Standup data is sensitive — blockers, sentiment, project status. This page describes what PulseBoard actually does today, and is explicit about what it does not do yet.
DPDP Act 2023 (India)
in-progressProcessor terms in the DPA; Grievance Officer to be named before launch
GDPR
in-progressDPA available. Export is self-serve as CSV, and an owner can delete the whole organisation from Settings — immediate and irreversible
SOC 2
not startedNo audit scheduled yet
ISO 27001
not startedNot certified
HIPAA
not supportedDo not put PHI in PulseBoard
The guarantee the whole product rests on.
Google, Microsoft, or a password you set from an invitation.
Permission-level, checked on the server.
Public links, built to be safe to send outside the company.
Deliberately small and boring.
What leaves the system, and what it costs.
A standard DPA is available on request, and our sub-processors are listed in the privacy policy. Ask us to export or delete your organisation's data at any time.
Read privacy policy →Found a vulnerability? Email security@pulseboard.io. We will acknowledge your report and tell you what we did about it. There is no paid bounty programme yet.
Reviewing PulseBoard for your team? Ask us anything about the architecture, sub-processors, or how tenant isolation is enforced — we will answer directly.
Request access