Everypact logo - text

Contracts and other documents are usually the most sensitive things you'd upload anywhere

So this page states plainly where they are processed, who can reach them, how long they are kept, and what we don't yet claim. Everything here describes how the product is built today, not a roadmap.

The commitments

Processed in the EU

Your documents are read and drafted inside EU datacenters. Nothing is sent to a general-purpose endpoint somewhere else.

Never training data

The model service runs under enterprise terms, where customer content is not used to train or improve the underlying models. Your contracts are inputs to your work, not to ours.

Encrypted in transit and at rest

Everything moves over TLS and is stored encrypted at rest. Files are never served from a public URL: access goes through short-lived signed links that expire in an hour or less.

Isolation enforced by the database

Every table holding your documents has row-level security switched on, so separation between accounts is enforced by Postgres itself rather than only by application code that could be bypassed.

Sign-in handled by a specialist

Authentication runs on WorkOS AuthKit. We never see or store your password, and session handling is not something we hand-rolled.

Deleted means deleted

Deleting a document moves it to trash for 14 days so mistakes are recoverable. After that a scheduled job hard-deletes it, including the stored file. There is no quiet archive.

Who else touches your data

The complete list. If a vendor is not here, it does not receive your documents.

ProviderWhat it doesWhere
Google CloudReads and drafts document textEU multi-region
SupabaseDatabase and file storageEU
WorkOSSign-in and session handlingEU / US

Those platforms hold ISO 27001 and SOC 2. Those audits cover the infrastructure we build on, not Everypact itself — we have not been through one.

Payment details are handled by our payment provider and never reach our servers.

When a lawyer is involved

Lawyers on the platform are admitted advocates in the country they practise in. Professional confidentiality binds them by law and by their bar, not by anything we ask of them. They see a document only when you hand it to them, and only for the matter you opened.

Everypact itself is not a law firm. It prepares documents and explains them in plain language. When you need advice, it comes from the lawyer, who is qualified to give it.

Found something, or need something?

If you believe you've found a vulnerability, tell us before telling anyone else and we will work with you on it. If your company needs a data processing agreement or a security questionnaire filled in, ask.