PharmaLedger.org
预约咨询

AstraTrace — Legal & Compliance

A blockchain-verified audit trail for your pharmaceutical supply chain.
Built to satisfy health authority requests — before they become demands.

AstraTrace is a GxP-qualified, SDLC-ready supply chain intelligence platform with a blockchain-verified audit trail, a full compliance documentation package, and a DPA governed under Swiss law.

GxP-qualifiedBlockchain-verified audit trailDPA — Swiss lawSOC 2 Type II scope H2 2026EPCIS 2.0 / GS1 standards

Request a conversation

We respond within one business day.

No spam. No sales automation. Stefan responds personally.

COMPLIANCE POSTURE
GxP-qualified platformHyperledger Fabric blockchainSwiss nonprofit · CHE-178.875.143SOC 2 Type II scope H2 2026DPA available · Swiss law governing

The compliance landscape

Three compliance requirements that converge on the supply chain data layer.

  • 01DSCSA (USA) and FMD (EU) — serialisation compliance is established. Supply chain intelligence is the next expectation. DSCSA and FMD mandated serialisation and authentication. Regulatory agencies in both jurisdictions are now moving toward supply chain transparency expectations — requiring manufacturers to demonstrate not just product authenticity, but supply chain visibility and shortage prevention capability. A GxP-qualified audit trail that spans the distribution chain is the compliance posture these expectations require.
  • 02Health authority data requests are increasing in frequency and specificity. Health authorities in multiple jurisdictions are requesting supply chain data — batch locations, distribution timelines, inventory positions — with increasing regularity. Legal and compliance teams need a platform that can respond to these requests accurately and rapidly, with an audit trail that demonstrates data integrity. Manual responses from fragmented ERP systems carry both accuracy and timeliness risk.
  • 03CSRD supply chain reporting obligations create a new data collection requirement. The EU Corporate Sustainability Reporting Directive requires supply chain emissions and logistics data that most organisations currently cannot produce from their existing systems. AstraTrace Enterprise includes CSRD analytics derived from the EPCIS data layer — converting a new compliance obligation into a standing data availability.

The compliance documentation package

What PLA provides for vendor qualification.

Blockchain-verified audit trail

Every supply chain event recorded on Hyperledger Fabric — an enterprise-grade, permissioned blockchain. Immutable audit trail. Tamper-evident event history. Each event is cryptographically verifiable without requiring counterparties to share raw data.

GxP qualification documentation

Full IQ/OQ/PQ documentation package. Qualification summary report. Platform maintained in a qualified state under a documented change control process. Ongoing change control documentation provided as part of the service.

DPA & security documentation

Standard DPA governed under Swiss law. Data processing in Switzerland and EU. SOC 2 Type II scope H2 2026 — security overview available now. Information security policy, access control documentation, incident response policy.

Governance and data sovereignty

Swiss nonprofit. Swiss law. No private ownership.

PharmaLedger Association is a Swiss nonprofit association (Verein) registered under Swiss law in Zürich (CHE-178.875.143 MWST). Supply chain data processed through AstraTrace is held on Swiss and EU infrastructure. There is no private ownership, no investor pressure, and no exit event that changes the data governance posture of the platform.

Governing law and jurisdiction

Swiss law. Standard contracts use Basel or Zürich jurisdiction. England & Wales governing law is not in standard terms. PLA has concluded contracts under Swiss law with multiple Top-20 MAHs whose legal teams have reviewed and accepted the standard terms.

Data sovereignty

Supply chain event data is processed and stored in Switzerland and EU-based infrastructure. No transfer to non-EU/EEA jurisdictions without an appropriate mechanism (SCCs or adequacy decision). Data residency specifics documented in the DPA, available at pre-signature stage.

The Hyperledger Fabric architecture

Why a permissioned blockchain is the right architecture for pharmaceutical supply chain data.

Public blockchain architectures require every participant to have access to all data on the chain — unsuitable for commercially sensitive pharmaceutical supply chain information. Hyperledger Fabric is a permissioned blockchain: participants see only the data they are authorised to see, governed by the network rules set by PLA as the nonprofit infrastructure operator.

This architecture satisfies two requirements simultaneously: an immutable, cryptographically verifiable audit trail for compliance and legal teams, and strict data access control for commercial sensitivity. Neither property compromises the other.

Common questions

Frequently asked questions

What does 'blockchain-verified' mean in the context of a compliance audit?
Every EPCIS supply chain event recorded in AstraTrace is written to a Hyperledger Fabric blockchain ledger. The ledger is append-only and cryptographically chained — once written, an event cannot be altered or deleted without breaking the chain, which would be detectable. In a compliance audit, this means the audit trail is tamper-evident by design, not just by policy. The verifiability can be demonstrated to auditors and health authorities without requiring them to trust PLA's word.
Our standard vendor contract requires English law. Is Swiss law negotiable?
Swiss law is PLA's standard governing law — it is not negotiable as a blanket position. However, PLA has concluded contracts with multiple Top-20 MAHs whose standard position was English law. The resolution in every case has been Swiss law with ICC Switzerland or Swiss Chambers arbitration, which satisfies the international arbitration requirement that usually underlies the English law preference. We have model contract language for this.
When a health authority requests our supply chain data, how does AstraTrace support the response?
AstraTrace includes a Regulator Portal that gives authorised health authorities direct, controlled access to the supply chain data layer relevant to their jurisdiction. This means a health authority data request becomes a data access question — not a manual extraction and reporting exercise. The portal access is provided to health authorities at no charge, which makes the data-sharing relationship bilateral and sustainable.
Does the blockchain architecture comply with GDPR right to erasure?
AstraTrace processes pharmaceutical supply chain event data — EPCIS events relating to product batches and movements. This data category does not typically include personal data as defined under GDPR (it relates to products, not individuals). Where personal data processing is involved (e.g. point-of-dispense data in certain architectures), the DPA includes the relevant GDPR compliance provisions. We assess data category specifics during the DPA negotiation.
What is the liability cap in your standard contract?
PLA's standard contract includes a liability cap expressed as a percentage of annual fees paid in the preceding 12 months. Uncapped liability provisions are not accepted in standard terms. The specific percentage is set out in standard contract terms, available on request before the commercial conversation.

Request the full compliance documentation package before the commercial conversation.

GxP qualification summary, DPA, security overview, Hyperledger Fabric architecture overview, and standard contract terms — sent in advance so your legal team reviews before any call.

Request compliance documentation