Skip to content
Real-time

Every unit of consignment inventory,tracked and compliant.

Lot-level trunk stock for medical device field teams — live counts down to the lot, recall notices matched across every rep, and an append-only audit trail.

The CompliMED inventory view: 41 items across a region's reps, each row showing product, rep, trunk location, lot number, quantity and expiry date, with filters for available, expiring, expired and used stock.
  • Receive
  • Scan
  • Transfer
  • Allocate
  • Quarantine
  • Return
  • Reconcile
  • Report

Built for teams where complianceisn’t optional.

Five things the product does that a spreadsheet cannot.

  • FEFO allocation
  • Expiry alerting
  • Role-scoped visibility
  • Disclosure on every export
  • Multi-specialty catalog
Outcomes

Fewer write-offs. Faster recalls.Always audit-ready.

The number that matters is not on this page. It is the one CompliMED computes from your own records — value recovered against value lost, over any period, with a written methodology your finance team can audit.

  • Cut waste

    Stock inside six months of expiry has, in practice, stopped being placeable. CompliMED surfaces it while it can still be moved, then reports what was recovered against what was lost — both figures, and the rate between them.

  • Recall in one pass

    Match a notice to every affected unit — still in trunks and already used — quarantine the stock so it cannot be used, transferred or requested, notify whoever is responsible for it, and produce the report that proves you did.

  • Prove compliance

    Every inventory-affecting action lands in an append-only, hash-chained log. Every export writes its own disclosure record: who took what, how many rows, and under what scope.

Tracking

Every unit, every rep,in real time.

Consignment stock lives in trunks and hospital storerooms, and the spreadsheet tracking it is always a day behind. CompliMED holds the live position, down to the lot.

  • Lot-level, per rep

    Quantity, expiration, location and status for every lot, held against the rep who actually carries it — not the admin who ran the import. A manager sees their own reps; an administrator sees the whole org.

  • Short-dated before it is dead stock

    Warning at 90 days, critical at 30, and a scheduled job that expires stock the day its printed date arrives. The point is to catch a lot while a facility will still take it.

  • Rep-to-rep, first-expiry-first-out

    A rep who is short can request from another rep's stock and the allocation runs FEFO, so the oldest dating moves first. Resolving a gap across the team beats waiting on a formal replenishment.

  • Captured offline, synced on reconnect

    Usage is written to the device before any network call, then drained to the server when the signal returns. Each capture carries its own id, so a retry after a dropped response is a rejected duplicate rather than a second procedure.

The CompliMED inventory view: 41 items across a region's reps, each row showing product and SKU, the rep holding it, trunk or office location, lot number, quantity and expiry date, with filter counts for available, expiring, expired and used stock.
Complaints

Something goes wrong.The record starts there.

A rep is standing in a cath lab. A device will not track, and the physician says so once before the case moves on. Everything that makes that a record — product, lot, serial, UDI, facility — is already on the rep's phone, because they scanned the unit in.

  • Filed from the phone that scanned it in

    The device identifies itself — product, SKU, lot, serial, UDI and expiry are already attached, because that unit was scanned into inventory. The rep supplies the one part nobody else can: what happened, in their own words. Started without signal, it syncs when the phone finds one.

  • Sent onward the moment it is filed

    It goes to the address your organization sets for complaints, and the time it was sent is recorded beside the time it was received and the time it was filed — three facts, because they are three different moments. There is no countdown, deliberately: which reporting clock applies depends on whether you are a manufacturer, an importer or a user facility, and that is not a role this product holds.

  • The determination, and the reasoning behind it

    A person decides whether an event is reportable. CompliMED records who decided, when, and why — including when the answer is no. A changed mind writes a second assessment rather than overwriting the first, so the reasoning that was superseded survives next to the conclusion that replaced it.

  • The rep who reported it can see what became of it

    Most of this part of the product is manager and administrator only. This is not, and the reason is practical: a rep who reports a device failure and never learns the outcome stops reporting, and the record depends entirely on them reporting. They see their own reports — not the queue.

A CompliMED complaint record: the device with its lot, SKU and UDI; when the complaint was received, filed and sent to the company; the reporter's account of what happened; and a reportability determination of not reportable, with the name of the person who made it, the time, and their written reasoning.

Scope, stated plainly: CompliMED does not file with the FDA. It captures a complaint, timestamps it, routes it to the address you nominate, and records the reportability determination your reviewer makes — including who made it and why. Deciding that a report is due, and submitting it, remain yours.

Recalls

From notice toevery affected unit.

A manufacturer names the lots. CompliMED finds every one of them across the field — sitting in trunks and already recorded against a case — holds the stock so it cannot be used, and produces the report that proves it.

  • Scoped to the lots the notice names

    One matching engine serves every recall surface, so two screens can never disagree about what a notice covers. Exact lots by default, with pattern matching as a deliberate fallback rather than a silent default.

  • Quarantined the moment it is issued

    Not a follow-up task that waits on every rep reading an email. Affected stock drops out of use, transfer and request immediately, enforced in three places rather than hidden in the interface. Returning it to the vendor stays open, because that is usually the required disposition.

