Trust center
Security at PactCanvas
We protect agreement evidence with controls designed around tenant isolation, limited access, and integrity.
Last updated July 20, 2026
Security approach
PactCanvas uses defense in depth. We assess risk across application code, Shopify integration, production infrastructure, people, and operational processes. Controls are reviewed as the service changes; this page is a summary and is not a certification or guarantee.
Access
Tenant-scoped authorization, restricted production access, and server-side secrets.
Data protection
HTTPS, private object storage, and application encryption for evidence files and completed PDFs.
Integrity
Webhook signature verification, document hashes, cart/version binding, and tamper-evident audit events.
Lifecycle
Privacy webhooks, retention workflows, controlled releases, and incident response.
Data and infrastructure safeguards
- External application traffic is served over HTTPS.
- Shopify OAuth and webhook requests are authenticated and verified server-side.
- Production databases and object storage are not intended to be exposed directly to the public internet.
- Uploaded proof files, drawn signatures, and completed evidence PDFs are encrypted by the application before private object storage.
- Database fields are protected by network, host, tenant-authorization, access, and retention controls; they are not represented as universally field-encrypted.
- Sensitive credentials are kept server-side and are excluded from browser payloads and source control.
Secure development and operations
- Development and production use separate app identities, credentials, services, databases, object stores, and encryption keys.
- Releases run dependency, configuration, migration, readiness, and version checks before activation.
- Supported Shopify API versions and first-party Shopify extension surfaces are used.
- Routine diagnostics are designed to exclude access tokens, signature images, and full agreement content.
- Mandatory Shopify privacy webhooks support access and deletion workflows.
- Release checks cover dependencies, configuration, migrations, readiness, and deployed version consistency.
Report a security concern
Send suspected vulnerabilities to info@techimprovement.net with a concise description, affected URL or component, reproduction steps, and impact. Do not include live customer data, signatures, credentials, or access tokens in email.
We will acknowledge a valid report, investigate it in good faith, and provide status updates appropriate to its severity. This is not a bug bounty program and we cannot promise payment.
Incident response
Our incident process covers triage, containment, evidence preservation, remediation, recovery, and lessons learned. If an incident affects personal data, we assess notification duties and coordinate with affected merchants and service providers as required by contract and law.
Assurance and limitations
PactCanvas does not currently claim SOC 2, ISO 27001, PCI DSS, or another independent certification unless a current report is provided directly by us. Merchants with security questionnaires or vendor-review requirements can contact the security address above.