Trust

Security is the product.

PulseWatch AI is built and maintained by a small team that has run production monitoring for a decade. Here is exactly what we do — and what we ask you to do — to keep your data safe.

This page is maintained by PulseWatch AI, Inc. and describes current product controls. It is not an independent certification.

Product controls

Encryption in transit and at rest
All customer traffic uses TLS 1.2+ with modern cipher suites. Data at rest is encrypted with AES-256 on managed AWS storage.
Role-based access control
Every workspace supports Owner, Admin, Editor, and Viewer roles. Enterprise adds custom roles and per-monitor scoping.
SSO and SCIM
Google and Microsoft SSO on Business. SAML 2.0 and SCIM 2.0 provisioning on Enterprise.
Audit log
Every workspace change — invites, role changes, monitor edits, alert rule changes — is written to an immutable audit log retained for 12 months.
Isolated infrastructure
Workloads run in a locked-down VPC per region with private networking between services. No third-party subprocessor has access to raw customer data.
Data residency
Choose us-east-1, eu-west-1, or ap-southeast-1 at signup. Data never leaves the region you selected.
Incident response
24/7 on-call rotation. Sev1 incidents get a status page update within 15 minutes and a written postmortem within 5 business days.
Responsible disclosure
Report vulnerabilities to security@pulsewatch.tech. We respond within one business day and credit reporters in our hall of fame.

Subprocessors

These are the third parties we rely on to deliver the service. We give 14 days notice before adding a new subprocessor.

VendorPurposeRegion
Amazon Web ServicesCompute, storage, networkingUS / EU / AP
CloudflareEdge network and DDoS protectionGlobal
StripePayment processingUS
PostmarkTransactional email deliveryUS
SentryApplication error reportingUS
Report a vulnerability

Email security@pulsewatch.tech with steps to reproduce. We reply within one business day.

Compliance documents

Customers on Business and Enterprise plans can request our DPA, security whitepaper, and pen-test summary via sales.