  • Including what has already been used

    Recall searches normally filter to stock on hand, which cannot answer the question a regulator asks first. CompliMED returns a second list — the units already recorded against a case, with facility and case reference — and notifies the rep who placed them, not just whoever holds stock today.

  • A completion report that checks itself

    What was found, what was pulled, who was told, what is still outstanding — and the report re-verifies the audit chain as it renders, printing the result. Proof that the record behind it has not been altered, not just an assertion that it has not.

The CompliMED recall view, listing active recall notices with the affected product, severity classification and the number of units affected across the field.

Scope, stated plainly: CompliMED traces affected inventory and the cases it reached. It does not ingest external recall feeds — you enter the notice — and patient follow-up remains your regulatory process. The product tells you which cases are affected; it does not manage the contact.

Compliance

Every action,provably logged.

An auditor does not ask whether you kept a log. They ask whether it could have been changed. CompliMED's answer is a chain the database itself refuses to rewrite, and a verifier that will say so on demand.

  • Append-only — and a deletion still shows

    Each entry hashes the one before it, and database triggers reject UPDATE and DELETE from every client, including a direct psql session. Sequence numbers are unique per organization, so a row removed underneath all of that leaves a gap that verification reports.

  • No action skips the log

    There is one write path and every inventory-affecting call site goes through it. Appends are serialized per organization, so two simultaneous writes cannot fork the chain — and a bulk-imported row shares a transaction with its audit entry, so it cannot exist without one.

  • Exports log themselves before the bytes leave

    Every export writes a disclosure record first: who ran it, how many rows, at what scope, and whether the data was patient-adjacent. System actions are recorded as system rather than left as an anonymous blank.

  • Provenance from the scan onward

    A GS1 UDI barcode carries the device identifier, lot and expiry, and CompliMED keeps the raw payload alongside what it parsed — so if the parser ever changes, old records can be checked against what the scanner actually read.

The CompliMED activity feed: an audit trail of inventory events, each row naming the action, the lot, the rep and who recorded it, with a timestamp.

Scope, stated plainly: these are engineering controls, not a certification — CompliMED holds no third-party compliance attestation today. Audit and disclosure records are retained indefinitely by design, with no purge path. That is deliberate for a record meant to outlast the questions asked of it, and it is worth weighing against your own retention policy.

Why it exists

Built for the daysomeone asks.

A recall notice. An audit. An inspection. Whether those days go well is decided months earlier, by how carefully every lot was recorded when nothing was wrong.

The CompliMED activity feed: an audit trail of inventory events, each row naming the action, the lot, the rep and who recorded it, with a timestamp — replenishment routed, quarantine released, stock received, transfer received.
The gap

The work stays.The process changes.

None of this is new work. It is the work a field team already does, done where it can be found again.

How each piece of field-inventory work is handled today, and how CompliMED handles it.
The workTodayWith CompliMED
Tracking what is in the fieldA spreadsheet someone updates when they rememberLot-level, live, held against the rep who carries it
Receiving new stockAd hoc, and often never written downOne scan fills product, lot and expiry
Passing stock to a teammateA text message, and the record moves with nobodyRecorded and attributable, first-expiry-first-out
Knowing what is about to expireFound when a case needs it and it is already deadWarned at 90 days, critical at 30
Seeing what your stock is worthNo number anyone can produce on requestValue recovered against value lost, on your own records
Reporting a problem with a deviceA phone call, and a record written from memory days laterFiled from the phone that scanned the unit, lot already attached
Answering a recall noticePhone calls, and hoping every rep repliesEvery affected lot matched, by the rep holding it
Getting started

Access is granted,never assumed.

Every account in an organization traces back to a decision its administrator made. That is the first control, and it is in place before any stock is recorded.

  1. We email your administrator

    You name the person who should hold the keys. The first message goes to them, not to a general address and not to a list.

  2. They create the organization

    Their sign-up link builds the organization around them. There is no shared password and no account that belongs to nobody.

  3. They add the team

    Reps and managers are entered by the administrator, and each one is invited at their own address.

  4. Only cleared addresses can finish

    The sign-up form is public, but it only completes for an address the administrator has already cleared. Anyone else gets no further.

Early organizations get help with setup rather than a manual. Access control is the first thing configured because it is the thing every later answer depends on — when a recall notice names a lot, the record of who held it is only as good as the record of who was allowed to hold it. See how access is scoped.

What you get

Everything below is codethat exists today.

What does not exist yet is listed underneath it, in the same size type.

Control and record

  • Access control

    Three roles — rep, manager, admin — with managers scoped to their own reps rather than the whole organization. Time-based one-time-password MFA with recovery codes, and account lockout on repeated failures. MFA is challenged after the password, never before, so a single guess cannot confirm that an account exists.

  • Tenant isolation

    Every server action and dynamic route resolves records through the caller's own organization, so swapping an identifier in a URL returns not-found rather than another customer's data. That behaviour was reviewed specifically for cross-tenant object access, not assumed.

  • A record of who did what

    Inventory actions and authentication events land in the same append-only, hash-chained log — sign-in, lockout, password reset, MFA enrolment and failure included. Data leaving the system writes its own disclosure record before the export runs.

