Trust
Enterprise readiness you can verify
Pamphlet is built for teams that need Pam Pod isolation, auditable automation, and transparent operations. This page summarizes how we handle data and where to find evidence. It is not a substitute for signed agreements.
Architecture
Pamphlet runs as a multi-tenant SaaS application on Vercel with Postgres and object storage through Supabase. Each Pam Pod is an isolated tenant. Application code enforces pod_id on every query; Supabase row-level security provides a database-layer backstop.
Data handling
Customers control Personal Data stored in Pam Pods. Pamphlet processes that data on documented instructions through product configuration and API use. Account billing metadata and security logs may be processed as controller data under the Privacy Policy.
Subprocessors
Pamphlet uses infrastructure and service providers listed in the Subprocessor List. Material changes receive notice as described in the DPA.
Access controls
Clerk handles authentication and organization membership. Pam Pod routes require a valid session. API keys are hashed, scoped to a single Pam Pod, and never returned after creation. Admin routes require elevated roles.
Encryption
Traffic to pamphlet.io uses TLS. Data at rest is encrypted by Supabase and Vercel infrastructure providers. API keys and connector credentials are stored hashed or encrypted at the application layer.
Incident response
Operational incidents are published on the Status page with component impact and resolution notes. Security reports are handled through cs@pamphlet.io with coordinated disclosure for validated findings.
Retention, export, and deletion
Retention follows the Privacy Policy and customer configuration. Operators can export Pam Pod data through the REST API. Verified deletion and data subject requests are submitted through cs@pamphlet.io.
Responsible disclosure
Report vulnerabilities to cs@pamphlet.io with reproduction steps and impact assessment. Do not access other customers' Pam Pods or exfiltrate data during testing.
Compliance status
Pamphlet publishes policies, subprocessors, and operational evidence on this site. Formal certifications or audit reports are shared with enterprise customers under order form when available. Pamphlet does not claim certifications it has not completed.
Support and escalation
Security reports and privacy requests: cs@pamphlet.io. Operational incidents: Status page and subscriptions. Self-service guides: Help Center.
