Enterprise · Security & Compliance
Enterprise-grade security, built for regulated pharma
pharcel is engineered to meet the security, privacy, and compliance bar of the world's most scrutinized industry, with the controls, documentation, and transparency your security and quality teams expect.
Compliance & certifications
Aligned to the frameworks your auditors already trust
SOC 2 Type II
Audited annually
HIPAA
BAA available
GDPR
EU data residency
ISO 27001
In progress
21 CFR Part 11
GxP-aware controls
AES-256 / TLS 1.2+
Encrypted end to end
Current attestations, audit reports, and a signed BAA are available to prospective and existing customers under NDA. ISO 27001 certification is in progress.
Security capabilities
Controls that span identity, data, and infrastructure
Encryption at rest & in transit
All data is encrypted at rest with AES-256 and in transit with TLS 1.2+. Keys are managed through a cloud KMS with regular rotation and no plaintext key storage.
SSO/SAML & SCIM
Enterprise SSO via SAML 2.0 and OIDC with your identity provider (Okta, Azure AD, Ping). SCIM 2.0 automates user provisioning and de-provisioning as your directory changes.
Role-based access control
Granular RBAC scopes every agent, dataset, and view. Least-privilege roles for Admin, Builder, Analyst, and Compliance keep access aligned to job function.
Immutable audit logs
Every access, query, export, and configuration change is captured in a tamper-evident audit trail, exportable to your SIEM for continuous monitoring and Part 11 traceability.
Data isolation & single-tenant
Logical tenant isolation by default, with a dedicated single-tenant deployment option for customers requiring physically separated compute and storage.
Data residency (EU / US)
Choose where your data lives. Regional deployments in the EU and US keep processing and storage inside your chosen jurisdiction to meet local regulatory requirements.
Penetration testing
Independent third-party penetration tests are conducted on a regular cadence and after material changes. Summary reports are available under NDA.
PII / PHI handling
Sensitive fields are classified, minimized, and access-gated. PHI is processed only under a signed BAA, with configurable retention and right-to-erasure workflows.
Sub-processor transparency
A current list of every sub-processor, its purpose, and its region is published and version-controlled. Customers are notified in advance of any material change.
How we handle your data
Your data stays yours, private, governed, and traceable
You own your data
Your data is never used to train shared or third-party models. It is processed solely to deliver the services you configure, and returned or deleted on request.
Least-privilege by design
Internal access is tightly scoped, logged, and reviewed. Production access requires justification and is time-bound, with no standing broad-access credentials.
Secure development lifecycle
Code review, dependency scanning, secrets detection, and infrastructure-as-code controls run in every pipeline before anything reaches production.
Business continuity
Encrypted, geographically redundant backups with tested restore procedures and defined RPO/RTO targets keep your operations resilient.
Security is not a checkbox at the end, it is designed into every agent, every pipeline, and every deployment from the first line of code.
pharcel Security & Trust
Explore enterprise
Request our security documentation
Get our SOC 2 report, security whitepaper, sub-processor list, and BAA, and bring your security, privacy, and quality teams into the conversation early.
Contact our security team