// Product

Everything You Need
For GxP Cloud Compliance.

From automated evidence collection to audit-ready PDF reports — ChillinnBOT handles the compliance work so your team can focus on building.

// Features

Built for validation teams.

Automated Control Checks
Run 16+ GxP-specific controls across AWS and Azure in under 60 seconds. No manual configuration files required.
📋
Audit-Ready PDF Reports
Download structured PDF evidence packages formatted for IQ/OQ/PQ documentation. Attach directly to your validation deliverables.
📦
JSON Evidence Export
Machine-readable evidence files with ISO 8601 timestamps. Ingest into your QMS or store in your audit trail automatically.
🔒
Read-Only Access
ChillinnBOT never writes to your cloud environment. Only reads configuration data required for control evaluation. Zero risk to production.
☁️
Dual-Cloud Support
AWS and Azure covered in a single scan. One report, both clouds, one audit evidence package. No maintaining two separate processes.
📊
Compliance Dashboard
Live Pass/Fail view across all controls. Filter by cloud, by result, or by control ID. Click any row for finding details and remediation notes.
// Controls

40+ GxP-critical controls
across both clouds.

Control IDNameServiceGxP Requirement
CTL-A001S3 Bucket Encryption at RestS321 CFR Part 11 — Data integrity
CTL-A002CloudTrail Enabled (All Regions)CloudTrail21 CFR Part 11 — Audit trail
CTL-A003Security Group Open Port ExposureEC2/VPCGAMP 5 — Network security
CTL-A004Root Account MFA EnabledIAM21 CFR Part 11 — Identity verification
CTL-A005KMS Key Rotation EnabledKMSAnnex 11 — Key management
CTL-A006IAM Admin Policy ScopeIAM21 CFR Part 11 — Least privilege
CTL-A007VPC Flow Logs EnabledVPCGAMP 5 — Network logging
CTL-A008GuardDuty Enabled Per RegionGuardDutyAnnex 11 — Intrusion detection
Control IDNameServiceGxP Requirement
CTL-Z001Azure Blob Storage EncryptionStorage21 CFR Part 11 — Data integrity
CTL-Z002Azure Monitor & Diagnostic SettingsMonitor21 CFR Part 11 — Audit trail
CTL-Z003NSG Open Port ExposureNetworkGAMP 5 — Network security
CTL-Z004MFA for Privileged UsersEntra ID21 CFR Part 11 — Identity verification
CTL-Z005Key Vault Rotation PolicyKey VaultAnnex 11 — Key management
CTL-Z006RBAC Over-Permission AuditEntra ID21 CFR Part 11 — Least privilege
CTL-Z007Network Watcher Flow LogsNetworkGAMP 5 — Network logging
CTL-Z008Microsoft Defender for CloudDefenderAnnex 11 — Intrusion detection