Software for making medicines closer to the patient
Local production means several smaller sites instead of one large plant. Pharmacy Flow runs a network of facilities from one database: each declares what it makes and how much, orders route to the right one, lots move between them, and every batch and unit is on the same record.
Drug shortages and supply-chain fragility have pushed governments on both sides of the Atlantic to encourage production closer to home. The operational reality of that agenda is not one big factory; it is a network of regional compounding and outsourcing facilities, each modest in size, that together cover a country. That shape has always been expensive to run because the software assumed one plant. Pharmacy Flow assumes a network.
Why local production is a software problem
A regional site making a few hundred units a day cannot carry the licence fees, implementation cost and IT staff of enterprise manufacturing software. It also cannot run on spreadsheets, because it must produce batch records, trace units, hold quarantined material, gate shipments on state licences and answer a recall in hours. Local production pencils out only when the system that does those things is affordable, multi-site by default and quick to stand up. That is the gap this platform is built for; the pricing page shows the plans and the 503B launch playbook shows the sequence.
One login, several sites: the active facility scopes the floor views; tenant-wide views roll everything up.
Facilities: what each site makes and how much
A facility is a record with a name, city and state, a status (active or planned), the list of product families it compounds and a daily capacity. Adding a family to a site or changing its capacity is an action in Settings. The batch action refuses to compound a family at a site that does not list it, so capability is not a label but a constraint. Users select an active facility for floor work; environmental readings, receiving and line stations are scoped to it, while orders, finance and insights roll up across the tenant.
Facility field
What it drives
Families compounded
Which orders can route here; which batches can be made here
Capacity per day
Utilisation, computed from trailing three-day throughput; the load-balancing rule
State
The geography rule: a capable site in the ship-to state is preferred
Status
Planned sites never receive orders
Routing orders across sites
Every order, whether from the partner API, the portal, a refill or staff entry, is assigned a facility by the same four rules in order: only capable sites qualify; a brand pinned to a capable site wins; a capable site in the ship-to state wins next; otherwise the least-utilised capable site. The reason is written on the order (for example, nearest capable site, or lowest load at 41 percent) and returned to API partners. An order can be rerouted by hand, and the Order Routing screen shows the family-by-site matrix and each site's utilisation. This is what lets a network keep cold-chain shipments short and spread load without a coordinator watching a spreadsheet.
Orders carry the facility they were routed to and why.
Moving material between sites
Lots belong to a facility. A stock transfer moves a lot between two sites in three permission-gated steps: the requesting site drafts it with quantity and reason; the sending site approves and ships it, which issues the quantity from the origin lot and writes the ledger row; the receiving site counts what arrived and books it, with any discrepancy recorded on the transfer. Each step is an event with the actor. A regional network that buys API centrally and distributes it to sites runs on this, with the same lot id and expiry following the material. See the inventory page for lots and the WMS page for receiving and putaway.
Model your network on a demo tenant
Tell us your sites, the families each makes and the states you ship to. We will set the facilities up, route a handful of orders and transfer a lot between sites while you watch.
Creating a batch inserts the finished lot in quarantine, marks the batch In Process, consumes raw lots first-expiry-first with the quantity per lot recorded, sets the BUD to the earlier of the formulation rule and the soonest component expiry, and creates the QC tests pending, all in one database transaction at the site that compounds the family. Release requires the QA permission. The batch record is identical at every site, which is what makes a network auditable as one operation rather than several. Detail is on the compounding software page.
Units are serialised at fill with an SGTIN, parcels aggregate into SSCC cartons and pallets per facility, and every station writes an EPCIS-style event with the facility on it. A recall on a lot traces every unit regardless of which site shipped it. The identifiers are explained in the serialisation guide.
One quality system, per-site evidence
Deviations, CAPAs, change controls and controlled documents are tenant-wide; environmental readings are recorded against the active facility with room, ISO class, metric, value and limit, and graded Pass, Alert or Action. Electronic signatures bind the signer's session identity and require password re-authentication at the moment of signing. A quality manager can therefore run one QMS across the network while every reading and signature says which site it came from. The 503B software page covers the cGMP expectations; the sterile compounding page covers environmental monitoring.
The quality dashboard across the tenant; readings and signatures carry their facility.
Tenancy, roles and the platform console
Pharmacy Flow is multi-tenant by design. Each operator is a tenant; every table carries the tenant id; row-level security resolves the tenant from the signed-in profile; and a trigger stamps new rows. A group standing up several regional operators can run each as its own tenant, or one tenant with several facilities, depending on whether they share licences, brands and inventory. Eight roles with permissions held in Postgres control who can release QA, sign, manage orders, buy or view finance. A separate platform console, reachable only by platform operators, provisions and suspends tenants. Detail is on security & compliance; the European framing is on the Europe page.
The policy context, sourced
We do not make claims about how much production will move or when. What can be stated is what the policy instruments are.
Whatever the pace, the operating requirement is the same: several sites, one record, affordable software. Read how to start a compounding pharmacy for the launch sequence and how to scale one for what breaks as volume grows.
Frequently asked questions
Can one tenant run several production sites?+
Yes. Facilities declare the families they compound and a daily capacity; batches can only be made where the family is listed; orders route by capability, brand pin, ship-to state and load; and lots move between sites through approved transfers.
How does routing decide which site fulfils an order?+
Four rules in order: capability, brand pin, geography (a capable site in the ship-to state), then lowest utilisation on trailing three-day load against capacity. The reason is written on the order and can be overridden by hand.
Is the batch record the same at every site?+
Yes. The same stored procedure creates the finished lot in quarantine, the In Process batch, FEFO consumption with quantities, the BUD floor and the pending QC tests, wherever the batch is made.
Should a group run one tenant or several?+
One tenant with several facilities if the sites share licences, partner brands and inventory. Separate tenants if they are separately licensed businesses. Both are supported; the platform console provisions tenants.
Does the software help with regulatory approval of a new site?+
It produces the records a site needs (batch records, quarantine and release, environmental readings, signatures, traceability) but registration, inspection readiness and the decision to compound a given product are yours and your counsel's.
Does it support the EU?+
The architecture is multi-tenant and multi-facility and the record model is jurisdiction-neutral, but ship-to validation is US-state based and there is no EU-specific regulatory module today. The Europe page sets out exactly what is and is not built.
A working platform, not a slide deck. Book a walkthrough and we'll run a real order from intake to carrier lane — or explore the public directory first, no account needed.