← Back to home
Security

Security at PULSE

Last updated June 22, 2026

Your financial and operational data deserves enterprise-grade protection.

Security isn’t a feature we bolted on — it’s how PULSE is built. Here’s exactly what protects your data today, and where we’re headed.

Security practices

Encryption in Transit
TLS 1.3 protects all data moving between your browser and PULSE.
Encryption at Rest
AES-256 encryption is applied to all stored data.
Row-Level Security
Every group’s data is isolated at the database level — cross-tenant access is structurally impossible.
Role-Based Access
Owner, Manager, and Staff tiers are enforced per location.
Canadian Infrastructure
Data is processed via AWS infrastructure (ca-central-1).
Session Security
JWT sessions are validated server-side on every request.

Trust at a glance

SOC 2 Audit In Progress256-bit EncryptionQuébec BusinessNo Data SellingRBAC Access Control

These badges describe our current posture and commitments — they are not official certification seals.

Data residency

Your data is hosted in Canada (AWS ca-central-1).

Zero data selling

We never sell, share, or use your operational data for any purpose other than running your account. Your numbers are yours.

Access controls & audit logging

  • Role-based permissions: Owner, Manager, and Staff access tiers.
  • Every sensitive action is recorded in an append-only audit log.
  • Service-role API routes authenticate in-handler — the UI is never the only gate.

SOC 2

We are actively pursuing SOC 2 Type II certification. Our controls are aligned with the AICPA Trust Service Criteria for Security. The “In Progress” badge above will be replaced with the official certified seal upon completion of our audit — and not before.

Privacy principles

We follow modern privacy principles for data handling and comply with Québec’s Law 25. You can export everything (PDF and CSV) at any time, and request permanent deletion if you leave — see our Privacy Policy or submit a data request.

Responsible disclosure

Found a vulnerability? Email security@barrancopartners.com. We acknowledge reports within 48 hours and resolve critical issues within 14 days.