Security & Privacy

Your board's decisions stay with your board.

PACT handles the most sensitive conversations in your organisation. Our security posture is built for that standard — and we are explicit about what we do, how we do it, and what we are still working on.

How we think about security

Every request to PACT passes through seven independent layers of defense, from the network perimeter down to the database row. A failure at any single layer is caught by the next. This is not a slogan — it is the model the platform is designed around, and we publish the full breakdown to security teams on request.

What we guarantee today.

Six commitments enforced in production — encryption, tenant isolation, AI guardrails, audit logging, deletion, and infrastructure discipline.

Encrypted at every layer

All data — in transit, at rest, and on every internal hop — is encrypted with industry-standard cryptography (TLS 1.2+, AES-256, HSTS preloaded). Session tokens are signed asymmetrically against a published key set, so a leak of our runtime configuration cannot be used to forge access.

Tenant isolation, enforced twice

Your sessions, documents, and decisions are filtered at the application layer and isolated at the database layer. A forgotten filter in code cannot leak data across tenants — the database refuses the query independently. Requests for resources outside your scope return 404, never confirming that other tenants' data exists.

AI under control

PACT's AI surface is bounded: every agent run has explicit limits on tool calls, runtime, and scope. Inputs and outputs pass through guardrails that detect prompt injection, strip hidden instructions from retrieved context, and redact PII before responses are returned. Our AI controls are mapped to the OWASP LLM Top 10. We do not train models on your data, and our model providers operate under zero-retention agreements.

Least privilege, audited

Every workload runs with the narrowest possible permissions. Secrets are injected at runtime, never baked into container images. Every administrative and data action is logged to an immutable bucket with 365-day retention that cannot be shortened or deleted, with a per-request correlation ID that lets us reconstruct any operation end to end.

Yours to delete

You can permanently delete your sessions, documents, and history at any time. Deletion propagates across our systems, including backups, within a defined retention window. No advertising trackers. No behavioural analytics sold downstream. No data exits without your consent.

Engineered with discipline

100% of our infrastructure is defined as code. Manual production changes are prohibited. Every change runs through automated integration tests that validate security properties — deny-all firewall, locked audit log bucket, TLS-only internal hops — before it reaches production.

Responsible AI

PACT is an AI-powered training and intelligence platform. We are explicit about what that means.

AI is used to simulate boardroom dynamics, surface relevant intelligence, and support governance learning. It is not connected to any system of record, and it does not take action on your behalf. Every output is there to inform your thinking, not to replace it.

Compliance & deployment

PACT runs on Google Cloud Platform. Our managed-service vendors (Supabase, LiveKit Cloud) hold their own SOC 2 Type II attestations.

SOC 2 Type II

Controls mapped to CC1–CC9, A1.x, C1.x. External audit observation planned for 2026.

ISO/IEC 27001:2022

Controls mapped to Annex A (themes 5, 7, 8). Certification path planned after SOC 2.

GDPR

EU data residency available.

EU AI Act

PACT is operated as a high-risk system: documented model use per feature, human oversight, full audit logging, and transparency to data subjects.

Data residency. PACT is deployed in the US today. EU and APAC regions are on our 2026 roadmap.

A detailed security and architecture brief is available on request.

Common questions

Talk to our security team

For architecture reviews, DPAs, vendor questionnaires, or to request our security brief —
security@rinnce.ai.