PantheonGet Early Access
PantheonGet Early Access

Security & Trust

Last updated: August 5, 2026

Pantheon is built to be trusted with your most important relationships. This page is a plain-language overview of how we protect your data, how access is controlled, and how we handle AI. For a detailed security package, contact us.

Our approach

Pantheon connects your channels, organizes the people and conversations that matter, and proposes actions you stay in control of. That means we hold sensitive relationship data on your behalf — and we treat protecting it as a first-order product requirement, not an afterthought.
Security is layered into the platform by default: isolation between accounts and teams, encryption in transit and at rest, least-privilege access internally, and an edge that screens traffic before it reaches our services. The sections below describe the commitments behind that posture.

Your data & privacy

  • Private by default. Your contacts and conversations are yours. They are not visible to other customers, and they are not shared to a team workspace until you explicitly choose to share them.
  • Scoped access. Data is isolated per user and per organization. Access is enforced at the database layer, so one account can never read another's data.
  • You stay in control. Pantheon proposes — drafts, suggestions, and enrichments are surfaced for your review. Nothing acts on your contacts without you.
  • We don't sell your data. Your data is used to provide the product to you, not sold or rented to third parties.

Security architecture

  • Defense in depth. Multiple independent layers — edge, application, and data — each enforce their own controls, so no single failure exposes your data.
  • Edge protection. Public traffic passes through a managed edge with DDoS protection, a web application firewall, and TLS before it reaches any service.
  • Encryption everywhere. Data is encrypted in transit (TLS) and at rest.
  • Account & organization isolation. Access controls are enforced at the data layer for every read and write, keeping each customer's data separated.
  • Hardened services. Internal services authenticate to each other, run on private networking, and are not exposed directly to the public internet.

Access & operations

  • Least privilege. Internal access to systems is limited to what each role needs, and operational tooling does not carry standing, unrestricted access to customer data.
  • Audit trails. Sensitive operations are logged so activity can be reviewed.
  • Secrets handling. Credentials and keys are managed through secure configuration and are never exposed in client code or logs.
  • Continuous improvement. Our security practices evolve with the product; we review and harden as we grow.

AI, handled responsibly

  • Assistive, not autonomous. AI helps you draft, organize, and prioritize. Suggestions are yours to accept, edit, or ignore.
  • Enrichment from signals you'd see anyway. We help you understand the people in your network using available information — surfaced to you, for your review.
  • Your data isn't training fodder. We do not use your private data to train third-party AI models.

Compliance & due diligence

Pantheon is currently in private alpha — access is invite-only. We build to SOC 2 best practices, and a SOC 2 Type II audit and independent third-party assessment are in preparation. A Google CASA assessment is on our roadmap.
Pantheon runs on shared, multi-tenant infrastructure, with every account and organization isolated at the data layer so that one account can never read another's data. Dedicated single-tenant deployments for teams with strict isolation requirements are on our roadmap. Our formal compliance program, including the SOC 2 Type II audit and independent assessment now in preparation, is being built alongside our team and enterprise offering, consistent with how enterprise software is typically assured.
We align our practices with established privacy principles, including GDPR and CCPA, and a Data Processing Agreement is available on request.
For partners and enterprise teams evaluating Pantheon, we maintain a more detailed security package — covering our architecture, data handling, sub-processors, and controls — that we share under NDA. Reach out and we'll walk you through it.

Contact us

Have a security question, a due-diligence request, or something to report? We want to hear from you.

Security & due diligence: enterprise@pantheon.run

General inquiries: support@pantheon.run

Website: https://pantheon.run