<DEV>

The platform

In the platformAPI & MCPAutomationsSecurity
Security

Enterprise security built
for institutional trust

Pulse Intelligence is built on the security foundations that institutional investors demand. From encryption to access control, every layer is designed to protect your intelligence workflow.

Security foundations

Built for the most security-conscious clients in finance

Every control has been chosen for the compliance requirements of institutional investment teams.

End-to-end encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Your intelligence stays yours. No exceptions.

Granular access control

Multi-factor authentication, role-based permissions, and organisation-level admin give your team full control over who sees what.

Customer data isolation

Private data (portfolios, uploads, and saved work) is scoped to your organisation. Private-data deployments run on dedicated database instances.

EU-hosted infrastructure

Continuous infrastructure monitoring and alerting on AWS in the EU (Stockholm), with databases held in private subnets and no public network access.

How we treat data

Two layers, two rules

We keep your confidential data completely separate from the anonymised signals that help Pulse improve. The two never mix.

Your private layer

Your data. Your boundary.

Everything you put in, and everything we produce from it, is encrypted, isolated and opt-in. No commingling, no cross-client exposure, no monetisation. Your confidential project data, including proprietary geological data, is never used to train shared models.

Rule: it stays yours, and it stays private.

The shared layer

What makes Pulse sharper for everyone.

Pulse improves over time from validated public records and anonymised, aggregated usage signals, how the platform, Ask Pulse and the MCP are used, none of which can be attributed to you or any individual. This is what keeps the intelligence layer current for every client.

Rule: only anonymised, aggregated, non-attributable.

Access paths

Three ways to use Pulse, each secured for enterprise

Choose the integration that fits your AI policy. Every path is read-only from your side and leaves your systems untouched.

Platform

The Pulse platform

The zero-integration option, sign in and work in Pulse, with embedded AI and voice.

Secured by: RBAC, MFA, SSO (SAML/OIDC), dedicated per-client environment.

Direct API

The Pulse API

Client-initiated request/response with no inbound path. Live in production, read endpoints behind org-scoped API keys with per-key quotas.

Secured by: you initiate every call and validate every response. More on the Pulse API page.

MCP

The Pulse MCP

The power-user path, query Pulse in natural language from your own Claude or AI tooling, with citations to the source page.

Secured by: read-only by design and enforcement; one-directional; OAuth 2.1; gateway and proxy friendly.

Where Pulse runs

Three deployment models, including fully on your infrastructure

Choose the boundary that suits your security posture. Migration between models is supported, so the choice is never permanent.

Model A

Pulse hosted

We host and manage everything on isolated, dedicated Pulse infrastructure. You access it by web app and API; we handle updates, scaling, monitoring and backups.

Model B

Your cloud, Pulse managed

You provide your own cloud account and keys; we deploy and configure the full stack inside it. You own all infrastructure and data from day one, and can revoke our access at any time.

Model C

Your cloud, you control

We deliver pre-built application images and deployment templates. You run Pulse independently with your own LLM keys, and keep operating even if Pulse ever discontinues.

Data protection

Encryption is applied at every layer: storage, backups, and the wire. Your proprietary research and portfolio data never leaves our environment unprotected.

AES-256 encryption for all data at rest

TLS 1.2 or higher for all data in transit

Encrypted database backups with point-in-time recovery

Your data is never used to train AI models

Secure deletion of customer data on request


Identity and access

Your IT and security teams remain in full control. Enforce MFA, manage permissions down to the individual user, and review active sessions and devices at any time.

Multi-factor authentication (TOTP) available on all accounts

Role-based access control with organisation-level admin

Granular user permission management

Active session management and device tracking


Infrastructure and operations

Our infrastructure is designed with defence-in-depth: multiple independent controls at each layer so no single failure exposes your data.

AWS cloud infrastructure with EU primary region (Stockholm)

Databases in private subnets with no public network access

Automated dependency monitoring and patching

Infrastructure managed as code, with every change peer-reviewed

Continuous infrastructure monitoring and alerting

For your security team

The rest of the detail

The rest of what a vendor security review asks for: where data sits, where inference runs, how the API and MCP are locked down, and what happens when you leave.

