Standup data is sensitive — blockers, sentiment, project status. We treat it like financial data. Encryption everywhere, audit logs you can prove, sovereignty where you need it.
SOC 2 Type II
Audit completes Q3
GDPR
Full DSR endpoints, EU residency
ISO 27001
Certification scoped
HIPAA
On Enterprise · BAA on request
CCPA / CPRA
California consumer rights
PCI DSS
Stripe handles all cardholder data
Every service is isolated, every request is authenticated, every change is audited.
Encrypted at rest (AES-256) and in transit (TLS 1.3 minimum).
Strong defaults, never optional.
You can prove who did what, when.
Boring, predictable infrastructure.
Pick the region. Bring your own LLM.
Standard DPA available. Sub-processor list published. Right-to-export & right-to-delete via UI on day one.
Read privacy policy →Found a vulnerability? Email security@pulseboard.io. Bounty programme paying up to $10K for critical findings.
SOC 2 report, pen-test summary, sub-processor list, network diagram.
Request access