PulseBeta

Security

Updated 2026-10-11.

Pulse is not SOC 2 certified and has no SOC 2 or ISO 27001 report. It is built and run by a very small team.

Where it runs

On Cloudflare's network. Cloudflare encrypts stored data (Durable Objects, D1, R2) at rest, and every connection uses TLS. Secrets you give us (AI provider keys, bucket credentials, SSO client secrets, chat tokens) are encrypted again before they are stored, with a key kept outside the database, and are never shown back to anyone.

Signing in

Passkeys (recommended), a password (stored only as a salted, peppered PBKDF2 hash), Google, Microsoft, GitHub or Apple, or your organization's SSO. Sessions are random tokens stored only as hashes and expire after 30 days of no use; you can sign out everywhere at once. Organizations can require SSO.

API keys and agents

Keys are shown once, stored only as hashes, tied to one person and one organization, limited by scope, can expire, and stop working when that person leaves the organization. Every API request that changes something and every MCP tool call is written to the audit log.

Audit log

Sign-ins, changes, API and MCP actions in your organization are recorded with who, how, when and from where. Organization admins can read, filter and export it. The last 28 days are searchable; each older day is archived as a compressed file, in your own bucket if you connected one, and admins can download it (every download is recorded).

Backups

Cloudflare keeps 30 days of point-in-time history for our databases. Last restore drill: not yet performed.

Ingest keys and ping URLs are signed tokens that belong to the organization, not to a person. They keep working when a member leaves, so revoke them in Pulse.

Your part

Use passkeys, give people and agents the lowest role that works, set expiry dates on keys, review your audit log, and rotate credentials you share with us if you think they leaked.

Reporting a problem

Email admin@nightroll.app.