Trust requires evidence.
Strategic PMO software can hold sensitive portfolio, investment, and decision context. The security posture has to match. Here is exactly what we do, what we have verified, what remains in progress, and what still requires contractual or independent review.
Where we stand, stated plainly.
SOC 2 Type II
Production-readiness controls are being assembled, but no completed SOC 2 audit or observation-window evidence is published.
Not certified · readiness work in progressISO 27001
A formal information security management system and certification audit remain future work.
Not certified · roadmapISO 27701
Privacy-management certification depends on the future ISO 27001 program and legal review.
Not certified · roadmapHIPAA
Do not submit protected health information. A BAA and HIPAA-qualified deployment are not currently offered without legal and infrastructure approval.
Not currently offeredGDPR & UK GDPR
Privacy terms, DPA/SCC language, and any regional-residency commitment require legal review and a verified regional deployment.
Legal and hosting review requiredCCPA / CPRA
Privacy requests are accepted through the published privacy contact; response obligations and procedures require legal approval.
Program under reviewPCI DSS · SAQ-A
The application uses Stripe-hosted payment workflows and does not intentionally collect PAN data. Final PCI scope and SAQ status require review before billing launch.
Stripe integration built · SAQ pendingCSA CAIQ v4
A CAIQ response is planned for the procurement package but has not been completed or published.
Not yet completedFive pillars.
Core application security controls apply across plans. Contractual certifications, residency, and recovery commitments are offered only after they are implemented and verified.
Encryption everywhere.
- HTTPS is enforced at the hosted application boundaries.
- Application-managed OAuth tokens and provider credentials use versioned AES-256-GCM encryption.
- Tenant identifiers scope application queries and mutations; cross-tenant denial is regression-tested.
- Database and disk encryption remain governed by the contracted hosting-provider configuration.
Identity & access.
- Supabase JWT issuer, audience, signature, and authorized-party controls are enforced server-side.
- Tenant roles and read/write permissions are enforced by backend dependencies, not UI visibility alone.
- Platform-superadmin authority is separated from tenant PMO administration.
- Authentication secrets remain in the hosting environment and are never returned to browsers.
Auditability is structural.
- Governance-sensitive transitions write tenant-scoped audit evidence.
- Decision execution, approvals, project closure, and key PMBOK workflows retain actor and timestamp context.
- AI usage, provider/model selection, evaluations, incidents, and human authority are recorded.
- Universal point-in-time reconstruction and real-time customer-bucket export are not currently claimed.
Resilience & recovery.
- Liveness, dependency readiness, metrics, and worker-heartbeat probes are implemented.
- The current recovery targets are 24-hour RPO and 4-hour RTO while daily backups are the recovery mechanism.
- Backup inventory, logical restore, migration rollback/reapply, and application rollback have been rehearsed.
- Point-in-time recovery and stronger contractual targets remain pre-customer launch decisions.
Vulnerability management.
- Dependency audits, static checks, secret-history scanning, and browser/backend regression suites run in CI.
- Automated weekly dependency updates are configured for Python, npm, and GitHub Actions.
- Independent security-review evidence is represented as complete only after the review is performed and findings are resolved.
- Responsible disclosures can be sent to [email protected]; no public bounty program is claimed.
Auditable AI.
- AI requests are tenant-scoped and protected by per-tenant and per-request usage limits.
- Provider/model inventory, usage evidence, evaluations, and AI incident records are available to platform governance.
- Human approval remains authoritative for decision execution.
- Provider retention and training terms are governed by the selected provider contract and must be reviewed before launch.
Tenant model.
A shared application with enforced tenant scoping; no physical-isolation claim is made.
Reliability targets.
Our production service-level objectives and disaster-recovery design. A live status portal with measured history is on the roadmap.
Who touches what.
The launch configuration and optional providers evidenced by the application. Final contractual notice periods and regions are confirmed in the executed customer agreement.
| Subprocessor | Purpose | Region | Customer data? |
|---|---|---|---|
| Render | API/worker hosting, managed PostgreSQL, Redis | US (Oregon launch configuration) | Application and account data |
| Vercel | Frontend hosting and edge delivery | Provider network | Request metadata; public application assets |
| Supabase | Authentication and isolated hosted identity services | Configured project region | Identity and session metadata |
| Stripe | Payment processing (PCI tokenization) | US, EU | Billing only |
| Sentry | Optional error monitoring and release health | Configured Sentry region | Redacted error and trace telemetry |
| Twilio SendGrid | Transactional account email | Provider region | Recipient address and message content |
| Customer-selected AI provider | Anthropic, OpenAI, or DeepSeek inference when enabled | Per provider contract | Prompt context and generated response |
| Configured customer connectors | Smartsheet import or Slack alert delivery when enabled; other providers require separate scope confirmation | Per connected provider | Only data needed for the configured action |
Last reviewed July 2026. Confirm enabled providers and regions during contracting; optional connectors process data only when a customer enables them.
Current evidence, without fictional completion claims.
Implemented technical evidence is available for review. Legal templates and industry questionnaires remain drafts until counsel and the responsible owner approve them.
Request the packWHAT IS INCLUDED
- WEBCurrent subprocessor registerPublished below
- MDArchitecture and data-flow overviewReview draft
- MDIncident response and observability summaryImplemented
- MDBackup, restore, and rollback summaryRehearsed
- MDAI governance control overviewImplemented
- DRAFTDPA and SCC termsLegal review required
- PLANSIG Lite and CAIQ responsesNot yet completed
- EMAILResponsible disclosure contact[email protected]
The other half of trust.
Customer data ownership
Customer data remains customer-owned under the Terms. Export, deletion, and AI-provider data-use commitments are finalized during legal and operational review rather than implied here.
Data residency
The launch configuration documents its actual hosting regions. EU, UK, APAC, or customer-selected residency is not promised until that deployment is contracted and verified.
DSR & deletion
Privacy requests are accepted through the published privacy contact. Self-service deletion/export and response-time commitments are not claimed until the workflow and legal policy are approved.
Responsible disclosure
Security reports can be sent to [email protected]. A public bounty program, payout schedule, and external triage SLA are not currently offered.
Responsible AI use
Pulse AI records provider/model usage, evaluations, incidents, and human authority. Provider data-use terms remain part of launch and contract review.
Incident communication
The incident runbook defines severity, ownership, containment, and evidence. A public status portal and contractual notification timelines remain launch decisions.
Need the doc pack now?
Drop a line and we will send the reviewed materials currently available, clearly identifying any legal template or questionnaire that remains in draft.
Request the packFound something?
Email [email protected] with a concise description, affected URL, reproduction steps, and impact. Do not include customer data or secret material. A public bounty program and encrypted PGP channel are not currently offered.
Email security team