Security and procurement

Your client's security review, answered.

Your client's reviewers will ask how its data is kept apart, who can get in, and what is logged. Each client's data sits behind two separate checks, and every answer below names the mechanism behind it.

Certification status, contract terms, retention, and subprocessors are provided on request, as they stand today.

Agency teamSigned in once

Switch client: rules, data, and brand change with it

By permission
Bramblewood PharmaVeeva Vault CRMIn person + virtual
Own rulesOwn dataOwn brand
Tidecrest BioSalesforceIn person + hybrid
Own rulesOwn dataOwn brand
Hollowbrook TherapeuticsVeeva CRMIn person
Own rulesOwn dataOwn brand
In short

Four questions reviewers ask first.

Each answer names the mechanism behind it.

Keep each client’s data separate

Organization context is enforced in application queries and PostgreSQL row-level security policies.

Limit access by user and role

Authentication, organization membership, roles, and current permissions are evaluated before access is granted.

Keep optional AI inside the same limits

The assistant works only within the signed-in user’s organization and permissions.

Require a person before records change

The assistant can suggest a change. An authorized person must confirm it before the program record changes.

Tenant isolation

Keep every client workspace inside its own data and access boundary.

Isolation is enforced twice: PostgreSQL row-level security policies on tenant tables and organization scoping in the application’s own queries. Neither layer relies on the other.

Fail-safe data access: A request without tenant context matches zero rows. The database returns nothing rather than another organization’s data.
No fallback tenant: Requests to an unrecognized domain stop at 404. There is no default client workspace.
Gated cross-organization administration: Platform-administrator cross-organization access is explicitly gated and logged.
Encryption

Protect data in transit, at rest, and in stored credentials.

Program data is encrypted in transit and at rest. Integration credentials get their own layer of encryption before they are stored.

Data in transit: TLS 1.2/1.3 with HSTS enforced.
Data at rest: Managed-database and object-storage encryption.
Integration credentials: AES-256-GCM envelope encryption before storage, with keys held in a cloud KMS the application can use but not export. Stored credentials are never returned by any API and never logged.
Access and authentication

Apply current user and role permissions.

Deactivate a user or change a role, and it takes effect on their next request. It doesn't wait for a token to expire.

SAML 2.0 SSO: Entra ID, Okta, or any standard identity provider, configured per organization
Short-lived sessions, revocable server-side
Access re-checked on every request: a role change applies immediately, no waiting on token expiry
Passwords hashed with bcrypt; login rate-limited and lockout-protected
Platform admin, agency, and pharma-client access kept separate
Role administration restricted to platform admins
Audit history

Keep a clear history of important changes.

An append-only audit log and supported program history help reviewers investigate what changed without reconstructing the event from separate systems.

Append-only audit log: Captures who did what, from where, and what changed, including previous and updated field values and correlation IDs.
Program decision history: Retains the actor, timestamp, previous value, updated value, and relevant decision context where supported.

Each rule’s exceptions are recorded with who approved them and why. See how each client’s rules are recorded.

Change history for one closed program: expense corrections, the close, the spend allocation, and the post-program certification, each with a name and a time.
Event closed by Maya ChenSeptember 15, 2026 at 01:56 PM ET
Infrastructure

Built for day-to-day operation and recovery.

The platform runs in a U.S. AWS region.

Private database network: Databases have no public access and are reachable only by the application.
Edge and application protection: Edge protection, a web-application firewall, and strict security headers sit in front of the application.
Short-lived deployment identity: Deployments authenticate through federated identity; the pipeline contains no long-lived cloud keys.
Backup and recovery: Automated database backups include point-in-time recovery and deletion protection.
Integration boundaries

Keep integration credentials within each client workspace.

Customer-configured integrations are enabled per organization. Credentials receive the encryption controls described above, and users remain inside their existing organization and permission boundary.

Supported connection patterns:

IntegrationWhat movesImportant note
Veeva / Salesforce CRMApproved healthcare professional (HCP) records in; supported event and attendance activity out.Configured per organization.
ZoomAttendee identity for join links; attendance returned to the program.Virtual and hybrid programs only.
Google PlacesTyped venue queries only.No HCP data; used for venue autocomplete.
PDF and email servicesDocument generation and email templating.Run inside Pharmagin’s application infrastructure.
See Integrations
Optional AI

What the assistant can see, where data goes, and when a person must confirm.

The assistant is off until it is turned on for a client. It prepares summaries, speaker checks, and attendance suggestions. It does not set policy, approve a program, or make a compliance call.

  1. 1

    A person asks

    A signed-in user starts a task the assistant can do.

  2. 2

    Access is checked

    Pharmagin applies that person's client workspace, role, and permissions.

  3. 3

    The model is called

    The request goes to the model provider with the prompt, the records this person may see, and any file they attached.

  4. 4

    A person reviews

    The answer comes back to the person who asked.

  5. 5

    A person confirms

    Nothing in a program record changes until an authorized person confirms it.

Off until turned on for a clientLimited by roleExisting permissions applyWeb search off by defaultA person confirms every change
Access stays bounded: AI tools operate within the signed-in user’s existing platform permissions and organization boundary.
The data path is disclosed: Relevant prompts, conversation context, authorized tool results, and user-supplied attachments may be sent to the configured model provider.
Changes require confirmation: Supported changes require a person to confirm before the platform executes them. Outbound web search is a separate option and is off by default.

The data terms are confirmed with each client before the assistant is turned on.

How Pharmagin uses AI
Current procurement information

Send us the question your reviewers are stuck on.

Ask for certification status, data-processing terms, or retention. We also answer on incident response, recovery targets, and subprocessors. Each answer says what’s live, what’s planned, and what doesn’t apply.

Privacy questions: [email protected]

We never present a documented control as a certification.