Compliance & security

Recovery you can defend at audit

Device recovery in a regulated setting isn't done when the box arrives — it's done when you can prove what happened to every unit. Divolvi builds that evidence automatically, as work gets done.

What's built in

Compliance as a byproduct of the workflow

You don't bolt these on at the end — they accumulate as outreach, shipping, receipt and assessment happen.

PHI-wipe certificates

Every device that could carry patient health information gets a sanitization attestation aligned to FDA and NIST media-sanitization guidance, generated per unit and tied to its record.

Immutable audit log

Site edits, deployments, shipments, assessments and certificates are all logged. Audit records survive even trial deletion via name snapshots, so history never disappears.

Chain of custody

From label creation to carrier-verified delivery to warehouse receipt, each hand-off is timestamped, and establishing a defensible custody trail for every box and device.

Value of record

Recovered devices carry an approved condition assessment and valuation, so financial and compliance reporting rests on a single, auditable source of truth.

Multi-tenant isolation

Every partner's trials, sites and devices are strictly scoped. Access is role-based — administrators see the full portfolio; operations users are limited to their assigned sites.

Exportable evidence

Compliance certificates and audit records export cleanly for internal QA, sponsor requests, or regulatory review. No scrambling to reconstruct a paper trail.

Standards we align to

Divolvi’s sanitization attestations and record-keeping are designed around the frameworks device and pharma teams are already accountable to.

FDA medical-device guidance
NIST 800-88 media sanitization
HIPAA-aware PHI handling
Role-based access control