Applications · IT and access
Scientific Rawdata stays original and complete on every GxP workstation
Quickflow ECS controls what can happen on your Windows workstations and proves it. Analysts cannot alter Scientific Rawdata, and every computer confirms live that its approved controls are in force.
- 21 CFR Part 11
- EU GMP Annex 11
- ALCOA+
- Windows 7+ and IoT
What Quickflow ECS does, in seven screens
Quickflow ECS · QC-HPLC-07 · File Explorer
ProtectedD:\CDS\Assay_B118\Scientific Rawdata
- B118_inj01.dat48 MB
- B118_inj02.dat48 MB
- B118_seq.seq48 MB
- B118_method.met48 MB
Step 1 of 7Analyst at the instrument PC
Scientific Rawdata cannot be changed
On protected folders, cut, copy, paste, rename, delete and drag-and-drop are simply not there. No menu option, no working shortcut, no prompt: the file stays exactly as the instrument wrote it.
Illustrative. Names, files and times are examples.
Quickflow ECS at a glance
Endpoint control for GxP workstations: Scientific Rawdata protected at the Windows kernel, and every control confirmed live on every computer.
- Who uses it
- QA and data integrity leads
- IT and CSV teams
- QC and production heads
- Site compliance
- What is included
- Protected Scientific Rawdata folders
- Application and USB control
- Desktop and clipboard lockdown
- Live enforcement status
- Drift detection and self-healing
- Signed, approved policy changes
- Works with
- Windows 7 and later
- Windows IoT
- Instrument and CDS PCs
- Line PCs and HMIs
- Microsoft Entra ID
- SIEM: syslog, CEF, LEEF, Splunk
- Built for
- 21 CFR Part 11
- 21 CFR 211.68(b)
- EU GMP Annex 11
- ALCOA+
Why every GxP site needs it
Data integrity is decided at the workstation
Your CDS and LIMS protect the data inside them. The files an instrument writes to Windows, and the configuration of the computer itself, are protected only by what Windows allows. Inspectors look for three gaps there.
The risk
The instrument writes its Scientific Rawdata to the Windows workstation beside it. Anyone with rights on that computer can delete, rename, cut, copy or drag those files away. The record is no longer guaranteed original or complete.
What ECS does
ECS removes cut, copy, paste, rename, delete and drag-and-drop from protected folders. There is no menu option, no working shortcut and no prompt: the file simply stays as the instrument wrote it.
Windows rights only
- Delete a Scientific Rawdata fileAllowed
- Rename an injectionAllowed
- Cut it out of the folderAllowed
- Copy and paste it elsewhereAllowed
- Drag and drop it awayAllowed
- Copy it to a USB driveAllowed
With Quickflow ECS · no prompt, nothing to try
- Delete a Scientific Rawdata fileNot available
- Rename an injectionNot available
- Cut it out of the folderNot available
- Copy and paste it elsewhereNot available
- Drag and drop it awayNot available
- Copy it to a USB driveNot available
Expected by 21 CFR 211.68(b)21 CFR 11.10(d)ALCOA+Illustrative.
Group Policy and ECS
Whatever Group Policy does, ECS does. And shows you it took effect.
Group Policy is a sound way to configure Windows. What it cannot give QA is evidence: that the control reached each computer, stayed in force, and was changed only with approval.
| What a regulated site needs | Group Policy | Quickflow ECS |
|---|---|---|
| Lock Control Panel, settings and Explorer actions | ||
| Block USB storage and other removable media | ||
| Allow only approved applications | ||
| Remove cut, copy, paste, rename, delete and drag-and-drop on Scientific Rawdata folders, with no prompt | ||
| Protect Scientific Rawdata folders, even against local administrators | Kernel level | |
| Confirm, centrally and live, that each computer applied it | Per computer, per control | |
| Put back a setting that drifted, and report it | At next refresh, unreported | |
| Second-person approval and e-signature for every change | ||
| Try a control in watch-only mode before enforcing it | ||
| Exceptions that expire on their own | ||
| Tamper-evident history of every policy change |
ECS manages the same Windows settings from its own console, so a control does not depend on a Group Policy refresh to arrive, or on someone checking that it did.
How it works
5 steps. Every one recorded.
- Step 1Policy composed from the control catalogueHuman decision
- Step 2Second person approves and e-signsHuman decision
- Step 3Policy signed and deliveredSystem
- Step 4Computer verifies the signature and enforcesSystem
- Step 5Enforcement status reported back liveSystem
At the workstation
Pick what an analyst might try. See why nothing happens.
Everyday restrictions run in user mode. The controls that protect records run in the Windows kernel, beneath the level where users and local administrators work, so they hold even when someone has full rights on the computer.
- 200+ hardening controls
- 20+ enforcement mechanisms
- 3 kernel protection layers
Not possible on this computer
Delete a Scientific Rawdata file
No Delete in the menu, and the Delete key does nothing. No prompt.
