Skip to main content

Help us improve the Digital Marketplace - send your feedback

CODESPLICE LTD

TraxQM - Risk based Quality Management System for regulatory compliance

Validated Risk based Cloud SaaS Quality Management system, digitising quality processes to meet data integrity and regulatory compliance. Ex-inspectors endorsed, Document management with AI reviews and collaboration, management of Deviations, Complaints, CAPA and Risks, Change Control management, Risk based Audits, Asset tracking, integrated Customer and Supplier verification and LMS Training.

Features

  • AWS hosting, SharePoint hosting for secure, compliant, saleable eQMS operations
  • Secure user access via Azure Entra ID SSO support
  • EU GMP Annex-11, DocuSign CFR 21 Part 11 compliant
  • Automated document versioning with single or multiple user approval workflow
  • Automated review cycles for Risk reviews, Supplier validation, SOP reviews
  • AI assisted document reviews, AI assist for controls and KPIs
  • Audit trail records, time stamps for critical actions
  • MHRA Integration, GPhC intergations, Edura Integration for supplier approval
  • User-based access control, Role based user control for fast onboarding
  • Unlimited storage, unrestricted retention for collaboration and scalable content management

Benefits

  • Risk based Quality Management System (eQMS), risk management for compliance
  • Risk based workflows addresses common regulatory deficiencies
  • Built-in Audit reviews, built-in Management reviews for continuous improvement
  • 5 ways Root Cause Analysis for Corrective and Preventative actions
  • Real-time dashboards and real time compliance reporting for management
  • Workflow designed with expert oversight to ensure quality and compliance.
  • Learning management system for courses, training records, competence assessment, reports
  • Task management oversight, tasks reallocation features, team's manager tasks overview
  • Notification based colloboaration, task based collaboration, for team collaboration
  • Automated reminders for document reviews, risk reviews, supplier re-validation

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@codesplice.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 6 9 6 5 6 3 3 0 7 4 2 0 8 0

Contact

CODESPLICE LTD Hitesh Kothari
Telephone: +44333 444 3150
Email: info@codesplice.com

About your service

Service categories

Applications

Content workflow and management

  • Document

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
TraxQM has been tested on Google Chrome & Microsoft Edge browsers. Compatibility with other browsers is not guaranteed.
System requirements
Latest Google Chrome or Microsoft Edge browser

User support

Email or online ticketing support
Yes
Support response times
Targeted Initial response is within 2-3 working hours. We operate a three-tier support model:
Level 1 (Service Desk): Front-line assistance via email or phone — handling incident logging, access issues, and general enquiries.
Level 2 (Technical Support): Product specialists resolving configuration, integration, and performance-related issues.
Level 3 (Engineering): Escalation to development for root cause analysis, code fixes, and controlled releases.
Support is available Monday–Friday, 08:00–17:00, with 24/7 coverage for Priority 1 (Critical) incidents.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Support is through a structured, ITIL-aligned framework that meets public sector standards for reliability, accountability, and compliance. Support is included in the subscription costs and every account is allocated a technical support engineer.
Targeted Initial response is within 2-3 working hours. We operate a three-tier support model:
Level 1 (Service Desk): Front-line assistance via email or phone — handling incident logging, access issues, and general enquiries.
Level 2 (Technical Support): Product specialists resolving configuration, integration, and performance-related issues.
Level 3 (Engineering): Escalation to development for root cause analysis, code fixes, and controlled releases.
Support is available Monday–Friday, 08:00–17:00, with 24/7 coverage for Priority 1 (Critical) incidents.
Service Level Commitments
Priority 1 - Critical
- Complete loss of service/Major impact on essentials operations
- Resolution Target - 4 Hours
- Availability 24/7
Priority 2 - High
- Degraded performance / key function unavailable
- Resolution Target - 8 hours
- Availability - Business hours
Priority 3 - Medium
- Minor impact / workaround available
- Resolution Target - 2 business days
- Availability - Business hours
Priority 4 - Low
- Minor Low / General query / cosmetic issue
- Resolution Target - 5 business days
- Availability - Business hours
Support available to third parties
No

