Trust & security

Trust requires evidence.

Strategic PMO software can hold sensitive portfolio, investment, and decision context. The security posture has to match. Here is exactly what we do, what we have verified, what remains in progress, and what still requires contractual or independent review.

Compliance roadmap

Where we stand, stated plainly.

SOC

SOC 2 Type II

Production-readiness controls are being assembled, but no completed SOC 2 audit or observation-window evidence is published.

Not certified · readiness work in progress
ISO

ISO 27001

A formal information security management system and certification audit remain future work.

Not certified · roadmap
ISO

ISO 27701

Privacy-management certification depends on the future ISO 27001 program and legal review.

Not certified · roadmap
HIPAA

HIPAA

Do not submit protected health information. A BAA and HIPAA-qualified deployment are not currently offered without legal and infrastructure approval.

Not currently offered
GDPR

GDPR & UK GDPR

Privacy terms, DPA/SCC language, and any regional-residency commitment require legal review and a verified regional deployment.

Legal and hosting review required
CCPA

CCPA / CPRA

Privacy requests are accepted through the published privacy contact; response obligations and procedures require legal approval.

Program under review
PCI

PCI DSS · SAQ-A

The application uses Stripe-hosted payment workflows and does not intentionally collect PAN data. Final PCI scope and SAQ status require review before billing launch.

Stripe integration built · SAQ pending
CSA

CSA CAIQ v4

A CAIQ response is planned for the procurement package but has not been completed or published.

Not yet completed
How we protect customer data

Five pillars.

Core application security controls apply across plans. Contractual certifications, residency, and recovery commitments are offered only after they are implemented and verified.

01

Encryption everywhere.

  • HTTPS is enforced at the hosted application boundaries.
  • Application-managed OAuth tokens and provider credentials use versioned AES-256-GCM encryption.
  • Tenant identifiers scope application queries and mutations; cross-tenant denial is regression-tested.
  • Database and disk encryption remain governed by the contracted hosting-provider configuration.
02

Identity & access.

  • Supabase JWT issuer, audience, signature, and authorized-party controls are enforced server-side.
  • Tenant roles and read/write permissions are enforced by backend dependencies, not UI visibility alone.
  • Platform-superadmin authority is separated from tenant PMO administration.
  • Authentication secrets remain in the hosting environment and are never returned to browsers.
03

Auditability is structural.

  • Governance-sensitive transitions write tenant-scoped audit evidence.
  • Decision execution, approvals, project closure, and key PMBOK workflows retain actor and timestamp context.
  • AI usage, provider/model selection, evaluations, incidents, and human authority are recorded.
  • Universal point-in-time reconstruction and real-time customer-bucket export are not currently claimed.
04

Resilience & recovery.

  • Liveness, dependency readiness, metrics, and worker-heartbeat probes are implemented.
  • The current recovery targets are 24-hour RPO and 4-hour RTO while daily backups are the recovery mechanism.
  • Backup inventory, logical restore, migration rollback/reapply, and application rollback have been rehearsed.
  • Point-in-time recovery and stronger contractual targets remain pre-customer launch decisions.
05

Vulnerability management.

  • Dependency audits, static checks, secret-history scanning, and browser/backend regression suites run in CI.
  • Automated weekly dependency updates are configured for Python, npm, and GitHub Actions.
  • Independent security-review evidence is represented as complete only after the review is performed and findings are resolved.
  • Responsible disclosures can be sent to [email protected]; no public bounty program is claimed.
06

Auditable AI.

  • AI requests are tenant-scoped and protected by per-tenant and per-request usage limits.
  • Provider/model inventory, usage evidence, evaluations, and AI incident records are available to platform governance.
  • Human approval remains authoritative for decision execution.
  • Provider retention and training terms are governed by the selected provider contract and must be reviewed before launch.
Architecture

Tenant model.

A shared application with enforced tenant scoping; no physical-isolation claim is made.

