Trust & Security

Security you can check, in plain English

How Pulse360 protects the data it handles. Where we are strong we say so; where we are still building we say what and when. This is the summary; security teams under evaluation can go deeper with us.

What Pulse360 handles

Pulse360 handles employee names, roles and manager relationships; verbatim feedback comments (often anonymous to the recipient); and the ratings and AI narratives derived from them. Each customer is a separate tenant, so no customer can access another customer’s data. Your organisation’s data stays within its own perimeter and never feeds another organisation’s workspace.

How we protect it

The controls that are live today, with an honest note where a limit applies.

Customer isolation

Available today

Every customer is a separate tenant, denied by default and isolated in three independent layers: role-based permissions, company-scoped queries, and database row-level security. Cross-tenant isolation is covered by automated tests.

Encryption

Available today

All traffic is encrypted in transit (TLS). Provider API keys and personal data are encrypted at rest, behind access controls.

Anonymous feedback

Available today

Below a minimum number of reviewers, ratings are blanked before they leave the server, and every read is logged. Anonymity is enforced at the application layer, through access controls and that minimum reviewer threshold.

Sign-in & audit

Available today

Hashed passwords, rate limiting, and short-lived, revocable sessions. Every sign-in, permission and data change is recorded in an append-only log. Multi-factor authentication and SSO are on the roadmap.

AI and your data

Pulse360 is model-agnostic. To write a report it sends limited identifiers and feedback text to a language model, and no provider trains on your data. The model provider is a choice, not a lock-in: for customers who need stricter data residency, we can run open-source models on EU-based infrastructure we operate, or deploy on the customer’s own infrastructure. The Pulse360 application and database are hosted in the EU.

Someone from your team always decides. The AI proposes; people review, challenge, edit or reject every output before it informs a decision. Pulse360 makes no autonomous employment decisions.

Compliance posture

GDPR

Built to act as a processor under a standard DPA: data minimisation, audit logs, access controls and deletion paths. The data-subject-request workflow is being automated.

EU AI Act

Pulse360 is built in line with the EU AI Act. Every insight carries a visible confidence score with the evidence behind it, and no output becomes a decision without human review and awareness. People decide; the AI assists.

For security teams

Evaluating Pulse360? We are happy to go deeper on any control above and share what is relevant to your review. Tell us what your security team needs.

Talk to us