Trust

Security & data

Built for pharmacies. Designed for trust.

PharmStack is designed to handle pharmacy operations safely. Customer data at rest stays in Sydney. Tenants are isolated at the database layer. Application controls are backed by the platform, not promises alone.

Key commitments

At a glance

  • Primary pharmacy data at rest is hosted in Sydney
  • Tenants are isolated with role-based access and database-level controls
  • Your data is not used to train public or shared AI models
  • The platform is designed to minimise sensitive clinical data

Where your data lives

  • Customer pharmacy data at rest is primarily hosted in Sydney-region cloud infrastructure
  • Application processing is configured to run in Sydney
  • Document AI processing uses Standard Azure OpenAI deployments in Australia East
  • Each pharmacy account is isolated using role-based permissions and database-level access controls, including row-level security
  • Data is not shared between pharmacies

Authentication

  • User authentication is provided through a third-party identity provider
  • Optional multi-factor authentication; MFA is available but not currently mandatory for every account
  • Compromised-password detection and account lockout after repeated failed attempts
  • Secure session management; PharmStack does not store users’ plaintext passwords

Encryption and secrets

  • Information is encrypted in transit using provider-managed TLS
  • Integration credentials and provider API keys stored by PharmStack are encrypted using AES-256-GCM
  • Staff passcodes are stored using password hashing rather than as readable values
  • Pharmacy documents are stored privately and are not exposed through permanent public URLs

How AI is used

  • AI-assisted answers are generated from your pharmacy's documents and configured workflows, and are designed to support (not replace) pharmacist judgment
  • If something isn’t covered, the system responds cautiously and can prompt verification or escalation, not open-web guessing
  • Your data is not used to train public or shared AI models
  • AI providers process submitted information only to provide, secure and monitor the service, subject to their contractual retention and abuse-monitoring arrangements
  • AI outputs are designed to assist pharmacists and should be reviewed before being relied upon

What data is shared

  • We minimise what is shared with external services
  • AI processing uses only the information needed to answer a question
  • SMS notifications use ClickSend; message content may include health-related information selected by the pharmacy
  • Sensitive clinical data is minimised

How we handle overseas vendors

Core pharmacy data is hosted in Sydney-region cloud infrastructure, and document AI processing runs in Australia East. Other providers may process information in the United States, European Union, Singapore, the Philippines, and through global edge or support infrastructure. That processing can include storage, support access, analytics, messaging, authentication, or data in transit, depending on the service.

We use available contractual, organisational, regional, and technical safeguards. Customer contracts may impose tighter residency or provider terms. For provider-level detail, see our Privacy Policy.

Data handling approach

  • Designed for pharmacy operational workflows
  • Avoids unnecessary sensitive data
  • Updates to your documents are reflected in future answers generated from your data

Operational security

  • Server-side role and pharmacy-membership checks
  • Private document storage with signed access links
  • Authenticated and signature-verified webhook handling
  • Encrypted third-party credentials
  • Short-lived authentication tokens for realtime features
  • Feature-specific activity and compliance records

Access and isolation

  • Secure access per pharmacy account
  • Role-based user permissions within each pharmacy
  • Database-level controls, including row-level security, help keep pharmacy accounts separated
  • We maintain a data-breach response process aligned with the Notifiable Data Breaches scheme

Built for how pharmacies work

PharmStack is built by pharmacists, for pharmacists. It fits into your existing workflow, without introducing new systems or risk.

Questions?

We're happy to walk through how PharmStack handles your data and how it would work in your store or group.

For legal detail, see our Privacy Policy.