Security
Last updated: July 2026
Pulse holds credentials for the advertising, analytics and commerce accounts you connect, and the reporting data pulled from them. This page describes the controls that protect them. It covers how the product actually works today — where something is on the roadmap rather than in place, it says so.
Connecting an account
Connectors are authorized through each provider’s own flow, and Pulse requests the minimum scopes needed for reporting — read-only wherever the provider offers a read-only scope. Pulse does not create, edit or delete data in your connected accounts through those scopes, except where you explicitly use a publishing feature you initiate yourself.
Credential storage
Access tokens and API credentials are encrypted at rest and never returned to the browser after they are saved. Disconnecting a connector deletes the stored credential along with that connector’s cached data.
Tenant isolation
Every row of reporting data is scoped to one client, and every request is filtered by the set of clients the signed-in user may access. A branch — a market or region within a client — is scoped the same way, so a report for one market cannot read another’s rows.
Access control
Roles are configurable, with granular permissions per client. An analyst assigned to three clients sees only those three; the platform surfaces nothing outside the assignment. User assignment and role changes are made by an owner or admin of the workspace.
Sessions and API access
Sign-in issues a short-lived access token alongside a refresh token that is rotated on every use, so a captured refresh token cannot be replayed. Programmatic access uses separate API keys, which can be issued company-wide or scoped to a single client, and can be rotated or revoked independently without disturbing anyone’s session.
Sub-processors
Pulse runs on secured infrastructure and may use sub-processors — hosting, for example — that process data on our behalf under confidentiality obligations. We do not sell data, and we do not use connected-account data to train generalized AI/ML models.
Reporting a vulnerability
If you believe you have found a security issue, please email [email protected] with the subject line “Security”. Please give us a reasonable window to investigate and fix before disclosing publicly.
Certifications
Pulse does not currently hold a SOC 2 or ISO 27001 attestation. If your procurement process needs one, email [email protected] and we will tell you where that stands.