Trust & security
Phial is built for organisations whose stock gets inspected, so it's built to be checked. This page answers the questions your managers, IG leads and IT reviewers will ask — and we're happy to go deeper on request.
Certifications and registrations
Cyber Essentials
Certified against the UK government's Cyber Essentials scheme, renewed annually.
NHS DSPT
Registered on the NHS Data Security and Protection Toolkit, reviewed annually.
ICO registered
Registered with the Information Commissioner's Office as a data controller and processor.
Only the data it needs, by design
Phial manages stock, not people. Nothing about your patients, clients or customers is ever entered into or stored by the system. Here is the complete picture of the data Phial holds for your organisation:
| What we store | Why |
|---|---|
| Staff name, work email, optional mobile | Sign-in, permissions, alerts and reminders |
| Organisation details (name, contact email) | Your account and settings |
| Product catalogue (name, type, pack details) | What your organisation stocks |
| Batches: numbers, expiry dates, quantities, locations | The stock record itself |
| Fridge temperature readings (value, time, recorded by) | Your cold-chain compliance log |
| Movement history (received, used, corrected, disposed) | Your permanent audit trail |
That's the whole list. No special category data, no patient or customer records, no clinical or case records — which keeps your information governance for Phial short and simple.
Where your data lives
- Database and authentication hosted in the European Union (Ireland)
- Encrypted in transit (TLS) and at rest
- Daily automated backups of the database
- Data returned or deleted on request when you leave
How it's protected
- Every organisation's data is isolated at the database level (row-level security)
- Role-based access — admins control who can do what
- Staff join by single-use invite links that expire after 7 days
- Multi-factor authentication on all infrastructure accounts
Sub-processors
Phial runs on a small number of established infrastructure providers, each covered by a data processing agreement:
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database and authentication | European Union (Ireland) |
| Vercel | Website and application hosting; cookieless website analytics | Global CDN (static assets only — no organisation data) |
| Resend | Email delivery (digests, reminders, sign-in emails) | European Union |
Working with your IT team
Phial runs in the browser with nothing to install. If your network uses web filtering, ask your IT support to allow phial.health and *.phial.health. We're happy to complete your security questionnaire or supplier assurance form — usually same week.
Documents on request
Data processing agreement (DPA) · data protection impact assessment (DPIA) summary · DTAC submission pack · clinical safety (DCB0129) summary · Cyber Essentials certificate. Email hello@phial.health.
Questions or concerns
For anything security or privacy related — including data protection complaints, which we acknowledge within 30 days — contact hello@phial.health. To report a suspected vulnerability, use the same address with "security" in the subject line and we'll respond within one business day.