PULSE by IntelAlytic · Trust & Security

Security you can verify.

How PULSE protects your data, the frameworks we align to, and who processes information on our behalf. PULSE is built on SOC 2 Type II and ISO 27001 certified infrastructure. For a security questionnaire, our DPA, or subprocessor notices, contact support@intelalytic.com.

AES-256Encryption at rest
TLS 1.2+Encryption in transit
Row-levelTenant isolation
Enforced MFAAdmin-controlled
Compliance

Frameworks & standards.

We map our controls to the frameworks our customers rely on. Ready means the controls are implemented and self-attested. Aligned means we build to the standard's requirements. In Progress means an assessment is underway — we never claim a certification we don't hold.

GDPR / UK GDPREU + UK data protection, self-attested
Ready
CCPA / CPRACalifornia privacy, self-attested
Ready
HIPAASupports PHI workloads under BAA
Ready under BAA
WCAG 2.2 AAAccessibility
Aligned
SOC 2 Type IIIndependent audit underway
In Progress
ISO 27001ISMS controls being implemented
In Progress
NIST SP 800-171Controls mapped for CUI handling
Aligned
CMMC Level 1Basic safeguarding practices in place
Aligned
Foundation

Built on certified infrastructure.

PULSE runs entirely on providers that hold independent SOC 2 and ISO 27001 certifications, and adds its own controls on top: encryption, role-based access, enforced MFA, and a full audit trail.

Amazon Web Services

Application hosting, storage, and compute. SOC 1/2/3, ISO 27001, PCI DSS Level 1, HIPAA-eligible services.

Supabase

Managed Postgres, authentication, and row-level security. SOC 2 Type II; HIPAA available under BAA.

Vercel

Frontend hosting and global edge delivery. SOC 2 Type II, ISO 27001.

GitHub

Source control and CI/CD with code review and dependency scanning. SOC 2 Type II, ISO/IEC 27001.

These certifications cover the infrastructure layer. PULSE layers its own encryption, access control, and audit controls above it.

Security posture

How we protect data.

Encryption

AES-256 at rest and TLS 1.2 or higher in transit, everywhere your data lives or moves.

Access control

Role-based, least-privilege access with optional and admin-enforced MFA, plus tenant isolation via Postgres row-level security.

Monitoring & audit

A full activity log records logins, changes, and role updates, with alerting, testing, and an incident-response process.

Backup & recovery

Automated backups and tested recovery so your data survives failure.

Data residency

Hosted on AWS in the United States, with contractual safeguards for any transfer and data export on demand — no lock-in.

Secure development

Source and CI on GitHub with code review and dependency scanning before anything ships.

Sub-processors

Who processes data for us.

The core processors behind PULSE, each under contract with data-protection terms no less protective than our DPA. Subscribe to change notices at support@intelalytic.com.

Sub-processorPurposeRegionScope
Amazon Web ServicesApplication hosting, storage & computeUnited StatesCore
SupabaseManaged Postgres, authentication & row-level securityUnited States (AWS)Core
VercelFrontend hosting & global edge deliveryUnited States / global edgeCore
GitHubSource control & CI/CDUnited StatesCore
ResendTransactional & notification emailUnited StatesCore
StripePayment processing & billingUnited StatesCore
AnthropicAI features (lead scoring, insights, drafting)United StatesCore

We publish notice before adding or changing a sub-processor. Request the current register and change notifications from support@intelalytic.com.

Need our security package?

Request our questionnaire responses, DPA, and sub-processor notifications.

Contact security