Trust

Security & data

Built for pharmacies. Designed for trust.

PharmStack is designed to handle pharmacy operations safely. Core pharmacy data is hosted in Sydney, Australia. Each pharmacy is isolated at the database layer, with application-level security controls layered on top.

Key commitments

At a glance

  • Core pharmacy data is hosted in Sydney, Australia and encrypted at rest using AES-256
  • Each pharmacy is isolated with role-based access and database-level controls
  • Your data is not used to train public or shared AI models
  • Sensitive clinical information is used only where needed for pharmacy workflows

Where your data lives

  • Core pharmacy database and storage are hosted in Sydney-region cloud infrastructure
  • Application processing is configured to run in Sydney
  • Document AI processing uses Standard Azure OpenAI deployments in Australia East
  • Each pharmacy account is isolated using role-based permissions and database-level access controls, including row-level security
  • Pharmacy data is isolated between stores unless access is explicitly granted to an authorised multi-store or group user

Core pharmacy data is hosted on enterprise-grade, independently audited infrastructure in Sydney, Australia.

Supabase, our core database and storage provider, maintains SOC 2 Type 2 compliance and ISO 27001 certification.

Authentication

  • User authentication is provided through a third-party identity provider
  • Multi-factor authentication is available for user accounts
  • Compromised-password detection and account lockout after repeated failed attempts
  • Secure session management; PharmStack does not store users’ plaintext passwords

Encryption and secrets

  • Core pharmacy data hosted in the Sydney region is encrypted at rest using AES-256. Scheduled database backups are also encrypted at rest
  • Information is encrypted in transit using provider-managed TLS
  • Integration credentials and provider API keys stored by PharmStack are encrypted using AES-256-GCM
  • Staff passcodes are stored using password hashing rather than as readable values
  • Pharmacy documents are stored privately and are not exposed through permanent public URLs

How AI is used

  • AI-assisted answers are generated from your pharmacy's documents and configured workflows, and are designed to support (not replace) pharmacist judgment
  • If something isn’t covered, the system responds cautiously and can prompt verification or escalation, not open-web guessing
  • Your data is not used to train public or shared AI models
  • AI providers process submitted information only to provide, secure and monitor the service, subject to their contractual retention and abuse-monitoring arrangements
  • AI outputs are designed to assist pharmacists and should be reviewed before being relied upon

What data is shared

  • We minimise what is shared with external services
  • AI processing uses only the information needed to answer a question
  • SMS notifications use ClickSend for pharmacy communications
  • PharmStack is designed to minimise sensitive clinical information in SMS content and can detect likely medicine names or other sensitive information and prompt staff to reword before sending
  • Where a dispensary integration is enabled, PharmStack uses dispensing and clinical information only where needed to support pharmacy workflows

How we handle overseas vendors

Core pharmacy data is hosted in Sydney-region cloud infrastructure, and document AI processing runs in Australia East. Some supporting service providers may process limited information outside Australia depending on the service. We use contractual, organisational, regional and technical safeguards. For provider-level detail, see our Privacy Policy.

Data handling approach

  • Designed for pharmacy operational workflows
  • Avoids unnecessary sensitive data
  • Updates to your documents are reflected in future answers generated from your data

Operational security

  • Server-side role and pharmacy-membership checks
  • Private document storage with signed access links
  • Authenticated and signature-verified webhook handling
  • Encrypted third-party credentials
  • Short-lived authentication tokens for realtime features
  • Feature-specific activity and compliance records
  • Deployed behind Vercel’s global Web Application Firewall with automatic DDoS mitigation and configurable traffic controls, including blocking and rate limiting

Access and isolation

  • Secure access per pharmacy account
  • Role-based user permissions within each pharmacy
  • Designed primarily for use on authorised pharmacy workstations; remote access is controlled by the pharmacy owner or authorised administrator, with additional authentication controls available for privileged and remote access
  • Database-level controls, including row-level security, help keep pharmacy accounts separated
  • We maintain a data-breach response process aligned with the Notifiable Data Breaches scheme

Built for how pharmacies work

PharmStack is built by pharmacists, for pharmacists. It fits into existing pharmacy workflows while minimising unnecessary operational and security risk.

Questions?

We're happy to walk through how PharmStack handles your data and how it would work in your store or group.

For legal detail, see our Privacy Policy.