Access control
Role-based access, least-privilege defaults, and tenant isolation are in place.
Trust
We publish our certification status honestly. Below is where we stand today and what is on the roadmap, so you can make an informed decision.
Status
PulsePigeon is not currently SOC 2 certified. We operate the underlying controls a SOC 2 audit examines, and we intend to pursue a Type II report as the business matures. We will not claim a certification we do not hold; this page is updated as our posture changes.
Role-based access, least-privilege defaults, and tenant isolation are in place.
TLS in transit and encryption at rest, with server-side secret management.
Access and delivery logging with alerting on anomalies.
Reviewed, tested deployments with a defined vulnerability-remediation process.
For a current security overview, see Security. For data-processing terms, see the Data Processing Addendum. Enquiries: [email protected].