Our approach
We use risk-based administrative and technical practices intended to protect information entrusted to us. Controls are selected for the engagement, data sensitivity, delivery model and agreed client requirements. This page describes our general approach; specific controls should be documented in the applicable contract or security schedule.
Confidentiality by agreement
We can enter into a mutual or client-provided non-disclosure agreement before receiving sensitive project details. Engagement documents should define permitted use, access, disclosure, return or deletion, and any special handling requirements. Access is intended to be limited to people and approved providers who need the information for agreed work.
Information handling
- Agree practical channels and repositories for project information.
- Use role-appropriate access and authentication on systems used for delivery.
- Separate client work logically and avoid unnecessary copies of sensitive material.
- Use version control and review practices appropriate to software and documentation.
- Retain and dispose of project information according to contractual and legal needs.
Sensitive and regulated data
Do not send PHI, patient records, credentials, production secrets or export-controlled information through the public contact form or ordinary email. If an engagement requires sensitive or regulated data, we first need to agree its necessity, permitted use, secure transfer, storage, access, retention and contractual requirements. We may ask for de-identified, redacted or synthetic data instead.
Service providers and remote work
Delivery may use vetted cloud, communication, development or business service providers. Appropriate provider terms, access settings and client requirements should be considered before confidential information is placed in a system. Remote work should follow the same need-to-know and secure-access expectations as office-based work.
Security events
Suspected security events should be reported promptly. We aim to assess relevant facts, contain and remediate the issue, preserve appropriate records and communicate with affected clients as required by the applicable agreement and law. Contractual notice contacts and timelines should be defined for engagements with specific incident obligations.
Certifications and assurance
This page does not claim that Predetics or Pharmadocx Consultants holds ISO 27001, SOC 2, HITRUST or another information-security certification or attestation. References elsewhere to standards describe services or client work, not our own certification. If formal assurance is required, ask us what current evidence is available before contracting.
Security enquiries
To discuss confidentiality requirements, request available security information or report a suspected issue involving our systems, email [email protected]. Please do not include sensitive evidence in the first message.
