Skip to content

Trust center

Security at PactCanvas

We protect agreement evidence with controls designed around tenant isolation, limited access, and integrity.

Last updated July 20, 2026

Security approach

PactCanvas uses defense in depth. We assess risk across application code, Shopify integration, production infrastructure, people, and operational processes. Controls are reviewed as the service changes; this page is a summary and is not a certification or guarantee.

Access

Tenant-scoped authorization, restricted production access, and server-side secrets.

Data protection

HTTPS, private object storage, and application encryption for evidence files and completed PDFs.

Integrity

Webhook signature verification, document hashes, cart/version binding, and tamper-evident audit events.

Lifecycle

Privacy webhooks, retention workflows, controlled releases, and incident response.

Data and infrastructure safeguards

  • External application traffic is served over HTTPS.
  • Shopify OAuth and webhook requests are authenticated and verified server-side.
  • Production databases and object storage are not intended to be exposed directly to the public internet.
  • Uploaded proof files, drawn signatures, and completed evidence PDFs are encrypted by the application before private object storage.
  • Database fields are protected by network, host, tenant-authorization, access, and retention controls; they are not represented as universally field-encrypted.
  • Sensitive credentials are kept server-side and are excluded from browser payloads and source control.

Secure development and operations

  • Development and production use separate app identities, credentials, services, databases, object stores, and encryption keys.
  • Releases run dependency, configuration, migration, readiness, and version checks before activation.
  • Supported Shopify API versions and first-party Shopify extension surfaces are used.
  • Routine diagnostics are designed to exclude access tokens, signature images, and full agreement content.
  • Mandatory Shopify privacy webhooks support access and deletion workflows.
  • Release checks cover dependencies, configuration, migrations, readiness, and deployed version consistency.

Report a security concern

Send suspected vulnerabilities to info@techimprovement.net with a concise description, affected URL or component, reproduction steps, and impact. Do not include live customer data, signatures, credentials, or access tokens in email.

Please do not access another person’s data, disrupt stores, perform denial-of-service testing, use automated high-volume scanning, or publish a vulnerability before we have had a reasonable opportunity to investigate and remediate it.

We will acknowledge a valid report, investigate it in good faith, and provide status updates appropriate to its severity. This is not a bug bounty program and we cannot promise payment.

Incident response

Our incident process covers triage, containment, evidence preservation, remediation, recovery, and lessons learned. If an incident affects personal data, we assess notification duties and coordinate with affected merchants and service providers as required by contract and law.

Assurance and limitations

PactCanvas does not currently claim SOC 2, ISO 27001, PCI DSS, or another independent certification unless a current report is provided directly by us. Merchants with security questionnaires or vendor-review requirements can contact the security address above.