Windows kernel
Holds against local administrators and the tools they run
Tamper resistance
An administrator cannot quietly switch it off
The ECS service and its registry keys are locked against change by anyone but the system. Two components watch each other: stop one and the other starts it again, and IT is alerted.
Two components, watching each other
- Service and registry keys locked against non-system change
- Stopping either component restarts it from the other
- Kernel layers start and fail independently, so one fault does not open the others
Illustrative commands. No software control is absolute; kernel-level enforcement makes circumvention significantly harder.
Controlled rollout
Watch first. Enforce when the evidence says so.
A lockdown that stops an analyst mid-run is its own deviation. ECS lets you see what a control would do on live computers before it blocks anything, and promotes it only through an approved change.
Controls are assigned but nothing is blocked. ECS reports what each one would have stopped, so you see the effect on real work first.
- a.rao renames B118_inj02.dat
- USB drive inserted on QC-GC-02
- portable-zip.exe started on QC-UV-01
Exceptions that expire
An engineer needs USB access until 18:00. The exception is approved, scoped to one computer and ends on its own.
Maintenance windows
Controls relax for a planned window and protection is restored automatically when it closes.
Seconds to apply, seconds to reverse
Policy changes reach computers within seconds, and a change can be reversed just as fast.
Electronic records
Every policy change is a record you can defend
Who changed a control, who approved it and why is written as it happens, each entry linked to the one before it. Change a single entry afterwards and the chain shows exactly where. What analysts do on the workstation is not logged: the restricted actions are simply not available.
Policy change history · hash-chained
- #4810POL-QC-017 v4 requested · R. Shah · reason givenbf0e85
- #4811POL-QC-017 v4 approved · A. Mehta · "Approved"4f7980
- #4812POL-QC-017 v4 promoted to enforce · QC lab51ad1b
- #4813EXC-0231 USB access QC-GC-02 · until 18:00da19b9
- #4814EXC-0231 approved · A. Mehta · "Approved"e756be
Try it: edit an entry and watch every link after it fail. Illustrative.
Maker and checker
Any change that weakens enforcement needs a second person
R. Shah · IT
Requests: allow USB storage on QC-GC-02
R. Shah · IT
Tries to approve own request
A. Mehta · QA
Approves with e-signature · meaning “Approved” · reason given
Other significant actions need the actor’s own signature and a mandatory reason.
Per-record history
Who changed what, when, the previous and new value, and under whose approval.
Signatures bound to the record
Signer identity, the meaning of the signature and the time, linked to the exact change approved.
Access recertified
Scheduled reviews confirm each console user still needs their role, with a signed record of the outcome.
Regulatory fit
Clause by clause, what ECS puts in place
Each expectation regulators apply to computerised systems, and the control ECS provides for it. Your validation confirms them for your intended use.
Cut, copy, paste, rename, delete and drag-and-drop are removed from protected folders, critical file protection holds in the kernel, and backups are integrity-checked with restores proven on a schedule.
Every Digital Scientist reasons over data that begins on a workstation. ECS makes sure that data is still the original when it gets there.
How we prove itFor IT
Full capability list for IT review
Three parts: a browser console, a management server and a lightweight agent with a signed kernel driver on each Windows computer. Below, the capabilities your IT and security reviewers will ask about, searchable.
Web console
Authoring, approvals, monitoring, reports and fleet management, in the browser.
Management server
Policy engine, identity, signing authority and the audit store.
Each Windows computer
Windows 7 and later, including Windows IoT. A lightweight agent verifies and enforces; a signed kernel driver guards files, processes and network.
Down: signed policies · Up: enforcement status, events and heartbeat
Runs where manufacturing runs
- Windows 7 and every later version
- Windows IoT editions
- Instrument and CDS workstations
- Line PCs, HMIs and equipment controllers
The computers that run validated instrument and equipment software often cannot be upgraded. ECS protects them as they are.
Key capabilities
- Cut, copy, paste, rename, delete and drag-and-drop removed on protected folders, with no prompt to the userGxP
- Protected paths: delete, rename, write, folder creation, shortcut creation and move blocked in the kernelGxP
- Enforced, pending, suppressed and failed states per computer and per controlGxP
- Drift detection with automatic re-application and alertsGxP
- Discover, audit-only and enforce modesGxP
- Windows 7 and every later version, including Windows IoT editions on line PCs, HMIs and equipment
- Removable media blocking (USB drives, phones, cameras, optical drives) by device class, with an approved-device allowlist
- SIEM forwarding: RFC 5424 syslog, CEF, LEEF, Splunk HEC and JSON
Some controls depend on the Windows edition in use, the modules licensed and the integrations you choose. We confirm the exact set during implementation.
Rollout
Five steps, nothing blocked until you approve it
A typical implementation. Most sites start with one QC lab or production area, watch for a few weeks, then enforce.
Set up
Server, database and console installed, with mail, SIEM and backup connected as you choose.
