Skip to content
Interactive concept · Fictional business and sample data · Back to portfolio
Portfolio

Pulsegrid / Security

Security and compliance

Where your data is stored, who can reach it, and who else is involved. Documents are available under NDA through the trust portal.

Certifications

StandardStatusLast audit
SOC 2 Type IICertifiedMarch 2026, Illustrative auditor
ISO 27001:2022CertifiedNovember 2025
GDPRCompliant, DPA availableReviewed January 2026
HIPAABAA available on ScaleOn request
Penetration testAnnual, third partyFebruary 2026, Illustrative testing partner

Data regions

Chosen at organisation creation and fixed thereafter. Data does not leave the selected region, including backups and support access.

RegionLocationProvider
eu-centralSample regionSample provider
eu-westSample regionSample provider
us-eastSample regionSample provider
us-westSample regionSample provider
ap-southeastSample regionSample provider

Subprocessors

CompanyPurposeData
Primary hosting partner (example)Hosting, four regionsAll customer data
Secondary hosting partner (example)Hosting, one regionAll customer data
Payments partner (example)PaymentsBilling contact and card token
Email partner (example)Transactional emailEmail address, alert body
Support partner (example)Support deskSupport correspondence

We give 30 days notice of any change to this list. Subscribe on the trust portal to be told automatically.

How it is protected

TLS 1.3 in transit, with TLS 1.2 accepted for older agents until January 2027. AES-256 at rest on all volumes and backups. Keys are managed in a hosted key management service with annual rotation.

Nobody by default. Support access requires you to grant it per ticket, it expires after 24 hours, and every session is recorded in your audit log. Eight engineers hold break-glass credentials which page the whole team when used.

The agent redacts values matching common secret patterns before they leave the host, including AWS keys, bearer tokens, private key blocks and anything matching your own configured regexes. Redaction happens at the source, so the raw value never reaches us.

Continuous replication within region plus daily snapshots retained 35 days. RPO is 5 minutes, RTO is 4 hours. We run a full restore exercise quarterly and publish the result in the trust portal.

security@example.com, PGP key on the trust portal. We acknowledge within 24 hours, triage within 3 working days, and pay between 100 and 8,000 euros depending on severity. We have never taken legal action against a good faith researcher and we do not require an NDA to report.