Security
What we hold, and who can see it.
Pharmaceutical buyers ask this early, and rightly. This page describes the data model plainly rather than listing certifications.
Internal — not ready to publish
The infrastructure and sub-processor facts on this page have not been verified yet, so they are marked as such rather than estimated. This page is excluded from search indexing and from the sitemap until they are confirmed.
Scope
The data PharmeXa holds
PharmeXa holds commercial distribution data: stockist stock statements, your product master, and the identities of the MRs and Area Managers who submit and approve them.
That list is the entire scope of the platform. PharmeXa operates on commercial movement between a company and its distributors — quantities, values, batches and periods. Every report, KPI and forecast it produces is derived from those fields, and it neither requires nor accepts anything outside them.
Stockist statements
The original file as received, plus the normalised records extracted from it.
Product master
Your catalogue, and the stockist-name mappings that resolve to it.
People
MR and Area Manager names, work contact details, and role assignments.
Activity
Submission timestamps, approval decisions, and the notes attached to them.
Access control
Who can see what
Visibility follows the same role model that drives the approval chain, so there is one set of rules to reason about rather than two.
| Role | Can see | Can change |
|---|---|---|
| Medical Representative | Only their own assigned stockists and their own submissions | Their own uploads and mapping confirmations, until approved |
| Area Manager | All submissions from the MRs reporting to them | Approve or reject submissions, with a note |
| Leadership | Approved data across the territories in their scope | Nothing — analysis is read-only by design |
| Administrator | Configuration, user and stockist assignments | Users, roles, assignments and the product master |
Submissions
How a statement reaches us
Statements are uploaded directly to the platform by a signed-in user over an encrypted connection. No third-party messaging or file-transfer service sits in the middle, so there is one path to audit rather than several.
The original file is retained exactly as it arrived, alongside the records extracted from it. That matters more than it sounds: it means a figure on a dashboard can be traced back to the document a stockist actually sent, months later.
Every submission then enters the Area Manager queue. Nothing appears in reporting until it has been approved there — the same control that makes the numbers defensible is what stops unreviewed data reaching an audience.
- Signed-in upload only
- Original file retained
- Approval before reporting
- No third-party carrier
Infrastructure
Hosting, encryption and retention
Deliberately left unfilled rather than estimated. Each row below needs a verified answer before this page goes live.
| Item | Value |
|---|---|
| Hosting provider | To be confirmed |
| Hosting region | To be confirmed |
| Encryption in transit | To be confirmed |
| Encryption at rest | To be confirmed |
| Backup cadence | To be confirmed |
| Backup retention | To be confirmed |
| Recovery objective | To be confirmed |
| Data retention on cancellation | To be confirmed |
Sub-processors
| Party | Purpose | Processing location |
|---|---|---|
| Cloud hosting | Application and database hosting | To be confirmed |
| Email delivery | Notifications and statements | To be confirmed |
Disclosure
Reporting a problem
If you believe you have found a security issue in PharmeXa, email ankur.patel@pharmexa.in with enough detail to reproduce it. We will acknowledge the report and keep you informed while it is being addressed.
Please do not test against a live customer deployment. If you need an environment to demonstrate something, ask and we will arrange one.
For how data is used rather than how it is protected, see the privacy policy.