Built on trust — from the schema up.
Pulse is the customer platform that regulated teams choose. Encryption, access controls, and audit trails are the defaults — not the add-ons.
Annual audit against the trust services criteria. Report available under NDA.
Standard Contractual Clauses, DPA available, EU + US data residency options.
ISMS aligned to ISO 27001 controls. Certification underway.
BAA available on request for healthcare-adjacent workloads.
Payment data is never stored in Pulse. Stripe handles PCI scope end-to-end.
Data subject rights honoured in-app: export, delete, opt-out, and consent.
Every layer, defensible.
Encryption everywhere
Data is encrypted in transit and at rest without any operator action.
- TLS 1.2+ on every request, no plaintext ingress
- AES-256 at rest across databases and backups
- Envelope encryption for secrets and private keys
- Signed webhooks and API requests where possible
Access control
Least privilege for humans, apps, and integrations.
- SSO with SAML and OIDC on Growth plans and above
- Fine-grained role-based access with custom roles
- SCIM provisioning to keep teams in sync
- Row-level security on every table by default
Observability
Every consequential action is logged, tamper-evident, and exportable.
- Immutable audit log across the entire workspace
- Real-time anomaly detection on messaging spikes
- Send-to-SIEM export via signed webhooks
- Data retention policies you configure and enforce
Resilience
The platform is built to keep sending when things go sideways.
- Multi-AZ deployments with automated failover
- Point-in-time recovery on core databases
- Rate-limited, back-pressured message queues
- Documented incident response and status page
Multi-region messaging plane, credited on Enterprise.
Security incident triage begins within one hour, 24x7.
Choose EU or US. On-shore compliance without workarounds.
Your data, on your terms.
Data residency
Choose EU or US at workspace creation. Data stays where it was born.
Right to delete
Delete a customer and every event, message, and profile they touched is gone.
Portability
Export a full customer profile as JSON, on demand, in-app.
Consent-first
Marketing sends respect opt-outs across every channel automatically.
Retention windows
Set a lifespan for events, messages, and PII. Pulse enforces it, not you.
Sub-processors
Full list published. Notification before any change, with objection window.
Answers for your security team.
Do you sign a DPA?+
Where is my data stored?+
How do you handle secrets and API keys?+
Can I get a SOC 2 report?+
What happens when we churn?+
How do you handle security disclosures?+
Need a deeper security review?
Our team will walk through your requirements, share reports, and sign a DPA.