-ins."

Richard Benamy, Controlware

System integrator: Controlware, LLC.

Read the Hikma case study

Common questions

What does 21 CFR Part 11 require from a SCADA system?

Part 11 governs electronic records and electronic signatures in FDA-regulated production. It requires that records be attributable, legible, contemporaneous, original and accurate, that changes be captured in a secure audit trail, that access be controlled by authenticated individual accounts, and that electronic signatures be linked to the records they approve. In a SCADA system that means individual named accounts rather than a shared operator login, an audit trail written where the operator cannot edit it, timestamps taken from the server, retention that outlasts the record, and signatures that carry both the signer and the meaning of the signature.

Does FrameworX support electronic signatures and audit trails?

Yes. Electronic signature can be required on any individual control in a display, with a configurable timeout after which the platform prompts for the password again, and the signature meaning is configured with it so the record shows reviewed by, approved by, verified by or released by. The audit trail is written to a SQL database with the user, a server-side timestamp, the message and the originating condition, and you choose which classes of event are captured, from logon and tag changes to operator actions and report saves. Authentication runs through LDAP or the platform's own directory, and role-based access control governs who can view, command and configure.

What is an audit trail in pharmaceutical manufacturing?

An audit trail is a secure, time-stamped record of every action that creates, modifies or deletes a regulated record, showing what changed, who changed it and when. It cannot be edited by the people it records. In practice it is what an inspector reads to establish that a batch record reflects what actually happened. The properties that make it hold up are that its timestamps come from the server rather than a workstation clock, that deletion is prevented rather than discouraged, and that it is retained at least as long as the record it describes.

Can SCADA support environmental monitoring in sterile areas?

Yes. Environmental monitoring systems track temperature, humidity, differential pressure and particle counts in classified areas, alarm on excursions, and hold the record for release. FrameworX supports these applications with continuous data collection, redundancy, integrated historian and configurable alarm handling, and derived statistics such as mean kinetic temperature are built as custom calculations and historised alongside the measured values. Hikma Pharmaceuticals uses it for sterile environmental monitoring, replacing a chart recorder system with electronic records.

How is data integrity maintained during a network or server failure?

Two mechanisms cover two different failures. For a server failure, redundancy is available as a licensed option: in a hot-standby pair the standby holds the solution loaded with its modules paused and synchronised from the active server, and takes over automatically in about a second without operator intervention and without custom engineering. For a storage or network interruption, the historian's Store and Forward buffers readings locally and writes them through when the destination is reachable again, so the archive is continuous rather than carrying a gap. For a regulated plant the gap is the whole problem, because environmental data with a hole in it does not support a release.

Does modernizing a SCADA system mean revalidating the entire process?

Not necessarily. Validation scope depends on which functions change and on how the system is qualified, so a phased migration that leaves the process control layer intact typically has narrower validation impact than replacing everything at once. FrameworX supports that shape of project directly: Execution Profiles hold separate Development, Validation and Production environments in one project so new work is built and tested without touching the qualified environment, and control stays in the PLCs while the supervisory layer is replaced area by area. The scope still has to be assessed against the specific installation and its existing qualification.

If an AI agent can act on the system, how is that captured under Part 11?

As an audited control action. FrameworX 10.1.5 adds a dedicated audit category for AI-driven actions: when an external AI client invokes a Custom Tool written by the solution author, the platform emits an audit row carrying the tool name, the full arguments, the caller chain, the connected user and the result status. Read-only queries are not logged, because reading a value is not a regulated control action, while executing a Custom Tool is, under 11.10(e). The audit is on by default. The AI client does not receive open access to the tag database: it can invoke only the tools the solution author deliberately wrote and only what the connected user's role permits.

Is FrameworX certified for 21 CFR Part 11?

No, and no SCADA platform is. There is no FDA approval or certification for a software product of this kind. Part 11 compliance is assessed for a validated computerised system in a specific plant, running a specific configuration under specific procedures, and it belongs to the plant. What a platform can provide is the technical controls the regulation asks for, the documentation showing how to configure them, and the validation documentation structure a qualification is built around. Tatsoft publishes all three, and applications built on FrameworX have been validated under 21 CFR Part 11 at solution level in production.

Does FrameworX support ISA-88 batch and equipment models?

Yes. Equipment is modelled to the ISA-88 hierarchy, from enterprise through site, area, process cell and unit to equipment module, with a live batch and its operations carried against that structure. The reference model is imported from a standard ontology file rather than rebuilt by hand, and the namespace materialises typed objects and tags from it. A worked wet-granulation example with a mixer and a reactor under a process cell ships with FrameworX 10.1.5 and is documented publicly. The same pattern applies to ISA-95 or to a corporate asset model.

What validation documentation does a Part 11 project need, and what does Tatsoft provide?

A qualification effort is normally built around a user requirements specification, a functional requirements specification, a design specification, installation, operational and performance qualification protocols, a traceability matrix, and standard operating procedures for user management, password management, audit trail review, backup and recovery, change control, electronic signature and system validation. Tatsoft publishes the configuration guide that maps each Part 11 requirement to the platform feature that carries it, together with the security hardening guides, so the traceability matrix can be built against documented behaviour. The qualification itself is executed by the plant or its integrator.