Trust centre
The controls and suppliers behind Pactlyra
A concise starting point for security, privacy and procurement review. Product-specific answers and contractual commitments are confirmed in the order form and DPA.
Security
- Tenant-scoped server-side authorisation; document content is excluded from logs and analytics.
- Executed evidence is sealed, versioned and independently verifiable; AI is kept out of the signature-evidence path.
- Encryption in transit and at rest, bounded uploads, rate limits, audit events, restore drills and dependency/secrets checks.
Subprocessors and AI
| Provider class | Purpose | Data/location note |
|---|---|---|
| Railway | Application hosting | Deployment region is confirmed for the customer environment. |
| Neon | Managed PostgreSQL | Database region is confirmed before production onboarding. |
| Microsoft 365 | Transactional and support email | Message metadata and content needed for delivery. |
| Stripe | Payment processing | Card data is entered with Stripe, not Pactlyra. |
| Configured AI provider | Optional drafting assistance outside the evidence path | Provider/model is disclosed before enablement; document content is not used to decide whether a signature counts. |
Retention and data location
Agreement records, evidence, audit events and backups follow the customer retention schedule and documented legal-hold requirements. Hosting and database locations, cross-border transfer mechanism and deletion timetable are recorded contractually; they are not inferred from the visitor's location.
DPA and data-protection contact
The DPA is in legal-review draft and is not published. Request it, the current subprocessor schedule, or a security review through [email protected]. Use the same address for data-protection questions.
Related detail: privacy, subprocessors, and retention.