Enrol computers
Agents deployed remotely or by package; placement rules put each computer in its group.
Discover
Controls assigned in watch-only mode to see their effect on live work.
Enforce under approval
Controls promoted to enforcement through signed, second-person approvals.
Evidence on demand
Dashboards, policy history and live enforcement reports answer the inspector’s questions.
Questions
Frequently asked
What QA, data integrity and IT teams usually ask first.
We already lock computers down with Group Policy. Why ECS?
Whatever you can do with Group Policy, you can do in ECS. What ECS adds is what QA needs: each computer confirms live that every control is in force, drift is put back and reported, every change is approved by a second person with an e-signature, and cut, copy, paste, rename, delete and drag-and-drop are removed from Scientific Rawdata folders without a prompt.
Can a local administrator get around it?
The controls that protect records run in the Windows kernel, below the level administrative tools work at. The ECS service and registry keys are locked, and two components restart each other if one is stopped, with IT alerted. No software control is absolute, but circumvention is significantly harder.
How does this help with our periodic review?
Your SOP still calls for a periodic review. ECS changes how it is done: instead of logging on to each workstation to compare settings with the approved list, the reviewer works from per-computer enforcement reports that show every control as enforced, pending, suppressed by an approved exception or failed, with every drift and its restoration shown.
Will it disrupt analysts in the middle of their work?
Not if you roll it out the way it is designed. Controls start in discovery mode, then audit-only, and are promoted to enforcement only by an approved change. Rollouts go in waves that stop automatically if failures pass a threshold, and exceptions and maintenance windows are time-boxed.
Which versions of Windows does it support?
Windows 7 and every later version, including the Windows IoT editions common on manufacturing and production equipment: line PCs, HMIs and equipment controllers. Computers that run validated instrument or equipment software often cannot be upgraded, and ECS protects them as they are. A few controls depend on the Windows edition; we confirm the exact set during implementation.
What happens when a computer is offline?
It keeps enforcing the last signed policy it verified. Standalone and disconnected computers are supported with offline policy and licensing.
Do we need to write scripts?
No. Policies are composed from a catalogue of more than 200 hardening controls in the console, with guided help beside each one.
What does the analyst see when an action is restricted?
Nothing. There is no error or restriction message: cut, copy, paste, rename and delete are not in the menu, the shortcut keys do nothing, and a dragged file does not move. ECS does not log what analysts try; it keeps the actions unavailable and reports that the control is in force.
Does it meet 21 CFR Part 11 and EU Annex 11?
It provides the controls both expect: restricted access, a time-stamped history of every policy change, authority checks, electronic signatures bound to their records, controlled change and continuous evidence that controls remain effective. Your validation confirms them for your intended use.
Industries
Wherever a workstation holds GxP data
Across life sciences manufacturing, laboratories and research, on every Windows computer an inspector could ask about.
Pharmaceutical manufacturing
HMIs, line PCs and batch workstations, including older and Windows IoT systems, locked to their approved use.
Biotechnology and biologics
Bioprocess and analytical PCs where one lost file can cost a batch record.
QC laboratories
Scientific Rawdata on HPLC, GC, dissolution and balance PCs kept original and complete.
Clinical and contract research
Study data held on shared computers, protected per project and per sponsor.
Medical devices
Test, inspection and production PCs under ISO 13485 and Part 11.
Any GxP operation
Wherever a regulator expects computerised systems to be controlled and proven.
Full overview: Endpoint control for GxP workstations
Instruments write their Scientific Rawdata to the Windows workstation beside them. Anyone with enough rights on that computer can delete, rename, move or copy those files, and nothing on the computer stops them. That is a data integrity gap in its plainest form: the record is no longer guaranteed to be original or complete.
Quickflow ECS closes it at the workstation. On protected folders, cut, copy, paste, rename, delete and drag-and-drop are simply not available: the analyst sees no menu option and no prompt, and the shortcut keys do nothing. Critical file protection is enforced in the Windows kernel, below the level a local administrator works at. Removable media, unapproved applications and network destinations are controlled by the same policy. ECS runs on Windows 7 and every later version, including the Windows IoT editions common on manufacturing and production equipment.
Policies are composed from a catalogue of more than 200 hardening controls, approved by a second person with an electronic signature, signed before delivery and verified by each computer before it applies them. Every computer then reports, in real time, whether each control is enforced, pending, suppressed by an approved exception or failed. Whatever you can do with Group Policy, you can do in ECS, and you can see that it took effect.
If a setting drifts, ECS puts it back and reports it. Tamper attempts are blocked and reported, and two components watch each other so that stopping one restarts it. Every policy change is approved by a second person with an electronic signature, so the periodic review of workstation configuration works from a live enforcement report rather than a visit to every computer.
IT and access
Related applications
Prove it on one lab first.
A fixed-price pilot: one QC lab or production area, a set of its workstations, six to eight weeks. We start in watch-only mode, so nothing is blocked until your QA approves it, and you decide on the evidence.