Onboarding and offboarding

Getting started
Following deployment, users receive pre-configured templates to facilitate the onboarding & data migration process. Tailored induction and training sessions are then arranged to meet individual and departmental needs.
Training is delivered by a certified instructor with in-depth knowledge of the service, ensuring full user competence and compliance with organisational standards.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract or at any time, users may request us to facilitate a secure data export or download. In addition, users retain the ability to independently export relevant data from the system at any time during the contract period, ensuring full control and portability of their information.
End-of-contract process
1) Confirm Termination – Acknowledge client request, review contract, send confirmation.
2) Financial Closure – Issue final invoice, handle refunds, stop recurring billing.
3) Data Export – Provide data export options; assist if needed.
4) Access Deactivation – Disable accounts, remove integrations, revoke internal access.
5) Data Deletion – Retain for set period; delete and issue deletion certificate.
6) Technical Cleanup – Remove configurations, integrations, and stored artifacts.
7) Client Feedback – Collect exit feedback; maintain positive relationship.
8) Internal Closure – Update CRM, note termination reasons, and archive final records.
There are no additional costs at the end of contract process.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
The PDF user guide is designed to be print and read friendly with black text on standard white background with an A4 page size. All our documents have been validated using Microsoft Word accessibility checker.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The web app allow access to use all the services offered by TraxQM. Web App is our primary service to the user.
Our mobile app for Android and iOS allow users to only interact with notifications & perform task management and complete approval workflows on the go. Users can not create new or update existing documents, events, audits etc via the mobile app.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Users access TraxQM through a secure web-based interface via modern browsers (Chrome or Edge). Authentication is managed by Microsoft Entra ID (Azure AD), supporting single sign-on (SSO) and multifactor authentication.
The interface provides an intuitive navigation across modules for document management, events, change controls, audits, risk, training, management reviews and asset tracking. Role-based permissions ensure that each user can view or edit only the data relevant to their responsibilities.
Accessibility standards
None or don’t know
Description of accessibility
TraxQM is a browser-based application designed with accessibility in mind. The interface uses clear layouts, readable text and consistent navigation. Pages are structured with logical headings and labels to assist users of screen-reader technology. Although TraxQM is not yet fully compliant with WCAG 2.1 or 2.2, accessibility improvements are being implemented across the platform.
Accessibility testing
We use E2E test tools called Ghost Inspector, which utilise the open source Axe library provided by Deque Systems, Inc. to perform accessibility checks. We run built-in checks that follow best practices to help identify common accessibility issues.
API
No
Customisation available
No

Scaling

Independence of resources
The service is built on AWS serverless architecture, designed to automatically scale based on user activity and request load. Each customer operates within a logically isolated environment to prevent resource contention or data overlap. AWS-managed scaling ensures consistent performance during periods of high demand. Continuous monitoring and load balancing maintain stable response times and availability for all users.

Analytics

Service usage metrics
Yes
Metrics types
System maintains 99.9% monthly uptime with under 43 minutes unplanned downtime; scheduled maintenance excluded period.
Daily full backups and 12-hour incremental backups ensure consistent data protection while minimizing storage usage.
RPO 24 hours allows one-day data loss; RTO 4 hours restores full system functionality quickly.
AWS and Azure environments are continuously monitored with real-time alerts for performance issues and security threats
Incidents, requests, and SLAs are tracked in JIRA to ensure documentation, prioritisation, and timely resolution.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
User can export their data either via PDF or CSV reports.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
SLA of 99.9% as standard for our core services and application availability.
Approach to resilience
Service is deployed in multiple AWS Availability zones in an Active-Active setup to provide High-Availability and Load balancing.
Outage reporting
Via Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Admin logins are reviewed and setup based on least privilege model. Further security policies are added in scope of the admin users to enhance security. The access is reviewed on role change and annual audits.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Other
Description of management access authentication
Admin and management logins are protected with a mandatory 2FA in addition to user credentials.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Our security governance is not accredited but we've designed and follow all the processes inline with the ISO 27001 standard.
Information security policies and processes
Codesplice Ltd follows policies & processes aligned with the principles of ISO/IEC 27001:2022
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Codesplice Ltd follows configuration and change management processes aligned with the principles of ISO/IEC 27001:2022
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Codesplice Ltd follows vulnerability management processes aligned with the principles of ISO/IEC 27001:2022
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Codesplice Ltd follows monitoring processes aligned with the principles of ISO/IEC 27001:2022
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Codesplice Ltd follows a structured Incident Management Process aligned with the principles of ISO/IEC 27001:2022
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
A 3 month trial of the service is available, however, certain functionalities involving integration with external systems are not included in the trial. We enable trial access after reviewing user request.
Link to free trial
https://www.traxqm.com

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Approachable Certification Ltd
ISO 9001 accreditation date
Monday 15 July 2024
What the ISO 9001 doesn’t cover
The company does not use any equipment to monitor and measure processes for products delivered to the customer.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
945d17cd-da20-47b2-96c0-eb34a6647b4e
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Introducing transparency to pay and reward processes
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@codesplice.com. Tell them what format you need. It will help if you say what assistive technology you use.