Infrastructure security
Unique production database authentication, restricted encryption-key access, enforced account authentication.
Security & Trust
PharmaGuide handles personal health information on behalf of pharmacies across Canada. This page is the short version; the live trust centre carries the current control status and the documentation your security review will ask for.
Visit the trust centre
PharmaGuide maintains a SOC 2 Type II report covering the Security trust services criterion, issued following an independent examination by a licensed CPA firm. The current report is available under NDA on request.
Request it through thetrust centre, which handles the NDA before release.
PharmaGuide commissions independent penetration testing, with retest reports covering remediation. Available under NDA alongside the SOC 2 report.
All personal health information is stored and processed in Canada.
Production data is hosted on Google Cloud Platform in thenorthamerica-northeast2 region, in Toronto. Patient data does not leave the country in the course of normal operation — it is not replicated to US regions, and it is not processed outside Canada.
This matters in a privacy review. Wherever personal health information crosses the border, the review has to reason about cross-border disclosure and, depending on the province, justify it. Data that never leaves Canada removes that question instead of answering it.

PharmaGuide's privacy programme is aligned to PIPEDA, Canada's federal private-sector privacy legislation, and to provincial health privacy legislation includingPHIPA in Ontario.
Pharmacies are regulated provincially, so the operative legislation depends on where you practise. If your review needs the specifics for a particular province, ask and we will answer against that province's legislation rather than a general statement.
See also our privacy policy andterms of service.
Monitored continuously and published live, not asserted once a year.
Unique production database authentication, restricted encryption-key access, enforced account authentication.
Anti-malware coverage, employee background checks, an acknowledged and enforced code of conduct.
Data encryption, vulnerability and system monitoring, recurring control self-assessments.
Continuity and disaster-recovery plans, established and tested, with configuration management.
Data retention and classification procedures, and customer data deleted on departure.
Current status for every control is on thetrust centre — including the ones not summarised here.
If you believe you have found a security vulnerability in a PharmaGuide product, emailsupport@pharmaguide.ca. Please include enough detail to reproduce it. We will acknowledge your report and keep you informed while we investigate, and we will not pursue action against good-faith research.