Regulatory status
PharmaDeux CDSS and Shield are in development. Our products do not yet carry a CE mark and have not been placed on the market; in a clinical setting they may only be used within research protocols approved by an ethics committee. The standards on this page describe the framework we use as a reference during development; unless stated otherwise, they are not a statement of certification.
Reference standards
| Standard / regulation | Scope | Status |
|---|---|---|
| EU MDR 2017/745 | Medical Device Regulation; software classification under Annex VIII Rule 11 | Class IIa target for PharmaDeux |
| Medical Device Regulation (TİTCK) | Turkish national regulation harmonised with the MDR | Reference framework |
| IEC 62304 | Medical device software life cycle processes | Architecture aligned |
| ISO 14971 | Risk management for medical devices | Architecture aligned |
| ISO 13485 | Quality management system for medical devices | On the roadmap |
| IEC 62366-1 | Usability engineering | On the roadmap |
| ISO/IEC 27001 | Information security management system | Control set target |
| HL7 FHIR R4 | Health data interoperability standard | In use |
Architecture aligned: processes and documentation are being built to the standard’s requirements. On the roadmap: implementation and certification are planned in the product’s regulatory roadmap.
MDR and positioning the software as a medical device
PharmaDeux provides information used to inform drug therapy decisions, and is designed as medical device software (SaMD) targeting Class IIa under MDR Annex VIII Rule 11. Accordingly:
- The intended use, intended users and intended patient population are defined in writing;
- Clinical evaluation is supported by literature, retrospective validation and, where needed, prospective studies;
- Risk management follows ISO 14971 throughout design;
- Post-market surveillance (PMS) and incident reporting are planned together with the product.
Shield is designed as an operational platform that supports reimbursement and pre-authorisation processes and does not produce clinical diagnoses or treatment decisions. Its regulatory classification is assessed against its final intended use.
Quality management principles
- Traceability: each requirement is linked to a design element, its implementation and a verification test.
- Verification: software changes are not released until they pass automated unit and integration tests. The PharmaDeux test suite has more than 2,480 automated tests.
- Change control: rule sets and the knowledge base are versioned; every change is reviewed and recorded.
- Deterministic behaviour: no generative or probabilistic models are used in the clinical or operational decision path; the same input with the same rule version always gives the same output.
- Human oversight: the systems produce suggestions and risk signals; the final decision belongs to the authorised user.
Information security
Our platform architecture is built on the following security principles:
- Role-based access control (RBAC) and least privilege;
- Logical isolation of each institution’s data in a multi-tenant architecture;
- Decisions and user actions kept in append-only audit logs;
- Data minimisation, and anonymisation or pseudonymisation in pilot studies;
- Encryption in transit and secure software development life cycle practices.
Security and quality reports
If you find a security vulnerability, quality issue or clinical safety concern related to our products, please report it to [email protected] with the subject line “Güvenlik / Kalite Bildirimi” (security / quality report). Reports are handled with priority.