Trust Center

Your contracts deserve the highest level of protection.

European hosting, AES-256 encryption, GDPR & eIDAS compliance. Security is not an option.

Our commitments

5 commitments to protect your data

European hosting

Data hosted exclusively on servers in Europe

AES-256-GCM encryption

Sensitive data encrypted at rest. HTTPS/TLS in transit.

GDPR compliance

Privacy by Design. DPA available. Data subject rights supported.

No AI use

Your contracts are never used to train the AI. PII removed before analysis.

Full audit trail

ISO 27001 compliant. Integrity verification. Minimum 90-day retention.

Data protection

Technical details

Every layer of Pactolane is designed to protect your contract data.

Encryption at rest

AES-256-GCM with scrypt key derivation. AAD (Additional Authenticated Data) to prevent tampering.

Encryption in transit

HTTPS/TLS for all client-server communications.

Passwords

Hashed with bcrypt (10 rounds) : irreversible. No password stored in plaintext.

OAuth tokens

AES-256 encrypted in the database. Never stored in plaintext.

Third-party personal data

Emails, phone numbers, addresses encrypted at rest (GDPR Art. 32).

HMAC verification

Constant-time SHA-256 for tokens and webhooks. Timing-attack prevention.

Multi-tenant isolation

Each organization only sees its own data. Cache with TTL.

CSRF protection

Anti-forgery token compliant with ISO 27001 A.14.1.2.

File validation

Real MIME-type verification via magic bytes (PDF, PNG, JPEG, GIF, WebP, DOCX).

PII sanitization for AI

14 types of personal data removed before sending (emails, phone numbers, IBAN, national ID, etc.).

GDPR compliance

Your rights, implemented natively

Every right under the GDPR is technically supported in Pactolane.

Art. 15

Right of access

View all your personal data from the account settings.

Art. 20

Right to portability

Full export as ZIP (summary PDF + 9 JSON files), in the user's language.

Art. 17

Right to erasure

Account deletion and data anonymization. Deletion of ~60 data types in a transaction.

Art. 6-7

Consent

Explicit consent collected for each processing activity. Specific AI consent required.

Art. 32

Processing security

AES-256 encryption of third-party personal data in the database.

Art. 5

Minimization

Only strictly necessary data is collected and processed.

Access control

Authentication & role management

Granular roles

Multiple role levels to separate administration, validation, viewing and external access

60+ permissions

Granular control by resource and action

MFA (TOTP)

Multi-factor authentication with 10 recovery codes

Rate limiting

Anti-brute-force protection on sensitive endpoints

Secure sessions

JWT (HS256, 7 days), httpOnly cookie, token version verification

eIDAS compliance

Electronic signature compliant with the European regulation

SES level

Simple Electronic Signature compliant with eIDAS (EU 910/2014)

Identity verification

Verification via OTP code sent by email, with expiry and attempt limit

Audit trail

Timestamp, IP address, User-Agent, document hash

Certificates

Generation, validation, revocation of digital certificates

Retention

Logs retained for a minimum of 90 days

Audit Trail & Traceability

Every action tracked. Every piece of evidence kept.

Document creation, modification, deletion
Viewing (who saw what, when)
Approvals and rejections (with comments)
Signatures (with eIDAS certificate)
Exports and downloads
Permission changes
Critical administrative actions (auto alert)
Chain integrity verification
Frequently asked questions

Your questions about security

Where exactly is my data hosted?
In Europe, on Google Cloud Platform (Paris, Brussels). No data transfer outside the European Union.
Who can access my contracts at Pactolane?
No one by default. Multi-tenant isolation ensures each organization only accesses its own data. Our support team has no access to your contracts.
Is my data used to train your AI?
No. Never. Moreover, 14 types of personal data are automatically removed from the text before any analysis by PactAI (emails, phone numbers, IBAN, national ID, bank cards, SIRET/SIREN, IP addresses, etc.).
Can you sign a DPA?
Yes. Our standard DPA (Data Processing Agreement) is available on request. Contact us at contact@pactolane.com.
What happens if I cancel?
Full export of your data guaranteed (right to portability, GDPR Art. 20). ZIP with summary PDF and 9 JSON files. Permanent deletion within 30 days.

Questions about security?

Our team is available to answer all your technical and compliance questions.

Download the full security pack
Manage my cookies