TeamPulse
Security

How we hold your data

TeamPulse holds objectives, delivery records and people data in one place, which raises the bar rather than lowering it. Here is the architecture, the certifications, and what we will not do.

Last updated
12 June 2026
Last updated

At a glance

What your security team will ask about first

SOC 2 Type II

Audited annually. Report available under NDA before you commit.

AES-256 at rest

TLS 1.3 in transit, with managed key rotation and separation of duties.

EU data residency

On any plan, plus private cloud and on-premises deployment options.

Cohort minimums

Enforced in the query, so an individual wellness report cannot be produced.

Certifications

TeamPulse is SOC 2 Type II audited annually and certified to ISO 27001. Reports are available under NDA, and we will send them before you commit to anything rather than after.

We are GDPR compliant as a processor, and act as a controller only for the account data we need to run the service. We also conform with the Kenya Data Protection Act, 2019 and are registered with the Office of the Data Protection Commissioner. A DPA is available on every plan, including the smallest.

Encryption

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Encryption keys are managed through a dedicated key management service with regular rotation and separation of duties.

Backups are encrypted with the same standard and tested by restore rather than assumed to work.

Access control

Authentication supports SAML and OIDC single sign-on with SCIM provisioning, so a leaver loses access on the day they leave rather than on the day somebody remembers.

Inside the product, permission sets govern what each role can read and write. Compensation and payroll sit behind their own model, separate from the rest of the platform.

Internally, engineer access to production is role-based, time-boxed, logged, and requires a second approver.

Data residency

Choose where your data lives, including EU-only or Kenya-resident storage on any plan. For organisations that require it, TeamPulse can be deployed into your own private cloud or on-premises.

Subprocessors are published, and we notify customers before adding one.

Privacy by design

We read metadata and survey responses. We do not read message bodies, documents, screens or keystrokes, and there is no configuration that turns that on.

Wellness risk is reported for cohorts of five or more. The minimum is enforced in the query itself rather than by policy, so a report about a named individual cannot be produced.

Every employee can see the full record held about them, and export or delete it.

Incident response

We run a 24/7 on-call rotation with a median detection time under fifteen minutes. Incidents are published to our status page as they are being worked, not after they are resolved.

Customers materially affected by a security incident are notified within 72 hours, with a written post-incident review to follow. Where the Kenya Data Protection Act, 2019 applies, we also notify the Office of the Data Protection Commissioner inside the same window.

Testing and assurance

We commission an independent penetration test annually and after any significant architectural change. Findings are remediated on a severity-based timeline and re-tested.

We operate a responsible disclosure programme. If you have found something, please write to us before publishing and we will work with you.

Questions your legal team needs answered?

We will send the DPA, subprocessor list and certifications without making you sign anything first.