Enterprise security built
for institutional trust
Pulse Intelligence is built on the security foundations that institutional investors demand. From encryption to access control, every layer is designed to protect your intelligence workflow.
Built for the most security-conscious clients in finance
End-to-end encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Your intelligence stays yours. No exceptions.
Granular access control
Multi-factor authentication, role-based permissions, and organisation-level admin give your team full control over who sees what.
Customer data isolation
Private data (portfolios, uploads, and saved work) is scoped to your organisation. Private-data deployments run on dedicated database instances.
EU-hosted infrastructure
Continuous infrastructure monitoring and alerting on AWS in the EU (Stockholm), with databases held in private subnets and no public network access.
Two layers, two rules
Your private layer
Your data. Your boundary.
Everything you put in, and everything we produce from it, is encrypted, isolated and opt-in. No commingling, no cross-client exposure, no monetisation. Your confidential project data, including proprietary geological data, is never used to train shared models.
Rule: it stays yours, and it stays private.
The shared layer
What makes Pulse sharper for everyone.
Pulse improves over time from validated public records and anonymised, aggregated usage signals, how the platform, Ask Pulse and the MCP are used, none of which can be attributed to you or any individual. This is what keeps the intelligence layer current for every client.
Rule: only anonymised, aggregated, non-attributable.
Three ways to use Pulse, each secured for enterprise
Platform
The Pulse platform
The zero-integration option, sign in and work in Pulse, with embedded AI and voice.
Secured by: RBAC, MFA, SSO (SAML/OIDC), dedicated per-client environment.
Direct API
The Pulse API
Client-initiated request/response with no inbound path. Live in production, read endpoints behind org-scoped API keys with per-key quotas.
Secured by: you initiate every call and validate every response. More on the Pulse API page.
MCP
The Pulse MCP
The power-user path, query Pulse in natural language from your own Claude or AI tooling, with citations to the source page.
Secured by: read-only by design and enforcement; one-directional; OAuth 2.1; gateway and proxy friendly.
Three deployment models, including fully on your infrastructure
Model A
Pulse hosted
We host and manage everything on isolated, dedicated Pulse infrastructure. You access it by web app and API; we handle updates, scaling, monitoring and backups.
Model B
Your cloud, Pulse managed
You provide your own cloud account and keys; we deploy and configure the full stack inside it. You own all infrastructure and data from day one, and can revoke our access at any time.
Model C
Your cloud, you control
We deliver pre-built application images and deployment templates. You run Pulse independently with your own LLM keys, and keep operating even if Pulse ever discontinues.
Data protection
Encryption is applied at every layer: storage, backups, and the wire. Your proprietary research and portfolio data never leaves our environment unprotected.
AES-256 encryption for all data at rest
TLS 1.2 or higher for all data in transit
Encrypted database backups with point-in-time recovery
Your data is never used to train AI models
Secure deletion of customer data on request
Identity and access
Your IT and security teams remain in full control. Enforce MFA, manage permissions down to the individual user, and review active sessions and devices at any time.
Multi-factor authentication (TOTP) available on all accounts
Role-based access control with organisation-level admin
Granular user permission management
Active session management and device tracking
Infrastructure and operations
Our infrastructure is designed with defence-in-depth: multiple independent controls at each layer so no single failure exposes your data.
AWS cloud infrastructure with EU primary region (Stockholm)
Databases in private subnets with no public network access
Automated dependency monitoring and patching
Infrastructure managed as code, with every change peer-reviewed
Continuous infrastructure monitoring and alerting
The rest of the detail
Data residency and where inference runs
Data at rest is in the EU (AWS, Stockholm) by default; any AWS region or client-hosted deployment is available. Inference depends on the path you use:
- MCP: Pulse performs no inference at all, model reasoning happens in your own Claude environment, in whatever region your Anthropic agreement provides.
- Embedded chat and voice: inference on Anthropic’s API in the US; speech services also US-hosted.
- Internal pipelines: document extraction on Google Vertex AI’s global endpoint; PDF OCR on Mistral’s EU platform.
- Specific data-residence requirements can be discussed per client.
AI governance and the two-layer model
Pulse builds proprietary extraction and processing pipelines with integrated LLM capabilities, and keeps the AI inside your boundary.
- Your confidential project data is never used to train, fine-tune or improve any model.
- LLM calls are stateless; providers’ enterprise API terms prohibit retention of, or training on, API inputs.
- You can supply your own API keys (Deployment Models B and C).
- Pulse does get sharper over time, from validated public data and anonymised, aggregated usage signals, never from your confidential data.
MCP and API security
Both external access paths are read-only and one-directional, your AI asks, Pulse answers. Pulse holds no client data via the MCP and performs no inference on the MCP path.
- Read-only by design and enforcement: query tools only (search, dossiers, structured lookups); SELECT-only database roles; every query in a read-only transaction; no standing database credentials on the MCP server.
- No capability to create, edit, delete or publish anything, and no access of any kind to your systems.
- Tool-call requests (query text and parameters) are logged for reliability and abuse prevention; query results are not logged, and logs are automatically purged after 90 days.
- Pulse never sees your chat: MCP conversations stay inside your own AI environment, under your enterprise terms.
- Standard MCP HTTP transport with OAuth 2.1, designed for gateway and proxy deployments; the Pulse API offers a no-inbound-path alternative behind org-scoped keys.
Monitoring and incident response
- Full observability stack: Prometheus, Grafana, Loki and CloudWatch, with client-facing dashboards available.
- Automated alerting on anomalies and thresholds; CI/CD-only deployment with signed images and no manual production changes.
- P1 (security breach or data loss): response within 3 hours, client notification within 8 hours.
- Automated dependency monitoring and patching, with every infrastructure change peer-reviewed before it ships.
- Post-incident review for all P1 and P2 incidents.
Resilience and recovery
- Automated daily backups with configurable retention, encrypted at rest, with point-in-time recovery.
- RPO 24 hours, RTO 4 hours, with a lower RPO available on request.
- Full environment recoverable from code and snapshots; disaster-recovery testing annually.
Data portability and exit
- Full database export at any time in standard PostgreSQL format; all documents and processed outputs (OCR text, results, embeddings) exportable.
- Data stored in open formats, no proprietary encoding, no lock-in.
- On exit: full export, deletion from Pulse infrastructure, credential revocation, and formal deletion certification on request.
“Your data, your encryption boundary, your own database.” That is how every client environment is provisioned, not a premium add-on, but the default.
From the Pulse Data Security, Ownership & Infrastructure Trust Framework.
Certification in process, not in principle
In process · Q1 2027
SOC 2 Type II
In process now, with the report expected Q1 2027. Scope includes Processing Integrity, not only Security.
In process · Q1 2027
ISO 27001
In process now on the same control set as SOC 2, certification expected Q1 2027.
Aligned
GDPR
Already GDPR-aligned on data sovereignty, right to export and right to deletion. A DPA is available on request.
In place
AWS Well-Architected
Infrastructure built and reviewed against AWS best practice today.
Continuous monitoring, not a point-in-time audit
From Q1 2027, control status will be monitored continuously rather than sampled at audit time, and shared with clients directly, so compliance is something you can check instead of a certificate you file. Until then, the Trust Framework sets out every control in the programme, and we answer your security team’s questionnaire directly.
Questions about our security posture?
We understand that security diligence is a critical part of procurement. Our team is available to answer questions, provide documentation, and work through your organisation's specific requirements.