Security at PULSE
Your financial and operational data deserves enterprise-grade protection.
Security isn’t a feature we bolted on — it’s how PULSE is built. Here’s exactly what protects your data today, and where we’re headed.
Security practices
Trust at a glance
These badges describe our current posture and commitments — they are not official certification seals.
Data residency
Your data is hosted in Canada (AWS ca-central-1).
Zero data selling
We never sell, share, or use your operational data for any purpose other than running your account. Your numbers are yours.
Access controls & audit logging
- Role-based permissions: Owner, Manager, and Staff access tiers.
- Every sensitive action is recorded in an append-only audit log.
- Service-role API routes authenticate in-handler — the UI is never the only gate.
SOC 2
We are actively pursuing SOC 2 Type II certification. Our controls are aligned with the AICPA Trust Service Criteria for Security. The “In Progress” badge above will be replaced with the official certified seal upon completion of our audit — and not before.
Privacy principles
We follow modern privacy principles for data handling and comply with Québec’s Law 25. You can export everything (PDF and CSV) at any time, and request permanent deletion if you leave — see our Privacy Policy or submit a data request.
Responsible disclosure
Found a vulnerability? Email security@barrancopartners.com. We acknowledge reports within 48 hours and resolve critical issues within 14 days.