Security & compliance

Built to pass audit
on day one.

Standup data is sensitive — blockers, sentiment, project status. We treat it like financial data. Encryption everywhere, audit logs you can prove, sovereignty where you need it.

Compliance

SOC 2 Type II

in-progress

Audit completes Q3

GDPR

compliant

Full DSR endpoints, EU residency

ISO 27001

in-progress

Certification scoped

HIPAA

available

On Enterprise · BAA on request

CCPA / CPRA

compliant

California consumer rights

PCI DSS

in-scope

Stripe handles all cardholder data

Six pillars of security

Defense in depth

Every service is isolated, every request is authenticated, every change is audited.

  • Per-service VPCs in production
  • Mutual TLS between internal services
  • Web application firewall + DDoS protection at the edge
  • Quarterly third-party penetration testing

Encryption everywhere

Encrypted at rest (AES-256) and in transit (TLS 1.3 minimum).

  • KMS-backed keys with annual rotation
  • Customer-managed keys on Enterprise
  • PII columns separately encrypted with envelope encryption
  • Backups encrypted and georeplicated

Authentication & authorization

Strong defaults, never optional.

  • Google OAuth + SAML SSO (SCIM provisioning on Enterprise)
  • MFA enforceable per role
  • Refresh-token rotation with reuse detection
  • Permission-level RBAC, not role-level

Auditability

You can prove who did what, when.

  • Append-only audit log (90d Pro / 365d Enterprise)
  • SIEM export (Splunk, Datadog, S3)
  • Webhook stream for real-time SOC integration
  • Per-event traceparent for distributed-trace replay

Operational maturity

Boring, predictable infrastructure.

  • Multi-AZ Postgres with automated failover
  • Stateless services + horizontal scaling (HPA)
  • OpenTelemetry across the stack — traces, metrics, logs
  • 99.95% uptime SLA (99.99% on Enterprise)

Data residency & sovereignty

Pick the region. Bring your own LLM.

  • Hosted in us-east-1 (default), eu-west-1, ap-south-1
  • EU customers stay in EU — full data residency
  • On-prem Ollama for full LLM data sovereignty
  • Self-hosted deployment available on Enterprise

Privacy & DPA

Standard DPA available. Sub-processor list published. Right-to-export & right-to-delete via UI on day one.

Read privacy policy →

Security disclosure

Found a vulnerability? Email security@pulseboard.io. Bounty programme paying up to $10K for critical findings.

Get the security pack

SOC 2 report, pen-test summary, sub-processor list, network diagram.

Request access