Security
Where data lives
Pulse runs on Cloudflare: Workers, Durable Objects (one per org) and an R2 bucket. Your telemetry is kept for 7 days, then copied to your own bucket and deleted from Pulse. Bucket credentials, the Shift routing key and other org secrets are encrypted with AES-256-GCM before they’re stored, and are write-only in the app.
Keys and ping URLs
- Ingest keys (
pulse_ik_...) and ping URLs are signed tokens that belong to the org, not to a person. They keep working when a member leaves, so revoke ingest keys and delete or recreate checks in Pulse when you need to. An ingest key can only send data. - API keys (
nr_pulse_...) belong to a person and one org, are stored only as hashes, and stop working when that person leaves the org. - Sign-in is by passkey, password, Google, Microsoft, GitHub, Apple or your org’s SSO.
Who can do what
| Role | Can |
|---|---|
| Viewer | Query, tail, and see checks, monitors, alerts and the archive |
| Member | Also create, change, pause and delete checks and monitors |
| Admin | Also manage ingest keys, alert settings, the archive, storage, members and API keys |
| Owner | Also delete the org |
What not to send
Pulse stores whatever your logs and attributes contain. Don’t send secrets, credentials or special-category personal data; scrub them in the Collector first.
Your records
Every change, sign-in and MCP tool call is in Settings → Audit log. The security and privacy pages have the details.