01SECURITY

How we protect your employee data.

HRPulsar stores HR-grade personal data: org charts, performance history, assessment results. The same controls that are non-negotiable for that kind of data are non-negotiable for us. This page is what we already do and what we are working toward.

This page covers how the data is protected. What we collect in the first place — and what we refuse to collect — is on What we measure, and what we never touch.

Last updated: May 13, 2026

Draft · pending US legal review

This page describes our current security practices and roadmap. The page itself is a draft — the underlying practices are implemented, but the wording has not yet been reviewed by US privacy or corporate counsel. Anything material to a vendor security review should be confirmed against the working version by emailing security@hrpulsar.com.

02WHAT WE DO TODAY

Practices in place across HRPulsar Cloud.Draft · pending US legal review

Encryption

Data in transit and at rest is encrypted by default.

All traffic to the HRPulsar Cloud is served over TLS 1.2+ with HSTS. Customer data, file attachments, and database backups are encrypted at rest using AES-256 (managed Postgres and Cloudflare R2 object storage). Secrets, API keys, and webhook signing keys are stored in a dedicated secrets store with per-environment rotation.

Access controls

Least privilege, MFA, audit trail.

Production access is limited to a named subset of engineers. SSH and admin consoles require hardware-backed MFA. Every privileged action against production is logged and reviewable. Customer workspaces are tenant-isolated at the database level.

Backups & disaster recovery

Daily encrypted backups, multi-region object storage.

Postgres is backed up daily with point-in-time recovery within a 7-day window. File attachments live in Cloudflare R2 with multi-region replication. Our target recovery objectives are RPO ≤ 24 hours and RTO ≤ 4 hours for the Cloud tier. We test restores quarterly.

Incident response

Owned by engineering, communicated within 72 hours.

Security incidents are triaged by the on-call engineer, contained, and post-mortemed. Confirmed breaches affecting customer personal data are disclosed to affected workspaces within 72 hours, in line with GDPR Article 33 expectations. Post-mortems for material incidents are published on the changelog.

Vendor & AI governance

Sub-processors are listed and reviewed.

Customer data is processed only by a small, named set of sub-processors (the full list will be published in the Privacy Policy before Cloud billing launches; we share the current working list on request to security@hrpulsar.com). AI model providers used by Cloud workspaces are configured to not train on customer prompts or outputs. We track the EU AI Act vendor obligations and will publish our conformity statement before the act's general application date.

Application security

Reviewed code, automated tests, dependency scanning.

Every change to production code goes through review, automated tests, and static analysis. Dependencies are pinned and scanned for known CVEs on each build. We run an internal security review on each release and accept responsible disclosures at security@hrpulsar.com.

03ROADMAP

Certifications and programmes we are working toward.Draft · pending US legal review

We do not display a SOC 2 badge today because we are not certified today. Below is the actual timeline. If a procurement team needs a specific certification on a specific date, write to security@hrpulsar.com and we will tell you whether we can commit.

04CONTACT

Reporting a vulnerability or a procurement question.Draft · pending US legal review