Security at PACE IQ
Last updated — August 2026
Your operational data — schedules, costs, contracts, delays — is some of the most commercially sensitive information your business has. We treat it that way.
Encryption everywhere
All traffic is served over TLS, and data is encrypted at rest. Documents uploaded to the platform are stored in private buckets — never publicly addressable.
Database-level tenant isolation
Every organization's data is walled off with row-level security enforced by the database itself — not just application code. One organization can never read another's rows.
Role-based access control
Admins, managers, and viewers see and do different things. Privileged checks run as hardened, server-side functions with no anonymous access.
Independent scanning
The platform is continuously scanned for vulnerabilities — injection, cross-tenant exposure, and misconfiguration — and findings are remediated as part of our release process.
Compliance roadmap
PACE IQ is built on SOC 2-aligned infrastructure and practices — access logging, least privilege, encrypted storage, and change control. A formal SOC 2 Type II examination is on our compliance roadmap. We'll update this page as milestones are reached, and we're happy to complete security questionnaires for prospective customers.
Responsible disclosure
Found a vulnerability? We want to hear from you before anyone else does. Report it to hello@paceiq.dev with "Security" in the subject. We acknowledge reports within two business days and do not pursue good-faith security research.
