What PulseTrace stores, how it is protected, who can reach it, and how to tell us if you find something. Written to answer the questions a security questionnaire asks — plainly, and only about what is actually built.
httpOnly, SameSite=Strict cookies with double-submit CSRF protection and both idle and absolute expiry.CAP_NET_RAW as a file capability, never root.If you believe you have found a vulnerability in PulseTrace, email security@pulsetrace.app with the steps to reproduce. We acknowledge reports within two business days, keep you informed while we fix, and credit you if you wish. Please do not run automated scanners against the hosted service at volume, access data that is not yours, or disrupt other customers; the free tools under /tools are the right place to test a target of your own.
PulseTrace does not currently hold a SOC 2 report or ISO 27001 certification, and does not claim to. The controls above are what is built; we would rather describe them precisely than borrow a badge. Customers on Enterprise can request a data-processing agreement and a security review call.
Retention details →The SSL/TLS Security monitor applies this same scrutiny to your sites — A+ to F, with every finding listed.