● Data Security

Data Security
&
Governance

Drug and alcohol testing data — and functional impairment assessment data — is sensitive health-adjacent information. It requires the same standards applied to medical records: controlled access, secure storage, complete audit trails, defined retention, and clear governance at every level.

Both NEOVAULT® and DRUID® are built with this reality as a structural requirement, not a product feature. Security and privacy are embedded in the platform design. Your organization's data remains under your control, with access governed strictly by role, site, and organizational hierarchy.​

For organizations managing contractors across multiple sites and projects, the data governance structure ensures that each entity's information remains appropriately separated, with visibility aligned to the contractual relationship and the level of authority required.​

Role-Based Access — By Design

● PRIVACY COMMITMENT

Individual worker test results and impairment data are accessible only within the defined role structure. Aggregated and de-identified reporting is available for trend analysis and governance oversight without exposing personal records unnecessarily.

Not everyone should see everything. Access in both platforms is structured by role: supervisors see their team; site managers see their site; WHS leads see their portfolio; senior leaders see what they need for governance oversight. Individual worker data is not over-exposed at any level of the organisation.​

International Data Security Certifications

At Neopharma Technologies, we are committed to maintaining the highest levels of data security, privacy and compliance. Our adherence to key international certifications and standards aligns with our commitment to protecting our clients' sensitive information and maintaining their trust by meeting the highest international standard for security, privacy, and regulatory compliance.

ISO 27001
ISO 27001

The ISO 27001 certification confirms Neopharma's adherence to global best practices for Information Security Management Systems (ISMS). This ensures that all information is protected according to the highest international standards.

SOC 2 Type II
SOC 2 Type II

SOC 2 Type 2 certification ensures Neopharma processes and protects customer data in a highly secure and private manner based on Trust Services Criteria.

EU Compliant
EU Compliant

GDPR compliance confirms that Neopharma meets strict global standards for data protection, privacy, and security across its systems.

HIPAA
HIPAA

HIPAA compliance ensures that all medical and patient data is handled securely and meets federal regulations for healthcare data protection.

Encrypted Storage

All test records, chain of custody data, and impairment assessment results are stored with encryption at rest and in transit. Data is never held in an unprotected state.

Role-Based Access

Access permissions are configured by site, team, and contractor group — with delegated structures for multi-site organisations ensuring the right people see the right information.

Full Audit Trail

Every action taken within the platform is logged with a timestamp and user identity. Who did what, when, and on which record is always traceable — for internal review or external scrutiny.

Contractor Data Separation

Contractor workforce data is appropriately segmented. Host employers and contractors access only their relevant records, with governance boundaries enforced throughout.

Retention Governance

Data retention settings are configurable to meet your organisation's policy requirements and relevant legislative obligations. Retention schedules are enforced automatically.

Configurable Alerts

Non-negative alerts, elevated impairment flags, and escalation notifications are configured to delegated authorities — ensuring the right people are informed at the right time.

● GOVERNANCE ARCHITECTURE

→ Configurable to your organisational structure

Notification Rules

Escalation to Delegated Authorities

Non-negative results, elevated impairment flags, and stand-down actions trigger notifications to the configured authority at each level — supervisor, site manager, WHS lead, or senior leader — based on your policy and delegation structure.

Your workers' data is sensitive. It deserves a platform built around that fact.

View Security Documentation
Neopharma Technologies
EU CompliantISO 27001HIPAA CompliantSOC2 Type 2
Contact

Australia: 1800 636 8378

USA/Canada: 1844 636 8378

Locations

Perth, Australia

Utah, USA

Kuala Lumpur, Malaysia


© 2026 Neopharma Technologies. All Rights Reserved

Privacy Policy