generated: '2026-08-13' method: searched source: https://pharmaforceiq.com/security-center/ note: >- Standards asserted here are the company's own published compliance and privacy posture, read from the PharmaForceIQ Security Center. There is no public API contract for this provider, so every API-level / cross-cutting technical standard (OAuth2, OIDC, RFC 9457, pagination, idempotency, FHIR, SCIM, OData) is recorded as unknown rather than false — absence of a public spec is not evidence of non-conformance. standards: - id: soc2-type-ii conforms: true evidence: 'Security Center: "We have secured SOC 2 Type II and ISO 27001 certifications, and we follow industry best practices in security monitoring, access control, and incident response."' source: https://pharmaforceiq.com/security-center/ - id: iso-27001 conforms: true evidence: 'Security Center: "secured SOC 2 Type II and ISO 27001 certifications"; "Audited systems are in place to ensure data confidentiality and integrity."' source: https://pharmaforceiq.com/security-center/ - id: hipaa conforms: true evidence: 'Security Center: "PharmaForceIQ is fully HIPAA compliant, and all relevant systems are configured to support HIPAA-mandated security and privacy controls."' source: https://pharmaforceiq.com/security-center/ - id: gdpr conforms: true evidence: 'Security Center: "our privacy framework prioritizes data minimization and anonymization to maintain compliance with global regulations like GDPR and CCPA."' source: https://pharmaforceiq.com/security-center/ - id: ccpa conforms: true evidence: 'Security Center describes CCPA rights and strict auditing processes; the site publishes a dedicated CCPA request form at /ccpa-request-form/.' source: https://pharmaforceiq.com/security-center/ - id: nai-code-of-conduct conforms: true evidence: Security Center states compliance with the Network Advertising Initiative (NAI) framework. source: https://pharmaforceiq.com/security-center/ - id: daa-principles conforms: true evidence: Security Center states compliance with the Digital Advertising Alliance (DAA) framework. source: https://pharmaforceiq.com/security-center/ - id: tls-in-transit conforms: true evidence: 'Security Center: TLS for data in transit, AES-256 encryption at rest. Independently probed: pharmaforceiq.com negotiates TLSv1.3 (see security/aktana-domain-security.yml).' source: https://pharmaforceiq.com/security-center/ - id: oauth2 conforms: unknown evidence: no public OpenAPI or auth documentation to evaluate - id: oidc conforms: unknown evidence: /.well-known/openid-configuration returns 404 on every reachable host - id: rfc9457-problem-details conforms: unknown evidence: no public API contract - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on pharmaforceiq.com and aktana.com - id: rfc8594-sunset-header conforms: unknown evidence: no public API contract, no published deprecation policy summary: published_certifications: - SOC 2 Type II - ISO 27001 regulatory_frameworks: - HIPAA - GDPR - CCPA self_regulatory_programs: - NAI - DAA technical_api_standards_evaluated: false reason: no public machine-readable API contract exists for this provider