Skip to main content
PulsePulse Appointments

Security

Protecting your business data and your clients' information is foundational to everything Pulse does. Here is how we keep your data safe.

Encryption in transit and at rest

Pulse uses HTTPS with modern TLS to protect data in transit. Production data is stored on managed infrastructure that provides encryption at rest. Specific infrastructure controls are reviewed with enterprise customers on request.

Password security

Passwords are hashed with bcrypt (cost factor 12) before storage. Pulse never stores plaintext passwords. Password reset tokens are single-use and expire in 15 minutes.

Two-factor authentication

All user accounts can enable two-factor authentication (2FA) via email or SMS. Business owners are encouraged to enable 2FA on initial setup. Recovery codes are provided at enrollment.

Audit logging

Pulse records selected administrative and operational events to support security review and incident investigation. Audit records are restricted to authorized administrative access. The current log does not include cryptographic immutability controls.

Login alerts

When a sign-in is identified as new based on device and IP history, Pulse attempts to send a security alert email. Where password sign-in is enabled, the alert includes a short-lived password-reset link.

Infrastructure

Pulse runs on Railway-managed infrastructure. Railway publishes its security and compliance posture, including its SOC 2 Type II attestation, through its trust documentation. Pulse does not claim that a provider attestation certifies Pulse itself.

PCI compliance via Stripe

Pulse does not store credit card numbers, CVVs, or full payment details. All card processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. Pulse receives only tokenized references.

Privacy practices

Pulse uses purpose limitation, data minimization, access controls, and documented request channels to support business privacy obligations. See our Privacy Policy for details.

Read our Privacy Policy

Breach notification

In the event of a confirmed data breach affecting your business, Pulse will notify affected businesses and, where required, regulators or individuals in accordance with applicable law.

Responsible disclosure

Security researchers who discover a vulnerability in Pulse are encouraged to report it responsibly. We commit to acknowledging reports within 2 business days and to not pursuing legal action against good-faith disclosures.

[email protected]

Questions about our security practices?

We are happy to answer questions from business owners, enterprise buyers, or privacy officers.

[email protected]

Last reviewed: July 3, 2026 · Privacy Policy · Canadian Privacy · Terms of Service