Skip to content

Security

What we hold, and who can see it.

Pharmaceutical buyers ask this early, and rightly. This page describes the data model plainly rather than listing certifications.

Internal — not ready to publish

The infrastructure and sub-processor facts on this page have not been verified yet, so they are marked as such rather than estimated. This page is excluded from search indexing and from the sitemap until they are confirmed.

Scope

The data PharmeXa holds

PharmeXa holds commercial distribution data: stockist stock statements, your product master, and the identities of the MRs and Area Managers who submit and approve them.

That list is the entire scope of the platform. PharmeXa operates on commercial movement between a company and its distributors — quantities, values, batches and periods. Every report, KPI and forecast it produces is derived from those fields, and it neither requires nor accepts anything outside them.

  • Stockist statements

    The original file as received, plus the normalised records extracted from it.

  • Product master

    Your catalogue, and the stockist-name mappings that resolve to it.

  • People

    MR and Area Manager names, work contact details, and role assignments.

  • Activity

    Submission timestamps, approval decisions, and the notes attached to them.

Access control

Who can see what

Visibility follows the same role model that drives the approval chain, so there is one set of rules to reason about rather than two.

Role-based visibility within a PharmeXa deployment.
RoleCan seeCan change
Medical RepresentativeOnly their own assigned stockists and their own submissionsTheir own uploads and mapping confirmations, until approved
Area ManagerAll submissions from the MRs reporting to themApprove or reject submissions, with a note
LeadershipApproved data across the territories in their scopeNothing — analysis is read-only by design
AdministratorConfiguration, user and stockist assignmentsUsers, roles, assignments and the product master

Submissions

How a statement reaches us

Statements are uploaded directly to the platform by a signed-in user over an encrypted connection. No third-party messaging or file-transfer service sits in the middle, so there is one path to audit rather than several.

The original file is retained exactly as it arrived, alongside the records extracted from it. That matters more than it sounds: it means a figure on a dashboard can be traced back to the document a stockist actually sent, months later.

Every submission then enters the Area Manager queue. Nothing appears in reporting until it has been approved there — the same control that makes the numbers defensible is what stops unreviewed data reaching an audience.

  • Signed-in upload only
  • Original file retained
  • Approval before reporting
  • No third-party carrier

Infrastructure

Hosting, encryption and retention

Deliberately left unfilled rather than estimated. Each row below needs a verified answer before this page goes live.

Infrastructure and retention facts, pending confirmation.
ItemValue
Hosting providerTo be confirmed
Hosting regionTo be confirmed
Encryption in transitTo be confirmed
Encryption at restTo be confirmed
Backup cadenceTo be confirmed
Backup retentionTo be confirmed
Recovery objectiveTo be confirmed
Data retention on cancellationTo be confirmed

Sub-processors

Third parties involved in processing, pending confirmation.
PartyPurposeProcessing location
Cloud hostingApplication and database hostingTo be confirmed
Email deliveryNotifications and statementsTo be confirmed

Disclosure

Reporting a problem

If you believe you have found a security issue in PharmeXa, email ankur.patel@pharmexa.in with enough detail to reproduce it. We will acknowledge the report and keep you informed while it is being addressed.

Please do not test against a live customer deployment. If you need an environment to demonstrate something, ask and we will arrange one.

For how data is used rather than how it is protected, see the privacy policy.