Data in and out

  • Scan it in

    A GS1 UDI barcode fills product, lot and expiry in one pass, on a phone camera or a desktop scanner. No keying lot numbers off a label, which is where trunk-stock records usually start going wrong.

  • Import a spreadsheet

    Bulk receipt from CSV, validated row by row against the same rules the manual form uses. Rows that fail come back individually with a reason instead of failing the file, and every imported item lands with its audit entry in the same transaction.

  • Or call the API

    A token-authenticated REST API over the same service layer the web app uses, so the two cannot drift apart on what a rule means. Revoking a device takes effect on the next request rather than whenever a token happens to expire.

  • And take it back out

    Exports are CSV and yours to take. Each one writes its own disclosure record first — who ran it, how many rows, at what scope — so leaving with your data is itself part of the audit trail.

The CompliMED compliance view: expiration exposure showing value recovered against value expired with a recovery rate, alongside active recalls and outstanding stock requests.

What we do not claim

  • No certifications. CompliMED holds no SOC 2, HITRUST or equivalent third-party attestation. Certification is a stated goal with no auditor or date committed.
  • No HIPAA claim. A code-level gap analysis has been done and acted on, but no review by qualified counsel has taken place, and nothing here should be read as a compliance opinion.
  • Tenant isolation is enforced in the application, not the database. Row-level security is not switched on. The gap is scoped and understood; it is not built. Until it is, isolation depends on query discipline that has been reviewed rather than on a backstop underneath it.
  • CompliMED does not file with the FDA. It captures a product complaint, timestamps it, routes it to the address you nominate, and records the reportability determination your reviewer makes — including who made it and why. It holds no Electronic Submissions Gateway account and files no Form 3500A. Deciding that a report is due, and submitting it, remain yours.
  • Retention is indefinite. Audit and disclosure records have no purge path, by design.
  • There are no ERP or EDI connectors. No SAP, Oracle or JDE adapters, and no webhook framework. Whether CompliMED should grow them, or stay deliberately integration-light, is an open product question rather than a dated roadmap promise. Today the API is the integration point, and it is documented rather than bespoke.
The founders

We watched this go wrongfor thirteen years.

Between us we have spent more than thirteen years around medical device field inventory — receiving it, moving it, counting it, and answering for it when somebody asked where a particular lot had gone.

The same things went wrong everywhere. Stock was tracked in a spreadsheet that was always a day behind. A rep handed product to a teammate and the record stayed with neither of them. Nobody could say what was sitting in the field, what it was worth, or how much of it was about to expire. And when a recall notice arrived, finding every affected unit meant phone calls and hoping everyone replied.

None of it was anybody’s fault. The work was real and the tools were a spreadsheet and a good memory.

So we built the thing we kept wishing existed: every unit held against the person carrying it, expiry visible before it becomes waste, and a record of every movement that cannot be quietly rewritten afterwards. Not because an auditor asks for it — because the day an auditor asks is the day it is too late to start.

The founders of CompliMED — 13+ years of combined medical device experience.

Questions

The three thingseveryone asks.

Taken from actual conversations, answered the way they get answered on the call.

We haven't had a problem yet, and we don't carry enough for this to matter.

That is usually true right up until it isn't, and the day it stops being true is the day this stops being possible to start. An audit trail can only prove what it was recording at the time. When a manufacturer names a lot, the question is who held it three months ago — and nothing you install afterwards can answer that.

The volume argument also cuts the other way. A small field inventory is the easiest one to get fully recorded, because there is less of it to catch up on. Every unit added before you start is a unit somebody has to reconstruct later from memory.

We're considering building our own.

Reasonable, and the inventory part is not the hard part. The hard parts are the ones that only matter under scrutiny: an audit log the database itself refuses to rewrite, isolation that holds when someone edits an identifier in a URL, first-expiry-first-out allocation across reps, recall matching on exact lots and on patterns, and capture that survives a hospital basement with no signal.

Then it has to stay built. Every one of those needs maintaining by a team whose actual priority is selling devices.

We're planning to put an internal process in place.

Good — a process is the prerequisite, not the alternative. The question is where it lives. A documented process in a shared drive is only as good as the people who remember it, and it leaves with them.

CompliMED is somewhere to put the process so that following it is the path of least resistance and skipping it leaves a gap you can see.

Talk to us

See it on yourown inventory.

CompliMED is provisioned per organization, so the first step is a conversation rather than a signup form with a credit-card field. Tell us what you carry and who carries it, and we will show you the parts that matter to you.

A person reads it
Requests go to the team directly. There is no qualification bot in front of us.
We show the product, not slides
A walkthrough of real screens — receiving, a recall, the audit trail — against the workflow you describe.
No obligation to continue
If it is not a fit, we will say so. This is a small team selling to a small market; wasting your afternoon costs us more than it costs you.

Prefer email? support@complimed.net

Not ready to talk? Take the recall-readiness checklist with you. Three short reads, no follow-up sequence.

We use this to reply, nothing else.

Make your job easier.

Request a demo

See it on yourown inventory.

Tell us what you carry and who carries it.

We use this to reply, nothing else.