Security

Effective: 2026-09-05

Where Paso stands

Paso itself has not completed a SOC 2 or ISO 27001 audit. The providers that hold your data publish their own attestations: Supabase, which runs our database and file storage, states SOC 2 Type 2 and ISO 27001; Vercel, which hosts the site, publishes its own security program. Those attestations cover the providers, not Paso.

What follows is what Paso does itself.

Where your data is held

Our database and file storage run on Supabase in the United States (AWS us-east-1). The site runs on Vercel. Analytics is held by Vercel in the United States. Paso runs no servers or disks of its own.

In transit

Everything between your browser and Paso travels over HTTPS. Analytics events go to our own domain first and are forwarded from there.

At rest

Our database and file storage are encrypted at rest by our provider (AES-256, as Supabase states).

Uploaded files

After the text of a deck submitted through our screening form has been extracted, we attempt to remove the deck from storage, and a weekly sweep retries any removal that failed; the extracted text is kept with the assessment. Files you upload inside your portal, and documents you send us during an engagement, are kept with your engagement.

Sign-in and sessions

Sign-in is by a one-time link sent to your email address. We do not store passwords. A session lives in a cookie marked secure and unreadable by scripts. Admin, member, participant, board, viewer and investor sessions are signed tokens; sessions for ecosystem contacts are random tokens checked against our database on each request. Some older viewer and investor cookies are still accepted until they expire. Internal sessions last seven days; investor, member, participant and ecosystem-contact sessions thirty days; board and report-viewer sessions ninety days. Shared pages open with single-purpose links, and those links are stripped from analytics before any event leaves your browser.

Who can read what

Our engine processes your text through an AI provider whose commercial terms do not use it for training by default. A person reads what you send through our screening form; during an engagement, the people working on it have access to your materials and use them only as reasonably necessary to perform our services. Internal tools are on a separate admin surface with analytics disabled.

Monitoring

Production errors are reported to Sentry with access tokens removed. A session replay is captured only when an error occurs.

If something goes wrong

If we learn of a security incident that affects your data, we notify you.

Reporting a concern

Write to info@bypaso.com with "security" in the subject line.

Adapted from the 37signals open-source policies, CC BY 4.0.