Security is not a feature.
It's a foundation.
Pulse handles your most sensitive business data — revenue, customers, operations. We built security into every layer, not bolted it on after the fact.
Industry-standard certifications
SOC 2 Type II
Audited annually for security, availability, and confidentiality controls.
HIPAA Compliant
BAA agreements available. PHI handled with encryption and access controls.
GDPR Ready
Data residency controls, right-to-erasure, and consent management built in.
Encryption at Rest & Transit
AES-256 for stored data. TLS 1.3 for every connection, no exceptions.
Defense in depth, by design
Every layer of Pulse — from authentication to query execution — is built with tenant isolation and least-privilege access in mind.
Multi-Tenant Isolation
Row-level security for shared infrastructure. Dedicated schema-per-org for Enterprise. Your data never leaks across boundaries.
Role-Based Access Control
Five-level hierarchy: Global Admin, Org Owner, Org Admin, Member, Viewer. Every action is permission-checked at the API layer.
End-to-End Encryption
TLS 1.3 in transit, AES-256 at rest. Encryption keys managed by Google Cloud KMS with automatic rotation.
Audit Trails
Every data access, configuration change, and login event is logged with timestamp, actor, and IP. Exportable and searchable.
SSO & SAML
Enterprise SSO with SAML 2.0 and OIDC support. Enforce MFA, session limits, and domain-restricted signups.
DDoS Protection
Google Cloud Armor and global load balancing absorb volumetric attacks. Rate limiting and bot detection on every endpoint.
Built on Google Cloud Platform
We chose GCP for its world-class security posture, global network, and compliance certifications.
Google Cloud Platform
Built entirely on GCP with SOC 1/2/3, ISO 27001, and FedRAMP certified infrastructure.
Cloud Run
Serverless containers with automatic scaling, zero cold-start data exposure, and per-request isolation.
Cloud SQL (PostgreSQL)
Managed PostgreSQL with automated backups, point-in-time recovery, and encrypted connections.
Firestore
Document-level security rules, automatic replication across regions, and IAM-controlled access.
How your data moves through Pulse
From ingestion to query, every step is encrypted, validated, and scoped to your organization.
Connector Ingestion
Data arrives via OAuth-authenticated connectors. Credentials are stored in Google Secret Manager, never in application code.
Encrypted Pipeline
Data is encrypted in transit via TLS 1.3 and validated against the unified schema before processing.
Tenant-Isolated Storage
Each organization's data is tagged with org_id and isolated via RLS policies or dedicated schemas.
Scoped Queries
Every query — whether from the UI, API, or AI — is scoped to the requesting org. No cross-tenant data access is possible.
Responsible Disclosure
Found a vulnerability? We take security reports seriously. Please disclose responsibly and we'll work with you to resolve it quickly. Do not publicly disclose issues before we've had a chance to address them.
Have security questions?
Our team is ready to walk through our security architecture, compliance posture, and data handling practices.