Sygenti
Solutions
Pricing

Security Policy

Our commitment to protecting your data

Security Policy

Last Updated: Mar 9, 2026

1. Our Commitment to Security

At Pulse, security is not an afterthought—it's fundamental to everything we do. We are committed to protecting your data and maintaining the trust you place in us.

2. Infrastructure Security

2.1 Cloud Infrastructure

  • Hosting: Built on enterprise-grade cloud infrastructure (Supabase/AWS)
  • Data Centers: Multiple geographically distributed data centers with redundancy
  • Physical Security: 24/7 monitored facilities with restricted access
  • Availability: 99.9% uptime SLA with automated failover

2.2 Network Security

  • Firewalls: Multi-layered firewall protection
  • DDoS Protection: Advanced distributed denial-of-service mitigation
  • Network Isolation: Segregated networks for different service components
  • Intrusion Detection: Real-time monitoring and threat detection systems

3. Data Security

3.1 Encryption

  • In Transit: TLS 1.3 encryption for all data transmission
  • At Rest: AES-256 encryption for stored data
  • Backups: Encrypted backups with secure key management
  • Database: Encrypted database connections and storage

3.2 Data Protection

  • Access Controls: Role-based access control (RBAC) with least privilege principle
  • Data Isolation: Logical separation between customer workspaces
  • Data Residency: Compliance with regional data storage requirements
  • Backup Strategy: Automated daily backups with point-in-time recovery

3.3 Data Retention and Deletion

  • User Control: Users can delete their data at any time
  • Retention Policy: Data is retained as per our Privacy Policy
  • Secure Deletion: Secure data wiping procedures for deleted data
  • Backup Retention: Backups retained for 30 days for disaster recovery

4. Application Security

4.1 Secure Development Practices

  • Security by Design: Security considerations from the initial design phase
  • Code Reviews: Mandatory peer review for all code changes
  • Static Analysis: Automated security scanning of source code
  • Dependency Management: Regular updates and vulnerability scanning of dependencies

4.2 Authentication and Authorization

  • Password Security: Bcrypt hashing with salt for password storage
  • Multi-Factor Authentication: Optional 2FA for additional security
  • OAuth Integration: Secure third-party authentication (Google, etc.)
  • Session Management: Secure token-based session handling with automatic expiration
  • API Security: API key management with rate limiting and monitoring

4.3 Input Validation and Security

  • Input Sanitization: All user inputs are validated and sanitized
  • SQL Injection Prevention: Parameterized queries and ORM usage
  • XSS Protection: Content Security Policy and output encoding
  • CSRF Protection: Token-based CSRF prevention
  • Rate Limiting: Protection against brute force and abuse

5. Operational Security

5.1 Monitoring and Logging

  • Security Monitoring: 24/7 automated security monitoring
  • Audit Logs: Comprehensive logging of system and user activities
  • Anomaly Detection: AI-powered detection of unusual patterns
  • Incident Response: Real-time alerts for security events

5.2 Incident Response

  • Response Team: Dedicated security incident response team
  • Response Plan: Documented incident response procedures
  • Notification: Prompt notification to affected users in case of breaches
  • Post-Incident Review: Thorough analysis and improvement process

5.3 Business Continuity

  • Disaster Recovery: Comprehensive disaster recovery plan
  • Data Backups: Automated backups with tested restore procedures
  • Failover Systems: Automated failover to backup systems
  • Regular Testing: Quarterly disaster recovery drills

6. Compliance and Certifications

6.1 Compliance Standards

Pulse complies with UK GDPR and is registered with the Information Commissioner's Office (ICO). We follow security practices aligned with ISO 27001, with formal certification planned. We are actively pursuing Cyber Essentials certification as part of our ongoing commitment to information security.

6.2 Privacy Frameworks

  • Privacy Shield principles (where applicable)
  • Standard Contractual Clauses for international transfers
  • Regional data protection regulations

7. Third-Party Security

7.1 Vendor Management

  • Due Diligence: Security assessment of all third-party vendors
  • Contracts: Data processing agreements with security requirements
  • Monitoring: Ongoing monitoring of third-party security posture
  • Limited Access: Principle of least privilege for third-party access

7.2 Sub-processors

We use the following trusted sub-processors:

  • Supabase: Database and authentication services
  • Stripe: Payment processing
  • Vercel: Application hosting
  • Google Cloud: Calendar integration and cloud services

8. Employee Security

8.1 Access Control

  • Background Checks: Security screening for all employees
  • Need-to-Know: Access limited to what's necessary for job function
  • Privileged Access: Multi-factor authentication for administrative access
  • Access Reviews: Regular review and revocation of access rights

8.2 Training and Awareness

  • Security Training: Mandatory security awareness training
  • Phishing Simulations: Regular testing of employee awareness
  • Secure Practices: Guidelines for secure development and operations
  • Confidentiality: All employees sign confidentiality agreements

9. Vulnerability Management

9.1 Vulnerability Assessment

  • Regular Scanning: Automated vulnerability scanning
  • Penetration Testing: Annual third-party penetration testing
  • Bug Bounty: Responsible disclosure program (coming soon)
  • Security Audits: Regular internal and external security audits

9.2 Patch Management

  • Timely Updates: Prompt application of security patches
  • Dependency Updates: Regular updates to dependencies and libraries
  • Emergency Patches: Rapid response for critical vulnerabilities
  • Testing: Thorough testing before deploying updates

10. Responsible Disclosure

10.1 Reporting Security Vulnerabilities

If you discover a security vulnerability, please report it to us:

  • Email: security@pulseio.net
  • Response Time: We aim to acknowledge reports within 24 hours
  • Investigation: We will investigate all legitimate reports
  • Updates: We'll keep you informed of our progress

10.2 What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any proof-of-concept code (if applicable)

10.3 Responsible Disclosure Guidelines

  • Give us reasonable time to address the issue before public disclosure
  • Do not access or modify user data without permission
  • Do not perform actions that could harm the Service or users
  • Do not use automated tools that generate excessive load

11. User Security Best Practices

11.1 Recommendations for Users

  • Use strong, unique passwords
  • Enable multi-factor authentication
  • Keep your software and devices updated
  • Be cautious of phishing attempts
  • Review workspace access regularly
  • Report suspicious activity immediately

11.2 Workspace Administrators

  • Implement strong access policies
  • Regularly review user permissions
  • Enable audit logging
  • Train team members on security best practices
  • Remove access for departing team members promptly

12. Security Updates and Communication

We communicate security updates through:

  • Status Page: Real-time service status and incident updates
  • Email Notifications: Security alerts for critical issues
  • Blog: Security announcements and best practices
  • Release Notes: Security fixes in product updates

13. Questions and Contact

For security-related questions or concerns:

  • General Security: security@pulseio.net
  • Report Vulnerability: security@pulseio.net (encrypted emails welcome)
  • Security Officer: vu@pulseio.net
  • Privacy: privacy@pulseio.net

Our Promise

Security is an ongoing journey, not a destination. We continuously invest in improving our security posture and welcome feedback from our users and the security community.

Last reviewed: March 9, 2026
Next review: June 31, 2026

Sygenti

Sygenti is your pit wall.

The execution intelligence system for leaders running complex work.

© 2026 Sygenti. All rights reserved.

LinkedIn

Product

  • Pricing
  • FAQ
  • Contact Us
  • Docs

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • Cookie Policy

Get Started

  • Sign In
  • Create Account