Trust

Security and Compliance

Updated September 21, 2026

PACE Pro builds and delivers marketing content for local businesses, including medical practices and health systems, and, when a practice turns the feature on, asks patients for feedback after a visit. Where PACE handles patient information it acts as a business associate under HIPAA, and the platform is built on that basis. This page summarises the controls in place. Every control listed is one we verify on our production systems, and our full Security and Compliance Statement, with evidence, is available to a client's IT or compliance team through their PACE contact.

What PACE holds, and what it never holds

The only patient information PACE holds is what the feedback feature needs: an appointment reference, a first name, the contact the patient consented to be reached on, the consent itself, the visit time, and the provider and clinic. PACE never receives or stores diagnoses, notes, results, documents, insurance or payment information. Everything else PACE processes is the practice's own marketing content and its public reviews.

Agreements

Encryption

Access control

Audit and monitoring

Built-in data handling rules

Integrations

Operations

Questions

A client's IT or security team can request the full statement, evidence for any control above, or a walkthrough of the architecture through their PACE contact. Evidence is shared directly with a named technical contact. Security researchers who believe they have found a vulnerability can reach us at security@pacepro.io.