Trust Centre
Security, compliance, and transparency at PolicyPulse
Security
Infrastructure Security
Data Encryption
All data transmitted via TLS 1.3 and encrypted at rest using AES-256
Database Security
PostgreSQL databases with row-level security, regular automated backups
Network Security
DDoS protection, WAF, and AWS infrastructure security
Access Control
Multi-factor authentication, role-based access control, regular access reviews
Application Security
Code Security
Secure coding practices, code review, OWASP compliance
Vulnerability Management
Regular security audits, penetration testing, bug bounty program
Dependency Management
Automated scanning for vulnerable dependencies, regular updates
Incident Response
24/7 security monitoring, incident response plan, breach notification
Security Reporting: If you discover a security vulnerability, please email security@policypulse.fun with details. We take security seriously and will investigate all reports promptly.
Privacy
Privacy Policy
Comprehensive details on how we collect, use, and protect your personal information.
Read Policy →Data Processing
Information about our data processing practices and GDPR/Privacy Act compliance.
View DPA →Data Rights
Your rights regarding your personal data including access, correction, and deletion.
Manage Rights →Privacy Principles
Data Minimization
We collect only the data necessary to provide our service
Security
Your data is protected with industry-leading encryption
Transparency
We're clear about how we use data and who has access
Control
You control your data and can export or delete it anytime
Compliance & Certifications
Australian Privacy Act
PolicyPulse complies with the Privacy Act 1988 (Cth) and Australian Privacy Principles in all data handling.
GDPR Compliant
We comply with the General Data Protection Regulation (EU) 2016/679 for personal data of EU residents.
SOC 2 Type II
In Progress: We are working toward SOC 2 Type II certification to demonstrate our commitment to security controls. Expected completion: Q3 2026.
ISO 27001
Planned: ISO 27001 certification is on our roadmap for 2027 to provide additional assurance on our information security management.
Note on Certifications: PolicyPulse does not claim to be legally certified or to provide compliance guarantees. Our educational content and tools are designed to help organizations understand and track their compliance obligations. Organizations remain responsible for their own legal compliance. Always consult qualified legal professionals for matters affecting your specific circumstances.
System Status
99.95%
Average uptime (last 30 days)
API Status
Real-Time Monitoring
View detailed system status, incident history, and planned maintenance.
View Status Page →Incident History
No major incidents in the last 90 days. Visit status page for complete incident history.
Subprocessors & Third Parties
PolicyPulse uses the following third-party services to provide our platform. We maintain data processing agreements with all subprocessors.
| Provider | Service | Data Processed | Location |
|---|---|---|---|
| Supabase | Database & Authentication | Application data, user credentials | AWS (AU) |
| Stripe | Payment Processing | Payment information (PCI-DSS) | Global |
| SendGrid | Email Service | Email addresses, message content | Global |
| Vercel | CDN & Hosting | Static assets, performance data | Global |
| Google Analytics | Analytics | Anonymized usage data | Global |
| AWS | Infrastructure | All platform data | Australia (Sydney) |
Data Processing Agreements: All subprocessors have signed Data Processing Agreements (DPA) requiring them to comply with applicable privacy and data protection laws. We can provide copies of DPAs to enterprise customers upon request.
Security & Compliance Contact
Security Incidents
security@policypulse.fun
Privacy Requests
privacy@policypulse.fun
Compliance & Certifications
compliance@policypulse.fun
General Contact
hello@policypulse.fun
All security and compliance inquiries will be responded to within 24 business hours.