The Workbench · The Shelf
A browser-only tool can still owe Part 11
Every interactive tool the shelf plans to ship — the classification decider, the RTA readiness scorer, the timeline estimator — runs entirely in the visitor's own browser, and we keep repeating that promise because it's real: nothing about your device or your submission is typed into a server we control. That promise answers a data-privacy question. It doesn't answer a different one a regulatory team will eventually ask about any tool's output: does 21 CFR Part 11 have anything to say about the record this tool just produced? The honest answer is that a tool's architecture was never the thing Part 11 was built to test.
Part 11 doesn't create an obligation — it conditions one that already exists
21 CFR 11.1 sets the scope directly: Part 11 applies to records already required by some other FDA regulation — a “predicate rule,” in the industry's own shorthand for the GMP, QMSR, or submission requirement that made the record necessary in the first place — when an organization chooses to keep that record electronically instead of on paper, or relies on the electronic version to satisfy the requirement. FDA's 2003 guidance, Part 11, Electronic Records; Electronic Signatures — Scope and Application, narrowed this further still: the agency reads Part 11 as reaching only records a predicate rule actually requires, not every electronic file a company happens to generate along the way. A tool that produces output nobody's regulation requires anyone to keep was never inside Part 11's reach, no matter how carefully the tool itself was built.
Client-side is a privacy answer, not a compliance one
Running entirely in-browser answers “where does my data go” — nowhere but your own machine — and that's a real design commitment, one this shelf has made before. It says nothing about “is my recordkeeping obligation satisfied,” because that was never a question about where the computation happens. A predicate-rule record kept entirely on your own laptop, in a spreadsheet nobody ever uploaded anywhere, can still owe Part 11 controls if your own procedure treats that spreadsheet as the electronic version of a record a regulation requires you to keep. Architecture and applicability are answers to two different questions, and treating a client-side tool as automatically compliance-safe is how a team skips the actual question: what is this tool's output being used for.
The moment that matters is what you do with the output
If a determination the classification decider produces gets exported, filed, and treated as the electronic record satisfying whatever your own quality procedure requires you to document and retain, Part 11's controls — an attributable, time-stamped audit trail; an electronic signature meeting 11.100 and 11.200's own identity and non-repudiation requirements; validation that the system does what it's supposed to — apply to that saved determination, on your own systems, exactly as they would if you'd typed the same content into any other piece of software. If instead a team runs the same tool as a scratch aid, then prints the output, signs the printed page by hand, and files the paper, Part 11 doesn't reach that transaction at all. Part 11 has never applied to paper, under any circumstance, regardless of what produced the draft that preceded it.
What that means for a tool built to be an aid, not a system of record
The shelf's interactive tools are built to answer a specific question quickly and show their reasoning, not to be validated systems of record standing in for whatever controlled software your own quality system already runs. The design implication follows directly: a tool's output that's meant to become your literal, retained, electronic record needs the audit trail, e-signature, and validation controls built around it by whoever adopts it — the same way a spreadsheet or a word-processed template would, the moment it's promoted from a working draft to the file a predicate rule actually requires. None of that changes because the tool that produced the draft happened to run in a browser instead of on a server.
If you build a controlled process around one of the shelf's tools and want a second opinion on where the Part 11 line actually falls for your own procedure, tell us how you're using it — that's exactly the kind of gap report the shelf exists to take. If you'd rather just see the tools when they're live, one email does that, and the current previews sit in the tools section now.
The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.