pharcel

Enterprise · Security & Compliance

Enterprise-grade security, built for regulated pharma

pharcel is engineered to meet the security, privacy, and compliance bar of the world's most scrutinized industry, with the controls, documentation, and transparency your security and quality teams expect.

Compliance & certifications

Aligned to the frameworks your auditors already trust

SOC 2 Type II

Audited annually

HIPAA

BAA available

GDPR

EU data residency

ISO 27001

In progress

21 CFR Part 11

GxP-aware controls

AES-256 / TLS 1.2+

Encrypted end to end

Current attestations, audit reports, and a signed BAA are available to prospective and existing customers under NDA. ISO 27001 certification is in progress.

Security capabilities

Controls that span identity, data, and infrastructure

Encryption at rest & in transit

All data is encrypted at rest with AES-256 and in transit with TLS 1.2+. Keys are managed through a cloud KMS with regular rotation and no plaintext key storage.

SSO/SAML & SCIM

Enterprise SSO via SAML 2.0 and OIDC with your identity provider (Okta, Azure AD, Ping). SCIM 2.0 automates user provisioning and de-provisioning as your directory changes.

Role-based access control

Granular RBAC scopes every agent, dataset, and view. Least-privilege roles for Admin, Builder, Analyst, and Compliance keep access aligned to job function.

Immutable audit logs

Every access, query, export, and configuration change is captured in a tamper-evident audit trail, exportable to your SIEM for continuous monitoring and Part 11 traceability.

Data isolation & single-tenant

Logical tenant isolation by default, with a dedicated single-tenant deployment option for customers requiring physically separated compute and storage.

Data residency (EU / US)

Choose where your data lives. Regional deployments in the EU and US keep processing and storage inside your chosen jurisdiction to meet local regulatory requirements.

Penetration testing

Independent third-party penetration tests are conducted on a regular cadence and after material changes. Summary reports are available under NDA.

PII / PHI handling

Sensitive fields are classified, minimized, and access-gated. PHI is processed only under a signed BAA, with configurable retention and right-to-erasure workflows.

Sub-processor transparency

A current list of every sub-processor, its purpose, and its region is published and version-controlled. Customers are notified in advance of any material change.

How we handle your data

Your data stays yours, private, governed, and traceable

You own your data

Your data is never used to train shared or third-party models. It is processed solely to deliver the services you configure, and returned or deleted on request.

Least-privilege by design

Internal access is tightly scoped, logged, and reviewed. Production access requires justification and is time-bound, with no standing broad-access credentials.

Secure development lifecycle

Code review, dependency scanning, secrets detection, and infrastructure-as-code controls run in every pipeline before anything reaches production.

Business continuity

Encrypted, geographically redundant backups with tested restore procedures and defined RPO/RTO targets keep your operations resilient.

Security is not a checkbox at the end, it is designed into every agent, every pipeline, and every deployment from the first line of code.

pharcel Security & Trust

Request our security documentation

Get our SOC 2 report, security whitepaper, sub-processor list, and BAA, and bring your security, privacy, and quality teams into the conversation early.

Contact our security team