Protecting your data is foundational to everything we build.
At Pulsepath, security isn't an afterthought — it's baked into our architecture, our processes, and our culture. We understand that you're trusting us with sensitive customer data, and we take that responsibility seriously.
In transit: All data transmitted between your systems and Pulsepath is encrypted using TLS 1.2 or higher. We enforce HTTPS on all endpoints and use HSTS headers to prevent downgrade attacks.
At rest: All stored data is encrypted using AES-256 encryption. Database backups and log files are also encrypted at rest.
Pulsepath is hosted on Railway, which runs on AWS infrastructure. Our infrastructure benefits from AWS's world-class physical security, network security, and compliance certifications. Key infrastructure practices include:
We follow the principle of least privilege across our organization:
We retain customer conversation data only as long as necessary to provide the Service and generate insights. You can request deletion of your data at any time. When data is deleted, it is permanently removed from our active systems within 30 days and from backups within 90 days.
We maintain a documented incident response plan that includes:
We welcome responsible security research. If you discover a potential vulnerability in our systems, please report it to security@pulsepath.ai. We ask that you:
We will acknowledge your report within 48 hours and work with you to understand and resolve the issue.
If you have questions about our security practices, please reach out to security@pulsepath.ai.