What gets asked before the demo
Every answer below restates a claim made elsewhere on this site. Nothing new is promised here; what is scattered is gathered.
Which standards does BellaKYS cover?
The core is ISO 9001. IATF 16949, ISO 13485, ISO 14001, ISO 45001, ISO/IEC 27001 and ISO/IEC 17025 are enabled as sector profiles that switch on their additional requirements. Clause references are not hard-coded; they are managed as a versioned compliance catalogue.
Will the product get us certified?
No. The product helps you operate the controls the standards require; certification is granted to your organisation, not to software. That boundary is deliberate and is not loosened.
How many modules are there, and are they bought separately?
Thirteen modules share one data model. They are not separate applications; the links between them are not drawn by hand — they form on their own on the same record model.
Cloud or our own servers?
Both run on one codebase. In the cloud deployment data is hosted in Türkiye; organisations that prefer it install on their own servers. The Docker Compose setup removes the need to maintain a separate on-premise edition.
How does ERP and time-attendance integration work?
Employee, supplier, material and equipment master data comes from its source; the quality system references it rather than duplicating it. Every connection has an error queue and a reconciliation screen listing what exists in the source but not here, what exists here but not in the source, and records whose fields disagree.
Can it connect to our corporate identity provider?
It works with corporate identity providers over OpenID Connect and SAML 2.0. Domain restriction, role mapping and auto-provisioning are supported; multi-factor authentication can be enforced for supplier portal users.
Is the electronic signature a qualified electronic signature?
No. The system signature is an approval record made after identity is re-verified (a password is requested), storing immutably who signed, against which content version and with what meaning. A qualified electronic signature for legally binding documents is positioned separately.
Is it 21 CFR Part 11 compliant?
Controls aligned with Part 11 and GAMP 5 expectations — authenticated signatures, an immutable trail, mandatory reasons — are built into the design. The full computer system validation package required for pharmaceutical and medical device use is separate work carried out for your specific installation.
Can a mistaken record be deleted?
Quality records and access records are never physically deleted; soft deletion is used. The audit trail is append-only and sealed with a hash chain. Rejection, cancellation and withdrawal decisions require a reason, which is written into the trail.
Most of our users are not from the quality department — is the system too heavy for them?
The landing screen is a task list, not a module menu. Authorisation is role-based: a field user and a quality specialist do not see the same menu density. Notifications carry a one-click action link and a daily digest is the default.
Can audits be carried out where there is no connectivity?
Yes. Checklists download to the device, answers accumulate locally where there is no coverage, and sync when the connection returns.
How long does roll-out take?
Because core modules ship with ready ISO packs, the target is a pilot within 10 weeks. The usual order is scope and organisation, documents, nonconformity and corrective action, then audits and training.
Why is there no pricing on the site?
A quotation depends on user count, the modules and sector profiles you switch on, and the deployment model (cloud or your own servers), so no single list price is published here. After the demo we send a written quotation for your scope.
Question not answered here?
Write to us directly and we will show it on your own scenario during the demo.
Request a demo →