Security
Last updated: October 10, 2026
This page explains in plain language how PaveGrid protects the data you entrust to us, which service providers handle that data, and how to report a security problem.
How we protect data
- Tenant isolation. Each organization's data is kept separate by row-level security rules in the database, and every API handler checks the signed-in user's identity and role before it reads or changes data.
- Multi-factor authentication. Organization admins must use multi-factor authentication, with an authenticator app or a passkey. Every user can turn it on.
- Encryption in transit. All traffic uses HTTPS, and browsers are told to always use HTTPS (HSTS).
- Encryption at rest. Stored data is encrypted at rest by our hosting and database providers.
- Third-party keys. When an organization connects its own key for an outside service, the key is stored encrypted in Supabase Vault.
Subprocessors
These service providers process customer data on our behalf to deliver the Service.
| Name | Purpose | Data involved | Region |
|---|---|---|---|
| Vercel | Application hosting | All requests to the Service, including account and content data in transit | United States |
| Supabase | Database, authentication, and file storage | Account information and all content data, including uploaded files | United States |
| Cloudflare | DNS, network protection, and bot protection on sign-up (Turnstile) | IP addresses, request metadata, and browser signals during sign-up | Global network |
| Sentry | Error monitoring | Error reports with browser, device, and request details | United States |
| PostHog | Product analytics | Usage events and the signed-in user's email address | United States |
| Resend | Transactional email | Recipient names and email addresses, and email content such as invitations and notifications | Not specified |
| Upstash | Rate limiting | Account and organization identifiers and IP addresses used as request counters | Not specified |
| Stripe | Subscription billing and payments | Billing contact details and payment information | Not specified |
| Stadia Maps | Satellite map tiles | Map tile requests, which include the viewer's IP address and the map area viewed | Not specified |
| Nearmap | Aerial imagery, only when an organization connects its own Nearmap key | Map tile requests for the areas viewed | Not specified |
| ConvertAPI | CAD drawing conversion, only when a CAD drawing is converted | The CAD drawing file being converted | Not specified |
| Anthropic, PBC | AI document reading (optional, per organization) | The pages of the one document being read, which can include names, figures, and project details printed on it | United States |
Reporting a vulnerability
If you find a security problem in PaveGrid, email [email protected]. Please include:
- A description of the problem and the impact you expect it to have.
- The steps or a proof of concept to reproduce it.
- The affected URLs, accounts, or requests.
- How we can contact you for follow-up questions.
Scope. pavegrid.com and its subdomains. Do not use social engineering or phishing, do not run denial-of-service tests, and do not access, change, or keep other customers' data beyond the minimum needed to prove the issue.
Safe harbor. If you act in good faith and follow these rules, we will not take legal action against you for your research, and we will work with you to understand and fix the issue.
We do not run a paid bug bounty program.