Pulse 3.0 shipped: Predictive signals, journey AI, and sub-90s response times. See what's new →
Trust & security

Built on trust — from the schema up.

Pulse is the customer platform that regulated teams choose. Encryption, access controls, and audit trails are the defaults — not the add-ons.

SOC 2 Type II

Annual audit against the trust services criteria. Report available under NDA.

GDPR ready

Standard Contractual Clauses, DPA available, EU + US data residency options.

ISO 27001 aligned

ISMS aligned to ISO 27001 controls. Certification underway.

HIPAA-friendly

BAA available on request for healthcare-adjacent workloads.

PCI-aware

Payment data is never stored in Pulse. Stripe handles PCI scope end-to-end.

CCPA / CPRA

Data subject rights honoured in-app: export, delete, opt-out, and consent.

The controls

Every layer, defensible.

Encryption everywhere

Data is encrypted in transit and at rest without any operator action.

  • TLS 1.2+ on every request, no plaintext ingress
  • AES-256 at rest across databases and backups
  • Envelope encryption for secrets and private keys
  • Signed webhooks and API requests where possible

Access control

Least privilege for humans, apps, and integrations.

  • SSO with SAML and OIDC on Growth plans and above
  • Fine-grained role-based access with custom roles
  • SCIM provisioning to keep teams in sync
  • Row-level security on every table by default

Observability

Every consequential action is logged, tamper-evident, and exportable.

  • Immutable audit log across the entire workspace
  • Real-time anomaly detection on messaging spikes
  • Send-to-SIEM export via signed webhooks
  • Data retention policies you configure and enforce

Resilience

The platform is built to keep sending when things go sideways.

  • Multi-AZ deployments with automated failover
  • Point-in-time recovery on core databases
  • Rate-limited, back-pressured message queues
  • Documented incident response and status page
99.99%
Uptime target

Multi-region messaging plane, credited on Enterprise.

<1h
Incident response

Security incident triage begins within one hour, 24x7.

2
Data regions

Choose EU or US. On-shore compliance without workarounds.

Privacy by design

Your data, on your terms.

Data residency

Choose EU or US at workspace creation. Data stays where it was born.

Right to delete

Delete a customer and every event, message, and profile they touched is gone.

Portability

Export a full customer profile as JSON, on demand, in-app.

Consent-first

Marketing sends respect opt-outs across every channel automatically.

Retention windows

Set a lifespan for events, messages, and PII. Pulse enforces it, not you.

Sub-processors

Full list published. Notification before any change, with objection window.

Frequently asked

Answers for your security team.

Do you sign a DPA?+
Yes. Pulse offers a standard DPA that includes GDPR Standard Contractual Clauses, and is happy to negotiate reasonable amendments for Enterprise customers.
Where is my data stored?+
You choose EU or US at workspace creation. Data at rest, backups, and analytics all stay in the chosen region. Cross-region processing is opt-in.
How do you handle secrets and API keys?+
Secrets are stored envelope-encrypted with an isolated key management system. Only the specific job that needs a secret can decrypt it, and every access is logged.
Can I get a SOC 2 report?+
Yes, the SOC 2 Type II report is available under NDA. Request a copy through your account team or from the demo form.
What happens when we churn?+
You can export data at any time. When you offboard, we delete customer data within 30 days from active systems and within 90 days from backups.
How do you handle security disclosures?+
Responsible disclosure via security@pulse.cloud. We triage within one hour and publish security advisories to affected customers directly.

Need a deeper security review?

Our team will walk through your requirements, share reports, and sign a DPA.