Your contracts deserve the highest level of protection.
European hosting, AES-256 encryption, GDPR & eIDAS compliance. Security is not an option.
5 commitments to protect your data
European hosting
Data hosted exclusively on servers in Europe
AES-256-GCM encryption
Sensitive data encrypted at rest. HTTPS/TLS in transit.
GDPR compliance
Privacy by Design. DPA available. Data subject rights supported.
No AI use
Your contracts are never used to train the AI. PII removed before analysis.
Full audit trail
ISO 27001 compliant. Integrity verification. Minimum 90-day retention.
Technical details
Every layer of Pactolane is designed to protect your contract data.
Encryption at rest
AES-256-GCM with scrypt key derivation. AAD (Additional Authenticated Data) to prevent tampering.
Encryption in transit
HTTPS/TLS for all client-server communications.
Passwords
Hashed with bcrypt (10 rounds) : irreversible. No password stored in plaintext.
OAuth tokens
AES-256 encrypted in the database. Never stored in plaintext.
Third-party personal data
Emails, phone numbers, addresses encrypted at rest (GDPR Art. 32).
HMAC verification
Constant-time SHA-256 for tokens and webhooks. Timing-attack prevention.
Multi-tenant isolation
Each organization only sees its own data. Cache with TTL.
CSRF protection
Anti-forgery token compliant with ISO 27001 A.14.1.2.
File validation
Real MIME-type verification via magic bytes (PDF, PNG, JPEG, GIF, WebP, DOCX).
PII sanitization for AI
14 types of personal data removed before sending (emails, phone numbers, IBAN, national ID, etc.).
Your rights, implemented natively
Every right under the GDPR is technically supported in Pactolane.
Right of access
View all your personal data from the account settings.
Right to portability
Full export as ZIP (summary PDF + 9 JSON files), in the user's language.
Right to erasure
Account deletion and data anonymization. Deletion of ~60 data types in a transaction.
Consent
Explicit consent collected for each processing activity. Specific AI consent required.
Processing security
AES-256 encryption of third-party personal data in the database.
Minimization
Only strictly necessary data is collected and processed.
Authentication & role management
Granular roles
Multiple role levels to separate administration, validation, viewing and external access
60+ permissions
Granular control by resource and action
MFA (TOTP)
Multi-factor authentication with 10 recovery codes
Rate limiting
Anti-brute-force protection on sensitive endpoints
Secure sessions
JWT (HS256, 7 days), httpOnly cookie, token version verification
Electronic signature compliant with the European regulation
SES level
Simple Electronic Signature compliant with eIDAS (EU 910/2014)
Identity verification
Verification via OTP code sent by email, with expiry and attempt limit
Audit trail
Timestamp, IP address, User-Agent, document hash
Certificates
Generation, validation, revocation of digital certificates
Retention
Logs retained for a minimum of 90 days
Every action tracked. Every piece of evidence kept.
Your questions about security
Questions about security?
Our team is available to answer all your technical and compliance questions.