Edge & ingress
FrontendVercel-hosted Next.js
APIRender-hosted FastAPI
TransportHTTPS provider edge
AuthSupabase JWT
↓ authenticated request ↓
Application tier
Tenant contextOrganization-scoped access
API gatewayRBAC, rate limit, audit
Workflow engineDecisions & approvals
AI gatewayQuota + provider evidence
↓ tenant-scoped persistence ↓
Data tier
PostgreSQLManaged, tenant-scoped rows
RedisQueue and worker heartbeat
Secret columnsAES-256-GCM
BackupsDaily; restore rehearsed
Reliability

Reliability targets.

Our production service-level objectives and disaster-recovery design. A live status portal with measured history is on the roadmap.

99.9%
Production uptime target (SLO)
24 hr
Current RPO target with daily backups
4 hr
Current managed-restore RTO target
Pending
Hosted alert-delivery proof
Subprocessors

Who touches what.

The launch configuration and optional providers evidenced by the application. Final contractual notice periods and regions are confirmed in the executed customer agreement.

SubprocessorPurposeRegionCustomer data?
RenderAPI/worker hosting, managed PostgreSQL, RedisUS (Oregon launch configuration)Application and account data
VercelFrontend hosting and edge deliveryProvider networkRequest metadata; public application assets
SupabaseAuthentication and isolated hosted identity servicesConfigured project regionIdentity and session metadata
StripePayment processing (PCI tokenization)US, EUBilling only
SentryOptional error monitoring and release healthConfigured Sentry regionRedacted error and trace telemetry
Twilio SendGridTransactional account emailProvider regionRecipient address and message content
Customer-selected AI providerAnthropic, OpenAI, or DeepSeek inference when enabledPer provider contractPrompt context and generated response
Configured customer connectorsSmartsheet import or Slack alert delivery when enabled; other providers require separate scope confirmationPer connected providerOnly data needed for the configured action

Last reviewed July 2026. Confirm enabled providers and regions during contracting; optional connectors process data only when a customer enables them.

Procurement & InfoSec pack

Current evidence, without fictional completion claims.

Implemented technical evidence is available for review. Legal templates and industry questionnaires remain drafts until counsel and the responsible owner approve them.

Request the pack

WHAT IS INCLUDED

  • WEBCurrent subprocessor registerPublished below
  • MDArchitecture and data-flow overviewReview draft
  • MDIncident response and observability summaryImplemented
  • MDBackup, restore, and rollback summaryRehearsed
  • MDAI governance control overviewImplemented
  • DRAFTDPA and SCC termsLegal review required
  • PLANSIG Lite and CAIQ responsesNot yet completed
  • EMAILResponsible disclosure contact[email protected]
Privacy & responsible disclosure

The other half of trust.

Customer data ownership

Customer data remains customer-owned under the Terms. Export, deletion, and AI-provider data-use commitments are finalized during legal and operational review rather than implied here.

Data residency

The launch configuration documents its actual hosting regions. EU, UK, APAC, or customer-selected residency is not promised until that deployment is contracted and verified.

DSR & deletion

Privacy requests are accepted through the published privacy contact. Self-service deletion/export and response-time commitments are not claimed until the workflow and legal policy are approved.

Responsible disclosure

Security reports can be sent to [email protected]. A public bounty program, payout schedule, and external triage SLA are not currently offered.

Responsible AI use

Pulse AI records provider/model usage, evaluations, incidents, and human authority. Provider data-use terms remain part of launch and contract review.

Incident communication

The incident runbook defines severity, ownership, containment, and evidence. A public status portal and contractual notification timelines remain launch decisions.

For procurement & InfoSec

Need the doc pack now?

Drop a line and we will send the reviewed materials currently available, clearly identifying any legal template or questionnaire that remains in draft.

Request the pack
For security researchers

Found something?

Email [email protected] with a concise description, affected URL, reproduction steps, and impact. Do not include customer data or secret material. A public bounty program and encrypted PGP channel are not currently offered.

Email security team