Trust & security

Phial is built for organisations whose stock gets inspected, so it's built to be checked. This page answers the questions your managers, IG leads and IT reviewers will ask — and we're happy to go deeper on request.

Certifications and registrations

Cyber Essentials

Certified against the UK government's Cyber Essentials scheme, renewed annually.

NHS DSPT

Registered on the NHS Data Security and Protection Toolkit, reviewed annually.

ICO registered

Registered with the Information Commissioner's Office as a data controller and processor.

Only the data it needs, by design

Phial manages stock, not people. Nothing about your patients, clients or customers is ever entered into or stored by the system. Here is the complete picture of the data Phial holds for your organisation:

What we storeWhy
Staff name, work email, optional mobileSign-in, permissions, alerts and reminders
Organisation details (name, contact email)Your account and settings
Product catalogue (name, type, pack details)What your organisation stocks
Batches: numbers, expiry dates, quantities, locationsThe stock record itself
Fridge temperature readings (value, time, recorded by)Your cold-chain compliance log
Movement history (received, used, corrected, disposed)Your permanent audit trail

That's the whole list. No special category data, no patient or customer records, no clinical or case records — which keeps your information governance for Phial short and simple.

Where your data lives

  • Database and authentication hosted in the European Union (Ireland)
  • Encrypted in transit (TLS) and at rest
  • Daily automated backups of the database
  • Data returned or deleted on request when you leave

How it's protected

  • Every organisation's data is isolated at the database level (row-level security)
  • Role-based access — admins control who can do what
  • Staff join by single-use invite links that expire after 7 days
  • Multi-factor authentication on all infrastructure accounts

Sub-processors

Phial runs on a small number of established infrastructure providers, each covered by a data processing agreement:

ProviderPurposeData location
SupabaseDatabase and authenticationEuropean Union (Ireland)
VercelWebsite and application hosting; cookieless website analyticsGlobal CDN (static assets only — no organisation data)
ResendEmail delivery (digests, reminders, sign-in emails)European Union

Working with your IT team

Phial runs in the browser with nothing to install. If your network uses web filtering, ask your IT support to allow phial.health and *.phial.health. We're happy to complete your security questionnaire or supplier assurance form — usually same week.

Documents on request

Data processing agreement (DPA) · data protection impact assessment (DPIA) summary · DTAC submission pack · clinical safety (DCB0129) summary · Cyber Essentials certificate. Email hello@phial.health.

Questions or concerns

For anything security or privacy related — including data protection complaints, which we acknowledge within 30 days — contact hello@phial.health. To report a suspected vulnerability, use the same address with "security" in the subject line and we'll respond within one business day.