Pharmacy Flow is the operating system for compounding and fulfillment pharmacies. Intake → clinical review → batch → QC → serialized pack → ship → recall, on one record whose lifecycle is enforced in the database — plus a public directory of who makes, compounds and dispenses every medicine, and an RFQ marketplace.
Directory counts as shown on pharmacyflow.ai/directory, compiled from the FDA National Drug Code Directory and the NPPES registry. Trial length from the app's signup flow.
Real product capture on synthetic demo data, September 2026.
The same record structure runs a patient-specific 503A fill and a 503B office-stock batch. Pick your model to see how the flow applies.
Prescription-driven intake, DUR, patient-specific fills, state licence gating on every ship-to.
503A software →Batch records with component-lot consumption, QC testing, deviations, CAPA and change control.
503B software →Brand-scoped order API, subscriptions and refills, cold-chain parcels, a white-label partner portal.
GLP-1 fulfillment →Customer-service cases, explicit hold reasons, per-unit traceability and cold-chain evidence on delivery.
Specialty →Environmental monitoring, document control, BUD that floors at the shortest component expiry.
Sterile →One master formulation, every strength and fill volume as a controlled variant with its own cost.
HRT →Prescriber and patient records with the same formulation, batch and recall spine.
Veterinary →Pack-verify, carrier scans that cascade to the order, returns and RMA, delivery events to partners.
Mail-order →Also: inventory management, WMS & control tower, local manufacturing and Europe.
Every screenshot below is the real product. The order that arrives at stage one is the same row that ships at stage six — and the same row a recall would find at stage seven.
Orders arrive from the partner API, the partner portal, a subscription refill or a marketplace award. The API is idempotent on the partner's own order id, so a retry never creates a duplicate. Before an order is accepted, the ship-to state is checked against your licence table — no licence row, or an expired one, and the order is held rather than let through. A controlled-substance flag tightens the gate further.
order.received / order.held sent from an outbox with retries

The prescription and the order are linked rows, not a free-text note. An order cannot move into production until its prescription is in a filled state; drug-utilisation review runs on the prescription and its findings sit on the record. Pharmacist actions that need a signature go through the approvals inbox, and each signature is applied only after the signer re-enters their password.
A master formulation generates every strength and fill volume as a controlled variant with its own bill of materials and cost. Planning a batch consumes specific raw-material lots with quantities, so genealogy is a table you can query rather than a list you hope is complete. A batch enters production as In Process and only becomes Released after QC — and its beyond-use date can never exceed the shortest component expiry.


The quality system is part of the same database as production, not a binder beside it. QC tests, deviations, CAPA, change control, environmental monitoring and document control each carry their own lifecycle; the finished lot's own status graph is enforced by a trigger, so a lot on hold cannot be picked, and a lot cannot be picked before it is released.
At the fill station the line claims a released finished lot (FEFO, atomic — the same unit can never be committed twice), mints a GS1 serial for the unit and writes a commissioning event. Pack and verify each add their own event. An order cannot reach Shipped unless pack-verify passed; that rule lives in the database, not in the screen.


Parcels carry the carrier, tracking number and a cold-chain flag; temperature readings attach to the parcel. Carrier scans are de-duplicated and cascade to the order and its units, and a parcel on QA hold is never marked delivered. When delivery lands, the partner's webhook receives order.delivered.
Because every unit is serialized and every batch records which raw lots it consumed, a recall starts from any handle — a raw-material lot, a batch, a finished lot or a single serial — and resolves to the exact units, orders, patients and parcels affected. Disposition is tracked per unit. Trace & Recall and Unit Trace are standard screens, not a services engagement.

Most systems record compliance. Pharmacy Flow makes the wrong thing impossible at the row level, so an audit is a report and not a reconstruction. These are the mechanics, not slogans.
Security & compliance detail →Order and finished-lot status graphs live in an allowed-transitions table. A BEFORE UPDATE trigger rejects any move not in the graph and enforces interlocks: Shipped needs pack-verify, Packed needs a released lot. Every change writes a history row.
Signing an approval requires the signer's identity and a fresh password check at that moment. If re-authentication fails, no signature is applied. Signatures, approvals, events and audit rows are append-only.
Each dispensed unit gets a GS1 SGTIN (GTIN + serial) at commissioning and an EPCIS-style event at fill, pack, verify and ship. Serial, order number, batch number and tracking number are unique by index and issued by database sequence.
Batches record which raw-material lots they consumed and in what quantity; units record which finished lot they came from. A recall is a query across that graph, with per-unit disposition.
API intake checks the ship-to state against your licence table and holds the order when no valid licence exists. Controlled-substance orders require a licence that explicitly allows them.
Row-level security on every tenant table; role permissions stored in Postgres; anonymous writes revoked. Public endpoints are rate-limited by token bucket in the database.
A free, public directory of pharmacies and drug manufacturers, compiled from the FDA National Drug Code Directory and the NPPES national provider registry. Search a medicine, a brand, a pharmacy or a city — no account needed.
Counts as displayed on /directory; sources FDA NDC Directory and NPPES, last refreshed August 2026. Unclaimed listings are not verified by Pharmacy Flow and carry no pricing.

Income statement, receivables and payables, a weekly business review and product, geography, growth and inventory analytics are SQL views over the operational tables — not an export. Cost & margin is computed per formulation variant from the component lots a batch actually consumed. AI Insights summarises what changed and why in plain language.


A telehealth or B2B partner logs into a portal scoped to their brand: submit orders, watch shipments, manage subscriptions, see performance, read statements and open support cases. They see only their rows. Everything they submit lands in the same order table your floor works from.
Portal screens: orders, submit, shipments, track, subscriptions, catalog, performance, billing, notifications, support, settings. Telehealth order API →
There is no published price list. The platform is priced per operation by facility count and order volume, and you can try all of it first.
Be found by buyers; publish your catalog; answer enquiries; bid on RFQs.
No fee to be listed, no fee to claim.
Find your listingEvery module, your own organization, provisioned on signup or when you claim a listing.
No card required to start.
Start a free trialSingle site to multi-facility network, with the partner portal and API.
By facility count and monthly volume.
Get a quoteA web-based operating system for compounding and fulfillment pharmacies. One record carries an order from intake and eligibility through clinical review, batch production, QC release, serialized pack-verify, shipping and, if ever needed, recall. It also publishes a free public directory of pharmacies and drug manufacturers with an RFQ marketplace.
503A compounding pharmacies, 503B outsourcing facilities, GLP-1 and telehealth fulfillment pharmacies, specialty, sterile, hormone-therapy, veterinary and mail-order pharmacies, and multi-site networks. See who it's for.
Yes. Signing up, or claiming your directory listing, provisions your own organization with a 14-day free trial of the full platform. There is no fee to be listed in the directory and no fee to claim a listing.
Directory listings and claims are free. The platform is priced on request by facility count and order volume; there is no published price list. Pricing explains what is included; request a demo and we will quote it for your operation.
Order and lot status transitions are enforced by Postgres triggers from an allowed-transition table, with a history row per change. Electronic signatures require a fresh password re-authentication at the moment of signing. Every dispensed unit carries a GS1 serial with an EPCIS-style event for commission, pack, verify and ship, so a recall can be scoped per unit. Details on security & compliance.
Yes. The order API accepts orders per brand with idempotency on the partner's order id, checks the ship-to state against your licences before accepting, and pushes order.received or order.held events to the partner's webhook with retries.
A working platform, not a slide deck. Book a walkthrough on your own workflow — or start with the directory and the free trial, no call needed.
Free 14-day trial on signup · Free to claim a listing · Log in