Security Practices
- All data encrypted in transit (TLS 1.3)
- All data encrypted at rest (AES-256)
- Two-factor authentication available
- Regular security audits
- Access logs and monitoring
- SOC 2 compliance planned for 2027
Document Integrity & Verification
Evidence Packs are built to hold up in a dispute, including one where you have to prove the document itself hasn’t been altered. We don’t ask you to just trust us on that.
- Every Evidence Pack PDF gets a SHA-256 hash computed and recorded the moment it’s generated.
- That hash is independently timestamped by a public RFC 3161 Timestamp Authority (DigiCert, with FreeTSA as a fallback): proof the document existed at that exact time, signed by a third party with no stake in either side of the deal.
- Anyone can verify a document at pacterms.com/verify: compare the published hash to one you compute yourself, and download the raw timestamp token to check independently with standard open-source tools. No Pacterms account or software required.
- SMS agreement confirmations are logged with a timestamp, IP address, and user-agent as a verifiable consent record.
Report a Concern
Found a security issue? We take reports seriously.
Email: security@pacterms.com
Response time: Within 24 hours
We work with security researchers and offer recognition (and rewards for valid vulnerabilities once we have funding).