AI software engineering company

Products.
Expertise.
Partnership.

DASLAB publishes its own AI software, works as an engineering partner inside client systems, and stays with them from design through to operation.

What we do

Three ways to work together.

01

Products

We publish our own software and we operate it. It is built under the same engineering rules we apply inside our clients' systems.

See the products
02

Expertise

Architecture, applied AI, data, security. We work where the engineering question and the compliance question cannot be answered separately.

See the approach
03

Partnership

Integration, validation, maintenance in an operational state. A critical system is not delivered — it is held, release after release.

See the method

Products

Three systems, in service or under construction.

They currently serve the pharmaceutical industry — the ground where traceability, validation and audit constraints bite hardest. Each one answers a friction we met in the field before deciding it was worth writing software for.

01

ATLAS RPMS

Regulatory Affairs orchestration

Technical foundation delivered and runningBusiness modules rolling out

The problem

A regulatory portfolio lives across dozens of spreadsheets, inboxes and systems that do not talk to each other. At any given moment nobody can say which requirement is blocking which submission in which market.

The principle

ATLAS is neither a RIMS nor a document management system. It is the orchestration layer above them: procedure clocks, requirements, health-authority questions, and the dependencies between projects.

The mechanics

  • Date engine: EMA and FDA procedure clocks, milestones, public holidays, cascading recalculation.
  • Requirement management with a reusable library and a traceability matrix.
  • Health-authority question knowledge base, searchable semantically.
  • Role and department views, assignment rules, configurable alerts.
  • Strict multi-tenant isolation through PostgreSQL Row-Level Security.
02

EMILE

Augmented regulatory authoring

Specified and presented to executive committee

The problem

Module 3 data lives scattered: LIMS results, batch records, scanned certificates of analysis, stability reports, ERP specifications. Copying it by hand is slow, error-prone, and breaks the link back to the source.

The principle

Ingest and normalise that data once into a typed, versioned repository bound to its source evidence — then project the repository into the dossier. Authoring becomes a projection rather than a transcription.

The mechanics

  • Ingests LIMS, documents, OCR-scanned PDFs, ERP and MES into a single structure.
  • Every attribute becomes a typed, versioned object linked to its source (ALCOA+).
  • Deterministic coverage of 3.2.S and 3.2.P sections; QOS 2.3 synthesised.
  • Propagation: a shelf life moving from 24 to 36 months updates 3.2.P.8.1, 3.2.P.8.3, 3.2.P.1, Module 1 and the QOS — with change tracking on.
  • Clinical documents — IND summaries, PIP outline, CSR from TLFs — on the same engine.
03

FACTOTUM

A private assistant for every employee

In production

The problem

Enterprise assistants are either chat interfaces with no memory, or services that assume you will export your company's data to a third party. Neither holds up in a regulated environment.

The principle

One private agent per employee, an orchestrator for leadership, and a shared company brain in versioned markdown. The whole thing runs on the client's own infrastructure and cloud contract.

The mechanics

  • Runs at the client: Bedrock or Vertex on their existing contract, Microsoft 365, their domain — no new third-party account to open.
  • Teams, email and web chat surfaces; onboarding an employee takes a single message.
  • Two-layer memory: shared upward, and private by construction — the private layer is never mounted for peers.
  • Commitment engine, inbox triage, meeting preparation.
  • Licensed distribution as closed images; source code never leaves DASLAB.

AI drafts, humans decide. The agent writes, sorts, reminds and prepares — it approves nothing and sends nothing on its own.

The rest of the range

Two systems specified on the same foundation.

C-GUARD

IDMP / xEVMPD compliance audit

Connects read-only to a RIMS, tests its data against the five ISO IDMP standards and the controlled vocabularies, scores every gap by severity and by product-market, then delivers a prioritised remediation plan. A repeatable, schedulable audit where a manual review is partial and out of date the moment it ends.

VALIA

Computer system validation

Learns a system from its documentation — user guides, SOPs, URS — derives an executable action map, then actually drives the target interface, capturing each step as timestamped evidence. The GAMP 5 pack assembles during the test: VMP, RTM, IQ/OQ/PQ protocols and reports.

Shared foundation

Designed once, reused everywhere.

The products share one foundation. That is what makes compliance consistent from system to system, and what keeps a new module from becoming new validation debt.

GxP compliance by design

21 CFR Part 11 and EU Annex 11: audit trail, electronic signature, version control, ALCOA+ — in the data model, not bolted on top.

Document ingestion

Multi-format engine with OCR and language processing, shared across the range to read any source.

System connectors

RIMS, LIMS, MES, QMS and ERP over API. Read-only for audit, read-write for authoring — never the reverse by default.

AI governance

Per-client data isolation, decision logs, explainability, encryption. A decision made by an agent has to be replayable and explainable.

Partnership

From design through to operation.

Four stages, and the same traceability standard at each one. A critical system is not delivered — it is held over time.

  1. 01

    Framing

    User requirements, architecture decisions, data model, validation scope. We deliberately spend time here: vagueness at this stage is paid back much further down the line.

  2. 02

    Build

    Development and testing under systematic human review. Nothing counts as delivered until code review and functional review have both passed.

  3. 03

    Validation

    Validation plan, functional and design specifications, traceability matrix, IQ/OQ/PQ protocols and reports. Timestamped evidence generated at execution.

  4. 04

    Operation

    Maintenance in a validated state: every change replays the portion of validation it touches. A fix is not shipped until its evidence is.

Compliance & security

What is wired, and what is under way.

We separate the two explicitly. It takes longer to write than a certification badge, but it is what survives due diligence.

Wired06
Immutable audit trail
Every write is traced, timestamped and non-editable.
21 CFR Part 11 electronic signature
Wired onto requirement, health-authority question and change-control approvals.
Multi-tenant isolation
PostgreSQL Row-Level Security — isolation enforced by the database, not by the application.
Strong authentication
Mandatory MFA / TOTP, Argon2 hashing, account lockout, session management.
Traceability matrix
Kept current, bound to requirements and tests.
GAMP 5 category 5
Methodology applied across the development cycle, human review at each gate.
Under way04
ISO/IEC 27001
Programme under way — scope, statement of applicability, risk assessment and asset register produced. Certification targeted, not held today.
Formal validation pack
IQ/OQ and Part 11 / Annex 11 mapping being assembled.
External penetration test
Scheduled as part of the security programme.
GDPR — data processing agreement
DPA and quality agreement being drafted.

Contact

Let's talk about your constraint, not our product.

Thirty minutes is usually enough to know whether we are useful — and to say so plainly if we are not.