PulseWatch is built for operations teams — so we design for security by default. This page summarizes how we protect your data and the signals we collect.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest across our managed infrastructure.
Signed webhooks
Every outbound webhook is HMAC-signed with a per-endpoint secret you control.
Audit logging
Privileged admin actions, plan changes, and data access events are logged for review.
Scoped data access
Role-based permissions isolate customer data. Admin-only operations are server-gated.
Abuse protections
Per-session rate limits, duplicate detection, and automated suspicion scoring on all public forms.
Vendor diligence
Subprocessors (Stripe, Slack, hosting) are evaluated for security posture before onboarding.
Responsible disclosure
If you believe you've found a security issue, please email security@pulsewatch.us. We acknowledge reports within 72 hours and work with researchers to reproduce, triage, and remediate. Please do not publicly disclose issues until we've had a chance to address them.
Compliance
For the latest on our compliance posture — including SOC 2, ISO 27001, HIPAA, and regional data-residency options — contact sales@pulsewatch.us to start a vendor security review. We're happy to provide our latest documentation under NDA.
Subprocessors
- Payment processing: Stripe
- Slack delivery: Slack Technologies
- Email delivery: the app's configured transactional email provider
- Hosting: managed cloud infrastructure
Data deletion
You can delete your account and associated data at any time. Email privacy@pulsewatch.us and we will process the request within 30 days.