Security & Sub-Processor Overview
Security at DonePact is built for businesses to securely create, collaborate on, execute, store, search, and manage agreements and related workflows.
We understand that customers entrust us with sensitive commercial, legal, financial, and operational information. Security, privacy, availability, and responsible AI practices are foundational to our platform.
1 Security Principles
DonePact’s security program is guided by the following principles:
- least privilege access
- encryption of sensitive data
- segregation of customer environments where applicable
- secure development and deployment practices
- continuous monitoring and logging
- controlled use of AI systems
- vendor due diligence and sub-processor oversight
- business continuity and operational resilience.
2 Infrastructure & Hosting Security
DonePact may use leading global cloud infrastructure providers for hosting, storage, AI processing, backup, networking, monitoring, and related platform services.
Security measures may include:
- hosting within professionally managed cloud environments
- firewalls and network segmentation
- encryption in transit using TLS/HTTPS
- encryption at rest where supported
- access logging and monitoring
- backup and disaster recovery mechanisms
- multi-factor authentication for privileged access
- role-based access controls (RBAC)
- environment separation between production, staging, and development systems
- periodic review of infrastructure configurations.
DonePact may process and store data in India and/or other jurisdictions depending on hosting configuration, customer requirements, integrations, and sub-processors engaged.
3 Application Security
DonePact follows commercially reasonable security practices throughout the software development lifecycle.
- authentication and authorization controls
- secure password handling
- API authentication and token-based access mechanisms
- session management controls
- activity logging and audit trails
- periodic dependency and vulnerability reviews
- input validation and protection against common web vulnerabilities
- controlled deployment workflows
- internal review and testing prior to major releases.
Customers are responsible for maintaining the confidentiality of their account credentials and for managing user access permissions within their organization.
4 AI Security & Responsible AI Usage
DonePact may use artificial intelligence and large language model (LLM) technologies to assist with:
- contract drafting
- clause suggestions
- redlining support
- metadata extraction
- search and summarization
- workflow automation
- contract analytics.
DonePact does not intentionally use customer confidential data to train public foundation models unless expressly permitted by the customer or the applicable AI provider terms.
AI-generated outputs may contain inaccuracies, omissions, or non-binding suggestions. Customers remain responsible for reviewing, validating, approving, and using all outputs generated through the platform.
Customers should avoid submitting highly sensitive regulated information unless appropriate safeguards and configurations have been agreed with DonePact.
5 Data Access Controls
Access to customer information is restricted to authorized personnel, contractors, and service providers who require access for legitimate business, operational, support, security, compliance, or maintenance purposes.
- restrict unauthorized access
- maintain confidentiality
- log administrative activities where appropriate
- limit access based on role and function
- revoke access upon termination or role change.
6 Incident Management
DonePact maintains internal processes for identifying, assessing, responding to, and mitigating security incidents.
In the event DonePact becomes aware of a confirmed security incident affecting customer data, DonePact will take commercially reasonable steps to:
- investigate the incident
- mitigate and remediate the impact
- notify affected customers where required by applicable law or contract
- cooperate reasonably with customer requests relating to the incident.
7 Business Continuity & Backup
DonePact may maintain backup and recovery procedures intended to support platform continuity and operational resilience.
However, customers are encouraged to maintain independent backups of critical data and exported records where necessary.
8 Customer Responsibilities
Customers are responsible for:
- maintaining secure credentials
- enabling available security controls where applicable
- managing user permissions
- reviewing AI-generated outputs
- ensuring lawful use of the platform
- maintaining their own endpoint and network security
- evaluating whether the platform is suitable for their specific regulatory or compliance requirements.
9 Sub-Processors
DonePact may engage trusted third-party vendors, infrastructure providers, AI providers, communication providers, analytics providers, and support tools (“Sub-Processors”) to support delivery of the Services.
Sub-Processors may process customer data solely for the purpose of providing services to DonePact and subject to applicable contractual, confidentiality, privacy, and security obligations.
The following list identifies the primary categories of sub-processors that may be used by DonePact.
Current Sub-Processors
- OpenAI — AI and language model services contract text, prompts, metadata, AI requests.
- Anthropic — AI and language model services contract text, prompts, metadata, AI requests.
- Google Cloud / Google APIs — cloud services, integrations, APIs files, metadata, integration data.
- Amazon Web Services (AWS) — cloud infrastructure, storage, processing platform data, files, logs.
- Slack — internal operational communications and support workflows limited support and operational information.
The above list may be updated from time to time as DonePact evolves, introduces new integrations, changes infrastructure, or engages additional service providers.
10 International Data Transfers
Certain sub-processors may process data outside India or the customer’s jurisdiction. Where applicable, DonePact takes commercially reasonable steps to ensure appropriate contractual safeguards are implemented with relevant service providers.
11 Updates to This Page
DonePact may update this Security & Sub-Processor Page from time to time to reflect operational, legal, technical, or business changes.
Material changes may be notified through the platform, customer communications, or updates published on this page.
12 Contact
For security, privacy, or sub-processor related queries, please contact:
- DonePact Legal & Security Team
- Email: info@donepact.com
- Website: www.donepact.com
