Trust & Security
How Pulse360 protects the data it handles. Where we are strong we say so; where we are still building we say what and when. This is the summary; security teams under evaluation can go deeper with us.
Pulse360 handles employee names, roles and manager relationships; verbatim feedback comments (often anonymous to the recipient); and the ratings and AI narratives derived from them. Each customer is a separate tenant, so no customer can access another customer’s data. Your organisation’s data stays within its own perimeter and never feeds another organisation’s workspace.
The controls that are live today, with an honest note where a limit applies.
Every customer is a separate tenant, denied by default and isolated in three independent layers: role-based permissions, company-scoped queries, and database row-level security. Cross-tenant isolation is covered by automated tests.
All traffic is encrypted in transit (TLS). Provider API keys and personal data are encrypted at rest, behind access controls.
Below a minimum number of reviewers, ratings are blanked before they leave the server, and every read is logged. Anonymity is enforced at the application layer, through access controls and that minimum reviewer threshold.
Hashed passwords, rate limiting, and short-lived, revocable sessions. Every sign-in, permission and data change is recorded in an append-only log. Multi-factor authentication and SSO are on the roadmap.
Pulse360 is model-agnostic. To write a report it sends limited identifiers and feedback text to a language model, and no provider trains on your data. The model provider is a choice, not a lock-in: for customers who need stricter data residency, we can run open-source models on EU-based infrastructure we operate, or deploy on the customer’s own infrastructure. The Pulse360 application and database are hosted in the EU.
Someone from your team always decides. The AI proposes; people review, challenge, edit or reject every output before it informs a decision. Pulse360 makes no autonomous employment decisions.
Built to act as a processor under a standard DPA: data minimisation, audit logs, access controls and deletion paths. The data-subject-request workflow is being automated.
Pulse360 is built in line with the EU AI Act. Every insight carries a visible confidence score with the evidence behind it, and no output becomes a decision without human review and awareness. People decide; the AI assists.
Evaluating Pulse360? We are happy to go deeper on any control above and share what is relevant to your review. Tell us what your security team needs.
Talk to us