PharmaLedger.org
Book a consultation
Trust Center & Operations

Transparency, by design.

Our governance documents, compliance posture, technology, and bylaws — open to every member, regulator, and researcher who wants to verify how the trust fabric is run.

Platform status

Verifiable by architecture.

All Systems Operational
AWS
Cloud-native, serverless platform
Multi-tenant SaaS or self-hosted
Hash-chained
Tamper-evident audit trail, independently validated
Open source
GitHub: pharmaledgerassoc
GxP
Qualified quality management system
How the platform is run
PTP Production LWAoperational
PTP Production Resolver Cacheoperational
PTP Production Backend APIoperational
PTP Production Portaloperational
PTP Production SSOoperational
PTP VAL - LWAoperational
PTP VAL - Frontend portaloperational
PTP VAL - Backend API healthoperational
PTP VAL - Cache gateway healthoperational
pharmaledger.orgoperational
Updated 21 Jul, 19:15 UTCFull status & history →
Governance

A neutral, member-governed network.

Decisions about the platform are made by an elected board, ratified by the membership, and recorded with minutes that anyone can read.

Structure
Member-governed

Non-profit association, headquartered in Zurich

Integrity
Tamper-evident audit trail

Hash-chained history, independently validated

No token
No token, no cryptocurrency

A cloud platform, not a blockchain or public chain

Code
Open source

Published on GitHub: pharmaledgerassoc

Governance & milestones
Adopted
Association Bylaws
Charter, voting rules, and membership tiers
Published
Adopted
Antitrust & IP / Open-Source policies
Member competition guardrails · contribution framework
In force
Adopted
Quality Management System SOPs
Product SDLC & validation, deviation, document control
In force
Qualified
ePI product qualification & AstraLabel launch
GMP-qualified electronic product information
Delivered
Technology, plainly stated

Yes — it’s a cloud-native platform, not a blockchain.

We talk about a "trust ecosystem" because it names the guarantees — verified, standards-based, auditable — rather than the mechanism. But a transparency page should be plain about the mechanism.

The platform is a cloud-native, serverless application on AWS that resolves GS1 Digital Link identifiers and unifies the EU Digital Product Passport and EPCIS 2.0. Trust comes from a cryptographically verifiable, tamper-evident audit trail — a hash-chained history of every change, independently validated by an external audit log — rather than from a blockchain. The earlier Quorum / OpenDSU approach has been retired. There is no token and no cryptocurrency, and the platform can run as managed SaaS or be self-hosted in your own cloud.

Read the architecture reference
Platform

Cloud-native, serverless on AWS. Multi-tenant SaaS or self-hosted.

Integrity

Tamper-evident audit trail: hash-chained history, independently validated.

Standards

GS1 Digital Link, EU Digital Product Passport, EPCIS 2.0, HL7 FHIR.

Code

Open source. Published on GitHub: pharmaledgerassoc.

Compliance

Built for regulated environments.

EU
GDPR

Data minimization by design; encryption with customer-managed keys; least-privilege, role-based access.

GxP
GxP quality framework

Documented Quality Management System with SOPs spanning product SDLC & validation, deviation, document, and identity & access management.

21
21 CFR Part 11

Electronic records and signatures, relating to clinical workflows (AstraEngage platform — coming soon).

GMP
GMP-qualified

The ePI product (AstraLabel) is GMP-qualified for production use in regulated environments.

A11Y
Accessibility (WCAG 2.2)

Patient-facing ePI is assessed against WCAG 2.2 international accessibility standards — text-to-speech, font scaling to 300%, and screen-reader support.

Regulation
AstraLabel
AstraTrace
AstraEngage
GDPR
✓ Conformant
✓ Conformant
✓ Conformant
EU IDMP · FHIR
✓ Aligned
DSCSA · FMD
Designed to support
21 CFR Part 11
Coming soon
GxP
✓ In scope
✓ In scope
✓ In scope

Full per-product control mappings are versioned in the document library.

Document library

Bylaws, policies, and architecture, in plain text.

PDF
Association Bylaws
Charter · Voting rules · Membership tiers
CurrentPDFDownload
PDF
Antitrust Compliance Policy
Member competition guardrails
CurrentPDFDownload
PDF
Intellectual Property & Open-Source Policy
Open-source contribution framework
CurrentPDFDownload
PDF
GDPR & Data Privacy Framework
Data minimization by architecture · member-controlled storage
CurrentPDFDownload
MD
Architecture Reference
Cloud-native platform · GS1 Digital Link · EPCIS 2.0 · verifiable audit trail
CurrentDocsDownload
PDF
Quality Management System SOPs
Product SDLC & validation · deviation · document control
CurrentPDFDownload
PDF
Identity & Access Management SOP
Member identity and access controls
CurrentPDFDownload
PDF
Business Continuity & Technical Security SOPs
Business continuity · technical security management
CurrentPDFDownload
PDF
Standards Conformance Reference
GS1 Digital Link & 2D DataMatrix · EU IDMP · HL7 FHIR
CurrentPDFDownload
PDF
Membership Application & Onboarding Kit
For prospective members
CurrentPDFDownload
Browse all documents
Contact

Who to ask.

Named channels — because a transparency page that ends in a dead end isn't one.

Data protection

GDPR inquiries & data-subject requests, handled by the Data Protection Officer.

Regulators

Liaison channel for agencies and regulatory inquiries.

Security

Coordinated vulnerability disclosure for the open-source codebase.

Research & press

Academic access, citations, interviews, and everything else.