An audit trail that can
prove it wasn't touched.
Most systems that claim to have an "audit trail" just mean a log table in a database — editable by anyone with admin access, with no way to prove it wasn't altered. ValiCore's audit trail is hash-chained: each entry cryptographically links to the one before it, so any tampering is mathematically detectable.
What is an audit trail in pharma, and does Excel have one?
An audit trail is a secure, computer-generated, time-stamped record of every operator action that creates, modifies, or deletes an electronic record — required under 21 CFR Part 11 §11.10(e) to independently record who did what and when, without ever obscuring the original data. Excel does not have this. Its "Track Changes" feature is optional, can be disabled or bypassed, doesn't capture user identity reliably, and isn't tamper-evident — anyone with edit access can silently change a cell and no trace survives unless Track Changes happened to be on and unmodified.
Built for
What goes wrong without it
Shared logins erase accountability
Shared login credentials are cited as the single most frequent ALCOA+ violation in FDA 483 observations — because a shared account makes it impossible to attribute an action to a specific individual, which is the entire point of an audit trail.
A log that can be edited isn't an audit trail
If a database administrator (or anyone with sufficient access) can open a table and change a row, that table is not tamper-evident — it's just a record that hasn't been tampered with yet.
"We'll reconstruct it during the audit"
Manual reconstruction of who-did-what from emails, sign-in sheets, and memory is exactly the scenario that turns a routine inspection into a Form 483 citing data manipulation.
What ValiCore actually does here
Hash-chained, tamper-evident log
Every entry's hash incorporates the previous entry's hash — altering or deleting a past record breaks the chain in a way that's independently verifiable, not just claimed.
21 CFR 211.68 · §11.10(e)One-click chain verification
A built-in verification tool re-derives the entire hash chain on demand and reports exactly where — if anywhere — it breaks, with the result exportable as audit evidence.
Individual e-signatures, never shared logins
Every signing event captures the individual's identity, the timestamp, and the signature's meaning (approved, reviewed, rejected) — the exact structure §11.10(e) requires.
21 CFR Part 11 Subpart CBefore/after values captured on every change
Field-level before/after snapshots on every update — not just "record was modified," but exactly what changed.
Documented, auditable chain breaks
If a chain break is ever legitimately documented (e.g. a data-recovery event), it's sealed forward with a signed, reasoned record — the break stays visible and explained, never silently hidden.
Exportable in standard formats, on demand
The full audit trail is exportable as PDF or CSV at any time — no gatekeeping, no waiting on a vendor support ticket to produce evidence for an inspector.
Regulations this addresses
Related modules
Frequently asked questions
No, not in its standard configuration. Excel's Track Changes is optional, can be turned off, doesn't reliably tie changes to authenticated individual users, and isn't tamper-evident — someone with edit access can disable tracking, make a change, and re-enable it with no trace. §11.10(e) requires a trail that independently and securely records every create/modify/delete action; a spreadsheet doesn't meet that bar without extensive, fragile custom controls layered on top.
Under §11.10(e): a secure, computer-generated, time-stamped audit trail that independently records the date, time, and nature of operator entries and actions that create, modify, or delete electronic records — with previously recorded information never obscured, and the trail retained for at least as long as the record itself and available for FDA review and copying on request.
Each audit log entry includes a cryptographic hash computed from its own data plus the hash of the entry immediately before it. If anyone alters or deletes a past entry, every hash computed after that point stops matching — the tampering is detectable by re-computing the chain, not just assumed based on trust in the system administrator.
See ValiCore
live in your lab.
Book a free 30-minute demo. We’ll walk through the modules your team will use, answer your compliance questions, and give you a clear picture of what implementation looks like for your lab.
Book your free demo
30 minutes. No credit card. We’ll respond within 4 business hours with a calendar invite tailored to your time zone.
Book my free demo35 working modules · Founder-led onboarding · 14-day go-live guarantee