New · Launch pricingHome →
Enterprise Security & Trust

Built for privacy. Engineered for trust.

How PulseROI protects your research data, ensures Mumbai data residency, prevents AI model training on your inputs, and implements defense-in-depth architecture.

🇮🇳

Mumbai Data Residency

All primary databases and object storage reside in Supabase's South Asia region (AWS ap-south-1 Mumbai). Your creator lists and brand profiles never leave Indian territory for storage.

🔒

Zero AI Training on Your Data

We use commercial API inference endpoints exclusively. Providers (Groq, Mistral, Cerebras, Google) process requests ephemerally and are contractually prohibited from training on your queries.

🛡️

Row-Level Security (RLS)

PostgreSQL Row-Level Security policies are strictly enforced on all database tables. It is mathematically impossible for one authenticated tenant to access or view another user's reports.

1. Infrastructure & Hosting Certifications

PulseROI is hosted on modern cloud infrastructure where our upstream providers maintain rigorous global compliance certifications:

Database & Auth (Supabase / AWS ap-south-1): SOC 2 Type II certified, ISO/IEC 27001 compliant, with AES-256 encryption at rest.
Edge & Compute (Vercel Inc.): SOC 2 Type II certified, TLS 1.3 encryption in transit with automated HSTS enforcement.
Payment Gateway (Razorpay): PCI-DSS Level 1 certified. PulseROI never sees or stores card details, CVVs, or UPI PINs.

2. Data Protection & Indian DPDP Compliance

We operate under the framework of India's Digital Personal Data Protection (DPDP) Act, 2023:

  • Data Minimization: We collect only your email, display name, and creator research inputs necessary to deliver the analysis.
  • Right to Complete Erasure: One-click account and data purge available in Settings → Data & Privacy.
  • No Third-Party Analytics Trackers: We do not load Google Analytics, Meta Pixel, Hotjar, or advertising tracking scripts.
  • 72-Hour Breach Notification: We commit to notifying affected users and the Data Protection Board of India within 72 hours of identifying any verified security incident.

3. Responsible Disclosure & Bug Bounty

I believe in radical transparency and welcome reports from ethical security researchers. If you discover a vulnerability or security flaw in PulseROI:

Subject: "Security Vulnerability Report"

Please include reproducible steps and allow 48 hours for a direct founder response before public disclosure. Valid, responsible vulnerability reports receive acknowledgment and public credit.

Questions about our security posture?

I personally answer all enterprise security questionnaires and technical inquiries.