Security & compliance
Pact is built on a SOC 2 Type II + HIPAA-ready managed Postgres tier, with encryption at rest and in transit, IP allow-listing, private networking, and tenant isolation enforced in the application. This page describes the posture as it stands today — what we've shipped, and what is in progress.
In production today
SOC 2 Type II data layer
Our cloud-managed Postgres provider holds SOC 2 Type II attestation. The attestation report is available to enterprise customers under NDA on request.
HIPAA-ready data layer
The managed Postgres tier supports the HIPAA controls required for storing PHI under a Business Associate Agreement (BAA). Customers handling PHI should request a BAA before loading clinical data — contact sales.
99.9% uptime SLA on Team
Multi-AZ managed Postgres with autoscaling compute (0.25 – 8 CU on the primary; never scales to zero). Instant read replicas isolate heavy analytics reads from the write path. Pro targets 99.5%; the Terms of Service carry the commitment.
Encryption at rest + in transit
AES-256 at rest across compute and storage. TLS 1.2+ on every public endpoint, with the same on database connections (sslmode=require). Tenant-managed keys for BYOK PII fields.
Private networking
In our primary region (us-east-1), application↔database traffic stays on the cloud-provider private network — it does not transit the public internet. Public ingress is locked to a published allow-list.
IP allow-listing
Public database access is restricted to the Pact application's egress CIDR and operator IPs. Preview environments use isolated branches with their own connection strings.
Per-PR database isolation
Every code change in our pipeline gets its own isolated database branch via our managed Postgres provider's branching primitive. Test data and migrations are never run against production state.
Tenant isolation in the application
Every request takes its workspace from the signed-in session, never from the request, and every workspace-scoped row carries its workspace id. Five cross-workspace reads found by our own audits have been closed, and isolation policies cover 783 of 783 workspace-scoped tables. The database-level half is below, under In progress.
Append-only audit log
Every mutation produces an event the database refuses to edit. Rows leave only when the retention window you set (12 months to 20 years) expires. Operators can search the log; tenants can export it as CSV, JSONL, or XLSX.
Consent matrix per contact
Per-jurisdiction (GDPR / CCPA / CASL / others) consent state per contact per channel, with point-in-time history. Sends route through core.consent + core.frequency_caps before egress.
DSAR fulfilment
Right-to-access, right-to-rectification, right-to-erasure, and right-to-portability requests are first-class data-flow objects, not a quarterly compliance scramble. SLA-tracked from receipt.
Hourly managed database telemetry
Compute utilization, replication lag, branch count, active time, and data transfer are sampled hourly and pushed to our observability backend. Replication lag > 5s pages oncall.
In progress
Pact's own SOC 2 report
Pact's own SOC 2 Type II report (application tier, not just the data layer) is planned. Today there is a complete policy library mapped to all 33 Common Criteria and an evidence engine, machine-validated in CI — and no audit yet. Until there is, we claim SOC 2 only on the substrate.
Database-level tenant isolation
Making the database itself refuse a query that forgets is built and staged, and is not switched on today. We will say so here on the day it is.
External penetration testbeing scheduled
An independent firm will test the application and API by hand, signed in, across roles and across workspaces.
Ready for the testers
- Scope and rules of engagement
- An inventory of every API route and how it authenticates, generated from the code
- One-command test workspaces that hold sample data only
Once the test and its fixes are complete, a summary and the firm's attestation letter will be published here, and enterprise customers will be able to request the full report under NDA.
Found something before then? Responsible disclosure is open now.
ISO 27001
Scoping discussion underway with a 27001-certified auditor. We'll publish a target date once the scope is locked.
Sub-processors
The complete sub-processor schedule — specific providers, certifications, DPA-on-file dates, and change-notification subscription — is published on our Trust Center or available on request at legal@pact.place. AI features (where enabled for your tenant) use Anthropic by default; no data is sent to any AI provider unless the feature is explicitly enabled for your tenant.
Retention & deletion
By default we retain customer data for the term of the contract plus 30 days for recovery. Tenants can request earlier deletion at any time; the same DSAR machinery that handles end-user erasure handles tenant-wide deletion. Backups roll out of point-in-time history within 7 days.
Reporting a vulnerability
Found something? Email security@pact.place. We acknowledge within 2 business days and keep you updated through remediation. The coordinated disclosure window is 90 days from acknowledgement, and we move faster when the issue is critical. Good-faith research is covered by our safe harbor.
Read the full disclosure policy · machine-readable at /.well-known/security.txt
Last reviewed: 2026-10-04. This page describes the production substrate; the canonical legal commitments are in the Terms of Service and Data Processing Addendum.