Compliance

Validated, not just tested.

Testing tells you a system works. Validation shows it — to the regulator, the auditor or the operator who has the authority to ask. We engineer systems to the standard that applies, and hand over the evidence.

Standards

The standards we build and validate to.

Healthcare, life sciences, payments, industrial control systems and any system exposed to the internet.

HIPAA

US health information privacy & security

Healthcare platforms that handle protected health information — access control, encryption, audit logging and the boundaries between systems.

21 CFR Part 11

FDA electronic records & signatures

Systems whose electronic records and signatures must be trustworthy — audit trails, e-signatures, access control and documented validation.

GxP

Good practice in regulated life sciences

Computerised systems validation for clinical, laboratory and manufacturing contexts.

PCI DSS

Payment card data security

Security assessment of payment-facing and partner-facing APIs.

IEC 62443

Industrial automation & control system security

OT and SCADA security: risk assessment, zones and conduits, security levels, secure remote access and cryptography for industrial networks.

OWASP

Application security testing

Vulnerability assessment and penetration testing of web, mobile and API surfaces.

Your policy

Internal & operator standards

The rules an operator or enterprise sets for itself — mapped into testable requirements like any regulation.

What we do

From risk register to audit-ready.

Compliance designed in during Discover, built in during Build, and demonstrated in Prove.

Security

Security testing

Finding the weaknesses before someone else does.

  • Penetration testingOWASP-based assessment of web, mobile and API surfaces.
  • API securityAuthentication, authorisation and data exposure in payment and partner APIs, to PCI DSS.
  • Findings you can act onSeverity-ranked results with clear remediation guidance.
  • RetestConfirmation that fixes actually closed the gap.
OWASP · Burp Suite · PCI DSS
Industrial

OT & ICS security

Securing the systems that run plants, pumps and utilities, where availability comes first.

  • Risk assessment & zoningAssets, threats and consequences mapped, the network divided into zones and conduits, and a target security level set under IEC 62443.
  • SCADA & PLC protectionLeast-privilege access, two-factor sign-in and role-based control across the supervisory, telemetry and controller layers, with monitoring and alerting.
  • Secure remote accessAuthenticated, logged access to remote assets in place of flat VPNs and on-site servers.
  • Cryptography & legacy devicesIT/OT segmentation, encrypted industrial links and key management, including instruments that can’t be replaced.
IEC 62443 · SCADA · PLC · IT/OT segmentation
Regulated

Regulated validation

Showing a system does what it claims, in the form a regulator expects.

  • Validation planningScope, risk assessment and the approach to demonstrating fitness for use.
  • Traceable requirementsEvery requirement linked to the test that proves it.
  • Audit trails & e-signaturesEngineered into the system, then verified.
  • Validation documentationExecuted tests, results and sign-off, organised for review.
HIPAA · FDA 21 CFR Part 11 · GxP
Assurance

Automated assurance

Keeping a validated system validated as it changes.

  • Regression automationPlaywright and TypeScript suites in CI/CD — 95% automation coverage on delivered work.
  • Performance & loadLoad testing to show the system holds up, including on core banking systems.
  • Quality gatesReleases blocked when evidence is missing.
  • Governed AIWhere AI is part of the system, its outputs are gated and logged. AI governance →
Playwright · TypeScript · JMeter · CI/CD

Evidence

What you hold at handover.

The difference between “we tested it” and “here is the proof”.

Risk & compliance register

The obligations that apply, the risks identified — for industrial systems, the zones and conduits — and how each was addressed.

Traceability matrix

Requirements mapped to design, tests and results.

Test evidence

Executed test records, automated reports and security findings with retest results.

Audit trail design

What the system records, where, for how long, and who can see it.

Operating documentation

Runbooks, monitoring and recovery procedures legible to the team that owns it.

Change control

How future changes are assessed, tested and approved without losing validation.

Your system carries the certification. We engineer it to the standard and hand you the evidence that proves it — the standards above are not certifications held by Pramilia. Where a standard has a formal certification, as IEC 62443 does, an accredited body issues it; we prepare the system and the evidence for it.

Facing an audit, a tender or a regulator?

Tell us the standard and the system. We’ll tell you what it takes to prove it.

Start a conversation