The platform
One system for the entire regulated lifecycle.
Requirements, architecture, tests, risk, and SBOM as native records in one database — connected by governed traceability, audit-ready by default. Here's a look at each piece.
Requirements
Author requirements as governed records.
Every requirement is a versioned, controlled item with its own identity, lifecycle, and state — scored for quality and checked for compliance as you write, not after the fact.
Learn more about Requirements →
Risk
Manage hazards and risk in context.
Risk registers with severity, priority, and mitigation status — each risk linked to the requirements and components it touches, so nothing is assessed in isolation.
Learn more about Risk →
SBOM
Your SBOM, on the thread.
Import CycloneDX or SPDX and every component becomes a first-class item — linked to the risks it threatens and the tests that cover it, with CVE/CVSS tracking and suspect propagation when a vulnerability lands.
Learn more about SBOM →
Review Center
Run formal reviews across every module.
Review sessions bring the right artifacts and reviewers together in one place — track status, velocity, and reviewer workload, with every comment and decision captured as part of the record.
Learn more about Review Center →
Releases
Bundle and approve releases with confidence.
Plan releases as governed bundles of modules, track each status from draft through GA, and approve the whole package against the evidence behind it — so what ships is exactly what was reviewed and signed.
Learn more about Releases →
Reports
Report on everything — 68 built-in.
68 built-in reports across 13 categories — from requirements status and FMEA to regulatory mapping (IEC 62304, ISO 14971, 21 CFR 820) and ReqIF export — plus a drag-and-drop builder for your own.
Learn more about Reports →
Interoperability & migration
Bring your data in. Keep your tools.
Import from CSV, Excel, Word, HTML, ReqIF (DOORS, Polarion), XMI (Cameo, Rhapsody, MagicDraw), and SBOM (CycloneDX, SPDX) — with round-trip sync and full export, so adopting TraceUnified is migration, not lock-in.
AI
Advisory AI for requirements and quality — governed, not autonomous.
AI agents analyze your requirements and quality as you work and propose improvements — they never write to your records. A human applies every change through the signed, audited workflow. Fail-closed and license-gated: AI starts off at every level until you deliberately enable it, and every change lands on the audit trail.
Flags ambiguous, weak, or untestable phrasing and missing acceptance criteria.
Proposes a clearer, testable rewrite of an item — for a person to accept or reject.
Surfaces likely-duplicate or overlapping items before they fork your trace model.
Checks an item against a selected regulatory framework and reports what it finds.
Built for compliance
Engineered to enable 21 CFR Part 11, ISO, and safety-critical development.
Controlled states, electronic signatures, and a tamper-evident audit trail run through every module — so the evidence an auditor asks for is a by-product of the work, not a scramble before a submission.