Last updated 25 September 2026
Where your data lives
- Hosted in London. The Pulse app and its database run in London, UK, with our hosting provider Fly.io.
- Encrypted in transit. Every connection to Pulse uses HTTPS (TLS), including uploads and downloads.
- Secrets encrypted at rest. Sensitive credentials Pulse stores for you, such as connected-service keys, are encrypted with AES-256-GCM.
- Files kept private. Uploaded drawings and documents are stored in private object storage and shown only to people on that project.
Who can see what
- Separate for every practice. Each practice's projects, files and conversations are kept apart. No other practice can see them.
- Permissions by project. Studio staff, clients, consultants and contractors see only the projects they're invited to, and only what their role allows. Contractors, for example, see approved drawings, not fees.
- You control the client view. Internal notes, risk flags and cost figures stay private unless you choose to share them.
Signing in
- Two-factor sign-in. Users can switch on an authenticator app, and sign-in can also require a one-time code sent by email.
- Passwords never stored. Passwords are kept only as a one-way bcrypt hash, so nobody at Pulse can read them.
- Protection against guessing. Repeated sign-in attempts are rate-limited, and sessions can be revoked after a password change or when someone leaves the practice.
AI, done carefully
- Never used to train models. Pulse uses Anthropic's Claude for AI features. Your project content is sent only to deliver the feature you asked for, and it isn't used to train third-party models.
- A human always decides. Pulse drafts replies, write-ups and reports. Nothing is sent to a client without someone at your practice reviewing it.
Accountability
- Audit log. Security-relevant actions, such as sign-ins, failed sign-ins, password and two-factor changes, invitations and role changes, are recorded.
- A proper decision record. Project decisions and approvals keep who did what and when, which helps if you ever need to show your working.
- UK GDPR. For project data, your practice is the data controller and Pulse is the processor. We act only on your instructions, under a data processing agreement.
Our providers
We use a short list of established providers, each under contract:
- Fly.io: application hosting and database, London region
- Tigris: private storage for uploaded files
- Anthropic: AI features, with no training on your data
- Microsoft: service email, and connected-mailbox features where you switch them on
Reporting a security issue
If you think you've found a vulnerability, please email enquiries@pulsecentric.com with "Security" in the subject. We'll acknowledge it within two working days. Please give us a reasonable chance to fix it before making it public.
Questions about how Pulse would fit your practice's own data policies? Talk to us. We're happy to share more detail with your IT or compliance lead.