Security

Last updated: October 10, 2026

This page explains in plain language how PaveGrid protects the data you entrust to us, which service providers handle that data, and how to report a security problem.

How we protect data

  • Tenant isolation. Each organization's data is kept separate by row-level security rules in the database, and every API handler checks the signed-in user's identity and role before it reads or changes data.
  • Multi-factor authentication. Organization admins must use multi-factor authentication, with an authenticator app or a passkey. Every user can turn it on.
  • Encryption in transit. All traffic uses HTTPS, and browsers are told to always use HTTPS (HSTS).
  • Encryption at rest. Stored data is encrypted at rest by our hosting and database providers.
  • Third-party keys. When an organization connects its own key for an outside service, the key is stored encrypted in Supabase Vault.

Subprocessors

These service providers process customer data on our behalf to deliver the Service.

NamePurposeData involvedRegion
VercelApplication hostingAll requests to the Service, including account and content data in transitUnited States
SupabaseDatabase, authentication, and file storageAccount information and all content data, including uploaded filesUnited States
CloudflareDNS, network protection, and bot protection on sign-up (Turnstile)IP addresses, request metadata, and browser signals during sign-upGlobal network
SentryError monitoringError reports with browser, device, and request detailsUnited States
PostHogProduct analyticsUsage events and the signed-in user's email addressUnited States
ResendTransactional emailRecipient names and email addresses, and email content such as invitations and notificationsNot specified
UpstashRate limitingAccount and organization identifiers and IP addresses used as request countersNot specified
StripeSubscription billing and paymentsBilling contact details and payment informationNot specified
Stadia MapsSatellite map tilesMap tile requests, which include the viewer's IP address and the map area viewedNot specified
NearmapAerial imagery, only when an organization connects its own Nearmap keyMap tile requests for the areas viewedNot specified
ConvertAPICAD drawing conversion, only when a CAD drawing is convertedThe CAD drawing file being convertedNot specified
Anthropic, PBCAI document reading (optional, per organization)The pages of the one document being read, which can include names, figures, and project details printed on itUnited States

Reporting a vulnerability

If you find a security problem in PaveGrid, email [email protected]. Please include:

  • A description of the problem and the impact you expect it to have.
  • The steps or a proof of concept to reproduce it.
  • The affected URLs, accounts, or requests.
  • How we can contact you for follow-up questions.

Scope. pavegrid.com and its subdomains. Do not use social engineering or phishing, do not run denial-of-service tests, and do not access, change, or keep other customers' data beyond the minimum needed to prove the issue.

Safe harbor. If you act in good faith and follow these rules, we will not take legal action against you for your research, and we will work with you to understand and fix the issue.

We do not run a paid bug bounty program.