
Quality Statement
Introduction
xBxBio is developing longitudinal cardiovascular intelligence infrastructure designed to connect clinical information across systems, modalities, and time while preserving provenance, chronology, data quality, and human oversight. The platform remains in pre-commercial research and engineering development and is not currently available for clinical diagnosis, treatment, patient management, commercial access, or production deployment.
In order to allow customers of xBxBio to utilize the data and results from xBxBio to support healthcare, life science, drug discovery and research, and to minimize the time and burden on customers to validate the system prior to deployment, the application shall be developed to meet the highest quality standard and comply with all requirements from global regulatory bodies governing software applications that support discovery, development, clinical trials, and manufacturing of biologics, pharmaceuticals, and medical devices (Software-as-Drug (SaD), Software-as-Medical Device (SaMD)) using acceptable Software Platforms (SaaS).
FDA Regulatory Framework for Medical Device Software
xBxBio’s regulatory approach is intended to follow applicable FDA requirements for medical device software based on the intended use, functionality, risk profile, and regulatory classification of each product or software function. FDA’s Software Precertification Pilot Program concluded in 2022; applicable xBxBio products will therefore be evaluated against current regulatory requirements and established FDA pathways.
Total Product Lifecycle (TPLC)
xBxBio intends to apply a total product lifecycle approach in which intended use, system requirements, risk management, software development, verification, validation, cybersecurity, data integrity, change control, and post-development monitoring are addressed throughout the applicable product lifecycle. Where an xBxBio software function is regulated as a medical device, development and quality activities will be aligned with applicable FDA requirements, including the Quality Management System Regulation (QMSR), as well as relevant international standards and guidance. Artificial intelligence and machine-learning functions will be developed using documented data-management, model-development, testing, traceability, and change-control practices appropriate to the intended use and risk of the software function.
Independent Quality at xBxBio will provide appropriate oversight of software and model development activities, including requirements management, risk management, design review, configuration and change control, verification, validation, issue management, and documented release decisions. Software source code, algorithms, models, and associated configuration items will be version-controlled and subject to review and testing appropriate to their intended use and risk. Quality activities will be planned and documented so that objective evidence supports traceability from requirements through implementation and verification. Where GAMP 5 principles are applicable, they may be used as a risk-based industry framework to support computerized-system lifecycle activities; they will not be treated as a substitute for applicable regulatory requirements.
xBxBio will apply risk-based quality-management principles throughout the software lifecycle, with the level of documentation, review, testing, and assurance proportionate to the intended use and associated risk. Where GAMP 5 concepts are applicable, they may support lifecycle planning, supplier assessment, configuration management, testing, and computerized-system assurance. For software used in production or the quality management system, xBxBio will apply FDA’s current Computer Software Assurance principles to establish confidence that the software performs as intended while focusing additional rigor on higher-risk functions. Quality-by-Design principles may also be used where appropriate to support robust requirements, development controls, and continual improvement.
Validation Considerations and Approach
xBxBio will maintain documented infrastructure, software, network, database, and security controls appropriate to the intended use and risk of each applicable system or software function. Qualification and assurance activities will be planned to establish that supporting infrastructure performs as intended and that critical configurations, interfaces, access controls, backup and recovery mechanisms, and cybersecurity controls are appropriately implemented and maintained. The scope and rigor of these activities will be proportionate to risk and to the role of the supporting technology within the applicable product or quality-management lifecycle.
Risk management activities will be planned, performed, and documented throughout the applicable product and software lifecycle. Methods may include Failure Modes and Effects Analysis (FMEA) and other risk-analysis techniques appropriate to the intended use, complexity, and potential impact of the software function. Identified risks will be evaluated, appropriate risk controls will be implemented and verified, and residual risk will be reviewed. Higher-risk functions will receive proportionately greater rigor in design review, verification, validation, cybersecurity assessment, and change control. Where an xBxBio software function is regulated as a medical device, these activities will be aligned with applicable FDA requirements and recognized risk-management standards.
xBxBio will establish documented data-governance and model-development controls appropriate to the intended use and risk of each artificial intelligence or machine-learning function. Development datasets will be assessed for provenance, relevance, completeness, quality, representativeness, and potential bias. Training, tuning, and test datasets will be separated where appropriate, and model performance will be evaluated using predefined acceptance criteria and clinically or scientifically meaningful metrics. Verification and validation activities will assess performance under relevant conditions of use, including robustness, repeatability, limitations, and reasonably foreseeable sources of error. Where deployed models may change over time, monitoring, retraining, change control, and re-evaluation activities will be defined and documented. For regulated AI-enabled device software functions, these activities will be aligned with applicable FDA requirements and recognized Good Machine Learning Practice principles.
xBxBio will implement access controls, authentication, authorization, auditability, data-integrity safeguards, and other security controls appropriate to the intended use and risk of each system or software function. Where electronic records or electronic signatures are subject to applicable regulatory requirements, xBxBio will design and test the relevant controls against those requirements. This may include 21 CFR Part 11 for FDA-regulated electronic records and signatures and, where applicable within EU GMP-regulated activities, EudraLex Volume 4 Annex 11 for computerized systems. Applicability will be determined based on the intended use, regulated activity, jurisdiction, and underlying recordkeeping requirements rather than assumed universally.
Conclusion
xBxBio intends to apply a total product lifecycle approach supported by defined quality-management, risk-management, software-development, verification, validation, cybersecurity, data-integrity, and change-control processes. Where an xBxBio product or software function is subject to medical-device regulation, applicable quality-system and regulatory requirements will be incorporated into the lifecycle based on the product’s intended use, risk, classification, and jurisdiction. For U.S. medical devices, the Quality Management System Regulation (QMSR) is now effective and incorporates ISO 13485:2016 into 21 CFR Part 820. U.S. Food and Drug Administration
xBxBio remains in pre-commercial research and engineering development. Its quality and validation framework is intended to generate documented evidence supporting system requirements, software assurance, risk controls, traceability, and release decisions as the technology matures. Validation and regulatory evidence will be developed and maintained for the specific intended use and applicable regulatory pathway rather than treated as a universal, prevalidated package. Where computer software is used within production or quality-management activities, xBxBio intends to apply risk-based software-assurance principles consistent with current FDA guidance. U.S. Food and Drug Administration