Security & compliance

How your data is
kept separate.

Standup data is sensitive — blockers, sentiment, project status. This page describes what PulseBoard actually does today, and is explicit about what it does not do yet.

Compliance

DPDP Act 2023 (India)

in-progress

Processor terms in the DPA; Grievance Officer to be named before launch

GDPR

in-progress

DPA available. Export is self-serve as CSV, and an owner can delete the whole organisation from Settings — immediate and irreversible

SOC 2

not started

No audit scheduled yet

ISO 27001

not started

Not certified

HIPAA

not supported

Do not put PHI in PulseBoard

What is actually in place

Tenant isolation

The guarantee the whole product rests on.

  • Every query is scoped to your organisation
  • A record from another organisation returns "not found", never "forbidden" — so the response cannot confirm it exists
  • Enforced in the service layer every page and API route goes through, not in the UI
  • Covered by tests that specifically attempt cross-organisation reads

Authentication

Google, Microsoft, or a password you set from an invitation.

  • Google and Microsoft Entra sign-in
  • Passwords hashed with scrypt, never stored or logged in the clear
  • Repeated failed sign-ins lock an address for 15 minutes
  • Sign-in never reveals whether an email address has an account

Access control

Permission-level, checked on the server.

  • Five roles, from member to owner
  • Permissions checked in the request handler, not just hidden in the interface
  • Organisations are invite-only — nobody joins by guessing your domain
  • Nobody can grant a role above their own

Shared client reports

Public links, built to be safe to send outside the company.

  • Reached by a 256-bit random token, never by a guessable id
  • Only the token hash is stored, so a database dump does not yield working links
  • Revocable, and regenerating a report invalidates the previous link
  • Excluded from search engines, and scoped to one client’s work only

Infrastructure

Deliberately small and boring.

  • One application on Vercel, one Postgres database on Neon
  • TLS in transit; encryption at rest provided by Neon
  • Managed backups by the database provider
  • No uptime SLA is offered today

AI and your data

What leaves the system, and what it costs.

  • Standup text is sent to OpenAI to write digests; it is not used to train models
  • Client reports are built from ticket titles only — never raw standup text
  • A hard daily spend cap per organisation, after which output falls back to a plain summary
  • Remove the API key and every AI feature degrades to deterministic text rather than failing

Privacy & DPA

A standard DPA is available on request, and our sub-processors are listed in the privacy policy. Ask us to export or delete your organisation's data at any time.

Read privacy policy →

Security disclosure

Found a vulnerability? Email security@pulseboard.io. We will acknowledge your report and tell you what we did about it. There is no paid bounty programme yet.

Security questions

Reviewing PulseBoard for your team? Ask us anything about the architecture, sub-processors, or how tenant isolation is enforced — we will answer directly.

Request access