Security is not a feature.
It's a foundation.

Pulse handles your most sensitive business data — revenue, customers, operations. We built security into every layer, not bolted it on after the fact.

Compliance

Industry-standard certifications

SOC 2 Type II

Audited annually for security, availability, and confidentiality controls.

HIPAA Compliant

BAA agreements available. PHI handled with encryption and access controls.

GDPR Ready

Data residency controls, right-to-erasure, and consent management built in.

Encryption at Rest & Transit

AES-256 for stored data. TLS 1.3 for every connection, no exceptions.

Security Features

Defense in depth, by design

Every layer of Pulse — from authentication to query execution — is built with tenant isolation and least-privilege access in mind.

Multi-Tenant Isolation

Row-level security for shared infrastructure. Dedicated schema-per-org for Enterprise. Your data never leaks across boundaries.

Role-Based Access Control

Five-level hierarchy: Global Admin, Org Owner, Org Admin, Member, Viewer. Every action is permission-checked at the API layer.

End-to-End Encryption

TLS 1.3 in transit, AES-256 at rest. Encryption keys managed by Google Cloud KMS with automatic rotation.

Audit Trails

Every data access, configuration change, and login event is logged with timestamp, actor, and IP. Exportable and searchable.

SSO & SAML

Enterprise SSO with SAML 2.0 and OIDC support. Enforce MFA, session limits, and domain-restricted signups.

DDoS Protection

Google Cloud Armor and global load balancing absorb volumetric attacks. Rate limiting and bot detection on every endpoint.

Infrastructure

Built on Google Cloud Platform

We chose GCP for its world-class security posture, global network, and compliance certifications.

Google Cloud Platform

Built entirely on GCP with SOC 1/2/3, ISO 27001, and FedRAMP certified infrastructure.

Cloud Run

Serverless containers with automatic scaling, zero cold-start data exposure, and per-request isolation.

Cloud SQL (PostgreSQL)

Managed PostgreSQL with automated backups, point-in-time recovery, and encrypted connections.

Firestore

Document-level security rules, automatic replication across regions, and IAM-controlled access.

Data Flow

How your data moves through Pulse

From ingestion to query, every step is encrypted, validated, and scoped to your organization.

01

Connector Ingestion

Data arrives via OAuth-authenticated connectors. Credentials are stored in Google Secret Manager, never in application code.

02

Encrypted Pipeline

Data is encrypted in transit via TLS 1.3 and validated against the unified schema before processing.

03

Tenant-Isolated Storage

Each organization's data is tagged with org_id and isolated via RLS policies or dedicated schemas.

04

Scoped Queries

Every query — whether from the UI, API, or AI — is scoped to the requesting org. No cross-tenant data access is possible.

Responsible Disclosure

Found a vulnerability? We take security reports seriously. Please disclose responsibly and we'll work with you to resolve it quickly. Do not publicly disclose issues before we've had a chance to address them.

security@pulse.app

Have security questions?

Our team is ready to walk through our security architecture, compliance posture, and data handling practices.