Processed in the EU
Your documents are read and drafted inside EU datacenters. Nothing is sent to a general-purpose endpoint somewhere else.
So this page states plainly where they are processed, who can reach them, how long they are kept, and what we don't yet claim. Everything here describes how the product is built today, not a roadmap.
Your documents are read and drafted inside EU datacenters. Nothing is sent to a general-purpose endpoint somewhere else.
The model service runs under enterprise terms, where customer content is not used to train or improve the underlying models. Your contracts are inputs to your work, not to ours.
Everything moves over TLS and is stored encrypted at rest. Files are never served from a public URL: access goes through short-lived signed links that expire in an hour or less.
Every table holding your documents has row-level security switched on, so separation between accounts is enforced by Postgres itself rather than only by application code that could be bypassed.
Authentication runs on WorkOS AuthKit. We never see or store your password, and session handling is not something we hand-rolled.
Deleting a document moves it to trash for 14 days so mistakes are recoverable. After that a scheduled job hard-deletes it, including the stored file. There is no quiet archive.
The complete list. If a vendor is not here, it does not receive your documents.
| Provider | What it does | Where |
|---|---|---|
| Google Cloud | Reads and drafts document text | EU multi-region |
| Supabase | Database and file storage | EU |
| WorkOS | Sign-in and session handling | EU / US |
Those platforms hold ISO 27001 and SOC 2. Those audits cover the infrastructure we build on, not Everypact itself — we have not been through one.
Payment details are handled by our payment provider and never reach our servers.
Lawyers on the platform are admitted advocates in the country they practise in. Professional confidentiality binds them by law and by their bar, not by anything we ask of them. They see a document only when you hand it to them, and only for the matter you opened.
Everypact itself is not a law firm. It prepares documents and explains them in plain language. When you need advice, it comes from the lawyer, who is qualified to give it.
If you believe you've found a vulnerability, tell us before telling anyone else and we will work with you on it. If your company needs a data processing agreement or a security questionnaire filled in, ask.