Pariom touches one of the most sensitive systems a company runs — its metrics. We treat that as a hard architectural constraint, not a compliance checklist. This page is what we send your IT director. We are an early-stage product; we tell you exactly what's in place today and what isn't yet.
For reconciliation checks against your own database or warehouse, we only ever run a single, read-only SELECT against the query you configure — the query runner rejects anything else. The OAuth grants we request from QuickBooks and Xero for the memo tool are read-scoped: we cannot post a journal entry, modify a contact, or invoice a customer.
We build on Vercel, Supabase, and AWS — each maintains its own compliance program; see their published certifications.
Data processing agreement available on request. Data subject requests handled within 30 days via security@pariom.ai.
California residents can request deletion or access to personal data. Email security@pariom.ai.
Not in scope. Healthcare customers should not upload PHI.
Pariom does not subcontract data handling without disclosing it. The list below is the complete set of vendors who touch customer data.
Full subprocessor list: /legal/subprocessors
Write to security@pariom.ai. We read every report and will acknowledge it and work with you on a fix timeline.