Enterprise · Security & Compliance
Enterprise-grade security, built for regulated pharma
pharcel is engineered to meet the security, privacy, and compliance bar of the world's most scrutinized industry, with the controls, documentation, and transparency your security and quality teams expect.
Compliance & certifications
Aligned to the frameworks your auditors already trust
GDPR
EU-hosted · DPA available
SOC 2 Type II
In progress
ISO 27001
Roadmap
AES-256 / TLS 1.2+
Encrypted end to end
Our DPA, sub-processor list, and security documentation are available to prospective and existing customers under NDA. SOC 2 Type II and ISO 27001 are in progress.
Security capabilities
Controls that span identity, data, and infrastructure
Encryption at rest & in transit
All data is encrypted at rest with AES-256 and in transit with TLS 1.2+. Keys are managed through a cloud KMS with regular rotation and no plaintext key storage.
SSO/SAML & SCIM
Enterprise SSO via SAML 2.0 and OIDC with your identity provider (Okta, Azure AD, Ping). SCIM 2.0 automates user provisioning and de-provisioning as your directory changes.
Role-based access control
Granular RBAC scopes every agent, dataset, and view. Least-privilege roles for Admin, Builder, Analyst, and Compliance keep access aligned to job function.
Immutable audit logs
Every access, query, export, and configuration change is captured in a tamper-evident audit trail, exportable to your SIEM for continuous monitoring and Part 11 traceability.
Data isolation & single-tenant
Logical tenant isolation by default, with a dedicated single-tenant deployment option for customers requiring physically separated compute and storage.
Data residency (EU / US)
Choose where your data lives. Regional deployments in the EU and US keep processing and storage inside your chosen jurisdiction to meet local regulatory requirements.
Penetration testing
Independent third-party penetration tests are conducted on a regular cadence and after material changes. Summary reports are available under NDA.
PII / PHI handling
We process HCP and public/market data — no patient PHI. Personal data (e.g. HCP profiles) is classified, minimized, and access-gated, with configurable retention and GDPR right-to-erasure workflows.
Sub-processor transparency
A current list of every sub-processor, its purpose, and its region is published and version-controlled. Customers are notified in advance of any material change.
How we handle your data
Your data stays yours, private, governed, and traceable
You own your data
Your data is never used to train shared or third-party models. It is processed solely to deliver the services you configure, and returned or deleted on request.
Least-privilege by design
Internal access is tightly scoped, logged, and reviewed. Production access requires justification and is time-bound, with no standing broad-access credentials.
Secure development lifecycle
Code review, dependency scanning, secrets detection, and infrastructure-as-code controls run in every pipeline before anything reaches production.
Business continuity
Encrypted, geographically redundant backups with tested restore procedures and defined RPO/RTO targets keep your operations resilient.
Security is not a checkbox at the end, it is designed into every agent, every pipeline, and every deployment from the first line of code.
pharcel Security & Trust
Explore enterprise
Request our security documentation
Get our security whitepaper, sub-processor list, and DPA, and bring your security and privacy teams into the conversation early.
Contact our security team