PulsePigeonemail infrastructure

Current posture

Built for regulated SaaS mail

The platform separates critical transactional mail from lifecycle traffic, records send decisions, and keeps tenant data scoped to the authenticated project.

Certifications

Readiness in progress

SOC 2, ISO 27001, HIPAA BAA, and regional residency are planned programs, not active certifications.

Security controls

Implemented safeguards

Published
Tenant isolationActiveProject-scoped API keys, tenant-scoped stores, and RBAC checks.
Mail stream isolationActiveCritical mail is isolated from marketing and warmup traffic.
Secret handlingActiveProvider credentials stay server-side and are never exposed to clients.
Abuse responseActiveRisk tiers, vetting records, throttles, and suspension appeals are tracked.

Compliance docs

Public commitments

Scoped
GDPR/CCPAActivePreference center, suppression export, retention windows, and DSR workflows.
CAN-SPAMActivePhysical address, unsubscribe, suppression, and consent checks.
PCIActiveCard-number detection blocks outbound mail before enqueue; billing stays with the payment provider.
Pen testsActiveAnnual external test cadence with Critical and High retest requirements.
HIPAAGatedNot a HIPAA BAA tier yet; PHI requires a signed BAA before use.

Status

Operational visibility

Live

SLA and service credits

Review current delivery health and incident signals.

Open

Certification readiness

Review current delivery health and incident signals.

Open

Send pipeline SLO

Review current delivery health and incident signals.

Open

Operations alerts

Review current delivery health and incident signals.

Open

Provider metrics

Review current delivery health and incident signals.

Open

Deliverability alarms

Review current delivery health and incident signals.

Open