# Security

> Where your telemetry lives, how keys and ping URLs work, who can do what, and what Pulse keeps.

## Where data lives

Pulse runs on Cloudflare: Workers, Durable Objects (one per org) and an R2 bucket. Your telemetry is kept for 7 days, then copied to [your own bucket](/docs/archive-and-grace/) and deleted from Pulse. Bucket credentials, the Shift routing key and other org secrets are encrypted with AES-256-GCM before they're stored, and are write-only in the app.

## Keys and ping URLs

- **Ingest keys** (`pulse_ik_...`) and **ping URLs** are signed tokens that belong to the org, not to a person. They keep working when a member leaves, so revoke ingest keys and delete or recreate checks in Pulse when you need to. An ingest key can only send data.
- **API keys** (`nr_pulse_...`) belong to a person and one org, are stored only as hashes, and stop working when that person leaves the org.
- Sign-in is by passkey, password, Google, Microsoft, GitHub, Apple or your org's SSO.

## Who can do what

| Role | Can |
| --- | --- |
| Viewer | Query, tail, and see checks, monitors, alerts and the archive |
| Member | Also create, change, pause and delete checks and monitors |
| Admin | Also manage ingest keys, alert settings, the archive, storage, members and API keys |
| Owner | Also delete the org |

## What not to send

Pulse stores whatever your logs and attributes contain. Don't send secrets, credentials or special-category personal data; scrub them in the Collector first.

## Your records

Every change, sign-in and MCP tool call is in **Settings → Audit log**. The [security](/legal/security) and [privacy](/legal/privacy) pages have the details.
