Skip to content

Trust centre

The due-diligence answers, on one page

A certificate of analysis is commercially sensitive and usually belongs to someone else in your supply chain. This page collects what protects it and what we will not claim.

Your documents are isolated

Documents and analyses are scoped to your organisation. Nothing you upload is pooled with another customer's data, and nothing is used to train a model.

Encryption in transit, enforced

The site and the API are served over HTTPS with automatically renewed certificates, HTTP redirected, and strict transport security set for a year including subdomains. A configuration that would serve the product without TLS refuses to start.

Storage that is not reachable from the internet

The database is reachable only on a private network inside the host. Object storage has public access prevention enforced and object versioning enabled, so an overwrite or deletion is recoverable.

Backups that leave the machine

The database is backed up nightly and each backup is copied off-site, so losing the server does not lose the backups with it.

Access is enforced server-side

Administrator and reviewer functions are gated by role on the server, not merely hidden in the interface. Service credentials are mounted read-only.

A record that reproduces

Every analysis stores the engine, source versions and rule fingerprint that produced it, so a report from months ago still resolves to the exact basis it was made on.

What we do not claim

We hold no audited security certification, and we will not describe ourselves as certified, compliant or accredited when we are not. A threat model, encryption evidence and an incident-response procedure are maintained and can be shared on request under NDA. Retention and deletion are set out in the retention policy the application serves; the privacy policy and terms are published with their version and status, and a document still in legal review is shown as pending rather than presented as if in force.

PharmaTrust supports qualified decision-making. It does not replace the responsible pharmaceutical or regulatory professional, does not certify compliance and does not grant regulatory approval.

Ask the rest

Security questionnaires and diligence questions go to info@pharmatrust.tech and are answered by a person. Questions asked often enough get answered here, in public.

The security page in full · Legal documents