Tenant-aware access
The current product build uses organization identifiers, tenant-aware foreign keys, forced row-level security, and private object paths.
Security
Sponsor agreements and proof records deserve a narrow access model, minimal telemetry, and explicit retention controls.
Effective August 4, 2026 · Security contact: admin@sponsorpact.com
SponsorPact is prelaunch. These controls are implemented in the current product build and must pass deployment checks before customer documents are enabled.
The current product build uses organization identifiers, tenant-aware foreign keys, forced row-level security, and private object paths.
Agreements, proof, logos, and reports use private storage with operation, path, and expiry-limited access URLs.
Models receive no tools or web-search access. Documents, prompts, completions, source quotes, contacts, and proof URLs stay out of SponsorPact logs.
Audit events are append-only and each report uses an immutable snapshot so prior versions remain reproducible.
Customer data is soft-deleted for 30 days, then database records and private objects are scheduled for purge.
Exceptions and explicit non-PII product events are collected. Session replay, autocapture, and PII collection stay disabled.
SponsorPact is being built for U.S.-first beta customers. AI processing is limited to public prospectuses and approved test documents until Replicate retention and DPA terms are contractually cleared. Executed agreements remain disabled.
Replicate documents that API prediction input parameters, output values, output files, and logs are automatically removed after one hour by default. SponsorPact does not describe this provider default as contractual zero data retention.
SponsorPact does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS, or FedRAMP certification. Payment card details are not intended to pass through the product.
Report suspected vulnerabilities to admin@sponsorpact.com. Include reproduction details and allow a reasonable remediation window before public disclosure.
Run a source-cited audit on one agreement and see the work clearly.