Data residency and where inference runs

Data at rest is in the EU (AWS, Stockholm) by default; any AWS region or client-hosted deployment is available. Inference depends on the path you use:

  • MCP: Pulse performs no inference at all, model reasoning happens in your own Claude environment, in whatever region your Anthropic agreement provides.
  • Embedded chat and voice: inference on Anthropic’s API in the US; speech services also US-hosted.
  • Internal pipelines: document extraction on Google Vertex AI’s global endpoint; PDF OCR on Mistral’s EU platform.
  • Specific data-residence requirements can be discussed per client.

AI governance and the two-layer model

Pulse builds proprietary extraction and processing pipelines with integrated LLM capabilities, and keeps the AI inside your boundary.

  • Your confidential project data is never used to train, fine-tune or improve any model.
  • LLM calls are stateless; providers’ enterprise API terms prohibit retention of, or training on, API inputs.
  • You can supply your own API keys (Deployment Models B and C).
  • Pulse does get sharper over time, from validated public data and anonymised, aggregated usage signals, never from your confidential data.

MCP and API security

Both external access paths are read-only and one-directional, your AI asks, Pulse answers. Pulse holds no client data via the MCP and performs no inference on the MCP path.

  • Read-only by design and enforcement: query tools only (search, dossiers, structured lookups); SELECT-only database roles; every query in a read-only transaction; no standing database credentials on the MCP server.
  • No capability to create, edit, delete or publish anything, and no access of any kind to your systems.
  • Tool-call requests (query text and parameters) are logged for reliability and abuse prevention; query results are not logged, and logs are automatically purged after 90 days.
  • Pulse never sees your chat: MCP conversations stay inside your own AI environment, under your enterprise terms.
  • Standard MCP HTTP transport with OAuth 2.1, designed for gateway and proxy deployments; the Pulse API offers a no-inbound-path alternative behind org-scoped keys.

Monitoring and incident response

  • Full observability stack: Prometheus, Grafana, Loki and CloudWatch, with client-facing dashboards available.
  • Automated alerting on anomalies and thresholds; CI/CD-only deployment with signed images and no manual production changes.
  • P1 (security breach or data loss): response within 3 hours, client notification within 8 hours.
  • Automated dependency monitoring and patching, with every infrastructure change peer-reviewed before it ships.
  • Post-incident review for all P1 and P2 incidents.

Resilience and recovery

  • Automated daily backups with configurable retention, encrypted at rest, with point-in-time recovery.
  • RPO 24 hours, RTO 4 hours, with a lower RPO available on request.
  • Full environment recoverable from code and snapshots; disaster-recovery testing annually.

Data portability and exit

  • Full database export at any time in standard PostgreSQL format; all documents and processed outputs (OCR text, results, embeddings) exportable.
  • Data stored in open formats, no proprietary encoding, no lock-in.
  • On exit: full export, deletion from Pulse infrastructure, credential revocation, and formal deletion certification on request.

“Your data, your encryption boundary, your own database.” That is how every client environment is provisioned, not a premium add-on, but the default.

From the Pulse Data Security, Ownership & Infrastructure Trust Framework.

Compliance

Certification in process, not in principle

Both audits are underway rather than planned. SOC 2 Type II and ISO 27001 are being certified against the same control set, with reports expected in Q1 2027.

In process · Q1 2027

SOC 2 Type II

In process now, with the report expected Q1 2027. Scope includes Processing Integrity, not only Security.

In process · Q1 2027

ISO 27001

In process now on the same control set as SOC 2, certification expected Q1 2027.

Aligned

GDPR

Already GDPR-aligned on data sovereignty, right to export and right to deletion. A DPA is available on request.

In place

AWS Well-Architected

Infrastructure built and reviewed against AWS best practice today.

Continuous monitoring, not a point-in-time audit

From Q1 2027, control status will be monitored continuously rather than sampled at audit time, and shared with clients directly, so compliance is something you can check instead of a certificate you file. Until then, the Trust Framework sets out every control in the programme, and we answer your security team’s questionnaire directly.

Request the Trust FrameworkRequest a DPA

Questions about our security posture?

We understand that security diligence is a critical part of procurement. Our team is available to answer questions, provide documentation, and work through your organisation's specific requirements.


Company information

FeaturesAPIInsightsSecurityPrivacy Policy & Terms of Use

Contact us

Email us

Request access

We’re global

Working hours

Click to email usBook a time here

London & beyond

Mon–Fri, 10:00–19:00 (UK time)


Pulse Intelligence © 2026. All rights reserved.

LinkedIn