How we protect your account, data, and payments at PulseBot. This page describes our controls today — it is not an independent certification.
Account & Authentication
Email + password and OAuth (Google, Apple) sign-in.
Email verification required for new accounts before checkout.
Sessions use short-lived access tokens with rotating refresh tokens.
Passwords are hashed by our managed auth provider; we never see them.
Data Storage & Access
Customer data is stored in a managed PostgreSQL database hosted in the EU.
Row-Level Security (RLS) is enabled on every user-facing table.
Privileged operations run server-side with scoped service credentials.
Admin actions are gated by a dedicated role table, not flags on the user record.
Encryption & Transport
TLS 1.2+ enforced on all traffic to www.33pulse.com.
At-rest encryption on the database and object storage layer.
Secrets are stored in the platform secret manager — never in source.
Payments
Card payments are processed by our PSP; we never store card numbers.
Crypto payments are processed via NOWPayments with signed IPN webhooks.
Webhook payloads are verified by HMAC signature before any state change.
Email & Communications
Transactional email is sent from an authenticated domain (SPF, DKIM, DMARC).
Every marketing email contains a one-click unsubscribe link.
Unsubscribed addresses are added to a suppression list and excluded from sends.
Privacy & Your Rights
We collect only the data needed to operate your account, deliver the product, and meet legal obligations. You can request export or deletion of your data at any time by emailing support@33pulse.com.
If you believe you have found a security issue, please email security@33pulse.com with a description and reproduction steps. We will acknowledge within 72 hours.
This page describes controls we operate today. It is editable project content and not an independent audit or certification.