Skip to main content
For enterprise buyers

One substrate. SAML, SCIM, BYOK, audit, consent — all first-class.

Enterprise buyers expect SSO, SCIM, immutable audit, BYOK encryption, DPA + BAA, SOC 2 Type II, and a single tenant-scoped consent ledger. Pact ships these as first-class surfaces — not as enterprise add-ons billed separately.

Illustrative outcomes — composite of design-partner deployments

↓ 4 quarters

vs. Salesforce + Marketo + Gainsight rollout

↓ 0

shadow accounts after IdP deprovisioning

↑ 100%

audit evidence pulls served from one ledger

↓ 78%

vendor-management overhead — one DPA, one SOC 2, one BAA

What you get on day one

Six things you stop juggling.

SSO + SCIM that ship out of the box

SAML, OIDC, Microsoft Entra ID, Google Workspace, Okta. SCIM provisioning into Pact roles automatically. When IT removes someone from the IdP group, their Pact access disappears in the same sync cycle. No 'enterprise SSO' upcharge.

BYOK + customer-managed keys

Bring your own data-encryption keys via KMS (AWS, Azure, GCP). Rotate without downtime; the system re-wraps data keys in the background. Key lineage is visible in the admin UI. Audit-grade key separation per tenant.

Immutable audit log — exportable to your SIEM

Every mutation produces an event with actor, IP, before/after, correlation id. Streamed to your SIEM (Datadog, Splunk, ELK) via webhook OR pulled via NDJSON. Retention is configurable per tenant — keep 30 days or 7 years.

DPA + BAA + SOC 2 Type II in the trust center

Standard DPA, signable HIPAA BAA, SOC 2 Type II report (current period), AI subprocessor list, penetration-test summary. Self-serve at /trust — your legal team gets the packet without a sales call.

Tenant isolation, audit-verifiable

Per-request tenant scoping is enforced at the API layer, not just at the UI. Every row has a tenant_id; cross-tenant queries are an exception class. The /audit page surfaces every access — yours and ours.

Procurement-friendly — annual + multi-year terms

Annual billing, multi-year discounts, custom MSA via /contact-sales. Volume pricing on contacts. AI-spend caps are contractual, not just guidelines. The implementation lift is days, not quarters; we will tell you up front if your shape needs something we don't ship.

We were running Salesforce, Marketo, OneTrust, and Gainsight. Quarterly access reviews took two weeks across four vendors. Pact ships the four in one tenant; access reviews now take a morning, and the DPA covers everything we send into the platform.

CISO · Regulated SaaS · 1,200 people · illustrative scenario

For other roles

Try Pact free. Upgrade when it pays for itself.

The Free plan stays free as long as you're under the limits. Pro and Team open with a 14-day trial — full features, no card.

Last reviewed: 2026-06-15

American English · claims grounded against shipped functionality

Closes DP-014 + DP-015