Security

Contract data that stays where it belongs

Pactthread is built on the assumption that every contract in your repository is sensitive: NDAs, MSAs, vendor agreements, and customer terms all carry information your organization cannot afford to expose. Here is exactly how we protect it.

Secure document vault concept with layered document storage

Six practices, applied to every contract in your repository

Encryption at rest and in transit

All contract data encrypted with AES-256 at rest. TLS 1.3 in transit, always. No plaintext contract data outside the encrypted layer.

Role-based access controls

Permissions scoped by contract type, team, and deal stage. No user sees more than their role requires. Admins control access with granular rules, not broad categories.

Immutable audit log

Every view, edit, comment, and approval is logged with user, timestamp, and IP. Tamper-evident log storage. Full export available for legal review or internal audit.

Data isolation

Each organization's contract data is logically isolated. No cross-tenant data access, by design. Your contracts are not visible to other Pactthread customers.

Secure document storage

Executed contracts stored in access-controlled, regionally-specified object storage. Retention policies configurable per organization. Deletion requests honored within 30 days.

Compliance-aligned design

Infrastructure and processes designed with GDPR data processing requirements, CCPA obligations, and NY financial privacy rules in mind. We do not claim certifications we have not completed. Where we have controls in place, we describe them. Where we do not yet have formal certification, we say so on our compliance roadmap.

What we have done and what is next

We do not claim certifications we have not completed. For legal and procurement teams doing due diligence on a new CLM vendor, here is the honest status of our compliance program.

Completed Q4 2025

Independent security review

Third-party security review of infrastructure, access controls, and application layer. Findings addressed and documented.

Completed Q4 2025

Penetration test

External penetration test of API and application surfaces. Full remediation completed before production release.

On our roadmap

SOC 2 Type II audit

SOC 2 Type II audit is on our compliance roadmap. We are building toward the required controls framework now. When the audit is complete and the report is in hand, we will announce it. Not before. We do not pre-announce certifications.

Questions about our security practices?

Our team will answer any security or compliance question, including sharing our penetration test summary and infrastructure architecture, before you move a single contract into the platform.

Contact Our Team