Security

Private by default, traceable by design.

Sponsor agreements and proof records deserve a narrow access model, minimal telemetry, and explicit retention controls.

Effective August 4, 2026 · Security contact: admin@sponsorpact.com

The launch control set.

SponsorPact is prelaunch. These controls are implemented in the current product build and must pass deployment checks before customer documents are enabled.

Tenant-aware access

The current product build uses organization identifiers, tenant-aware foreign keys, forced row-level security, and private object paths.

Private document storage

Agreements, proof, logos, and reports use private storage with operation, path, and expiry-limited access URLs.

Minimized AI exposure

Models receive no tools or web-search access. Documents, prompts, completions, source quotes, contacts, and proof URLs stay out of SponsorPact logs.

Reproducible records

Audit events are append-only and each report uses an immutable snapshot so prior versions remain reproducible.

Retention controls

Customer data is soft-deleted for 30 days, then database records and private objects are scheduled for purge.

Conservative telemetry

Exceptions and explicit non-PII product events are collected. Session replay, autocapture, and PII collection stay disabled.

Clear claims, including what is not claimed.

Current beta posture

SponsorPact is being built for U.S.-first beta customers. AI processing is limited to public prospectuses and approved test documents until Replicate retention and DPA terms are contractually cleared. Executed agreements remain disabled.

Replicate retention

Replicate documents that API prediction input parameters, output values, output files, and logs are automatically removed after one hour by default. SponsorPact does not describe this provider default as contractual zero data retention.

No certification claim

SponsorPact does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS, or FedRAMP certification. Payment card details are not intended to pass through the product.

Responsible disclosure

Report suspected vulnerabilities to admin@sponsorpact.com. Include reproduction details and allow a reasonable remediation window before public disclosure.

Review the workflow with a realistic sample.

Run a source-cited audit on one agreement and see the work clearly.

Run a fulfillment audit