Back to pact.place

Security & compliance

Pact is built on a SOC 2 Type II + HIPAA-ready managed Postgres tier, with encryption at rest and in transit, IP allow-listing, private networking, and tenant isolation enforced at the substrate. This page describes the posture as it stands today — what we've shipped, and what is in progress.

In production today

In progress

Sub-processors

The complete sub-processor schedule — specific providers, certifications, DPA-on-file dates, and change-notification subscription — is published on our Trust Center or available on request at legal@pact.place. AI features (where enabled for your tenant) use Anthropic by default; no data is sent to any AI provider unless the feature is explicitly enabled for your tenant.

Retention & deletion

By default we retain customer data for the term of the contract plus 30 days for recovery. Tenants can request earlier deletion at any time; the same DSAR machinery that handles end-user erasure handles tenant-wide deletion. Backups roll out of point-in-time history within 7 days.

Reporting a vulnerability

Found something? Email security@pact.place. We'll acknowledge within one business day and keep you updated through remediation. Coordinated disclosure timeline is 90 days from acknowledgement; we will of course move faster if the issue is critical.

Last reviewed: 2026-06-18. This page describes the production substrate; the canonical legal commitments are in the Terms of Service and Data Processing Addendum.