PactCue
SECURITY & DATA

You should know what happens to your contracts.

PactCue builds trust through explicit technical boundaries: private storage, workspace isolation, short-lived AI access and human verification of critical terms.

1
Private upload

Contract PDFs are uploaded to a private Supabase Storage bucket. The product bucket is PDF-only and size-limited.

2
Workspace-scoped access

Database and storage access use Row Level Security so authenticated users can only access resources in their own organization.

3
Short-lived AI access

For analysis, PactCue creates a time-limited signed URL to the private PDF and sends it to the OpenAI API. OpenAI states that API data is not used for model training by default.

4
Verification before automation

AI suggestions are not automatically treated as verified fact. Critical dates can be reviewed and reminder automation only uses verified action deadlines.

OpenAI API retention

PactCue sends analysis requests with store:false. OpenAI states that API data is not used for model training by default, but default abuse-monitoring logs may contain customer content and can be retained for up to 30 days. We state this explicitly rather than claiming zero retention without the required API configuration.

STORAGE

Private by default

The original document stays in the customer’s private PactCue workspace. PactCue uses signed URLs for time-limited access instead of making bucket files public.

PROCESSORS

A visible processor chain

The current beta architecture uses Supabase for authentication, database and file storage, OpenAI API for contract analysis, Vercel for application hosting, Resend for transactional email and Stripe for billing.

DATA REGION

No vague EU-only promises

PactCue will publish the exact production region and any cross-border processing before commercial launch. We do not claim all data stays in the EU until that is technically verified.

CUSTOMER CONTROL

Delete when you need to

PactCue v0.9 introduces contract deletion together with its stored PDF. Contract-linked events and reminder records are removed through database cascade deletion.

security@pactcue.com

We will connect the dedicated security address when the domain is activated and publish incident and privacy procedures here before public launch.