Built for teams that take security seriously
This page is maintained by the WorkPulse team to answer common security and privacy questions about the platform. It describes controls that are enabled today and how responsibility is shared between WorkPulse, your organization, and your users.
Isolated by design
Every company workspace is scoped by row-level security policies, so data from one organization is never visible to another.
Encrypted at rest & in transit
Traffic uses HTTPS/TLS and the managed database encrypts data at rest. Secrets are stored in the platform vault, never in code.
Auditable by admins
Sensitive actions such as role grants, approvals, and company changes are recorded to a tamper-evident audit log admins can review.
What's in place today
Every WorkPulse workspace ships with these controls enabled by default.
Email & password, Google, and Apple sign-in — with optional leaked-password protection.
Super admin, admin, manager, and employee roles decide what each user can see and do.
Postgres RLS policies enforce data isolation at the database layer, not just in the app.
The managed database platform runs automated backups so recovery is not left to app code.
Role changes, company creation, approval decisions and notifications are recorded with actor, entity, and timestamp.
Sensitive operations run through security-definer functions with a locked search_path, not broad GRANTs.
Who is responsible for what
- • Application hosting & runtime
- • Encrypted managed database
- • Row-level security enforcement
- • Authentication infrastructure
- • Automated backups
- • Managing roles & permissions
- • Reviewing the audit log
- • Data classification & retention decisions
- • Employee onboarding & offboarding
- • Internal security policies
- • Choosing strong passwords
- • Keeping credentials confidential
- • Reporting suspicious activity
- • Signing out of shared devices
Frequently asked
Where is my data stored?
WorkPulse runs on a managed Postgres database provided by the underlying cloud platform. Each customer workspace is logically isolated through row-level security. Storage location and retention specifics for your workspace can be confirmed with your workspace administrator.
Can WorkPulse staff read my data?
Application access is scoped by RLS, so ordinary application paths cannot read other customers' data. Platform maintenance may require privileged database access for a strictly limited set of operators, subject to internal policy.
How do you handle authentication?
Sign-in uses the managed authentication service with email & password, Google, and Apple. Sessions are HTTP-only. Optional leaked-password protection can be enabled by the platform administrator.
Is there an audit trail?
Yes. Role grants and revocations, company creation, approval decisions and notifications are recorded in an internal audit log that company admins can review from Trust & Security in their workspace.
Do you claim SOC 2, ISO 27001, or HIPAA compliance?
This page does not make regulatory or certification claims. If your organization needs a specific compliance statement, please contact your account owner so we can share the correct, approved wording rather than approximations.
How do I export or delete my data?
Company administrators can export data from the Reports and Files sections. To request account deletion or a workspace export, contact your workspace admin, who can raise a request through their platform account.
Have a security question?
Reach out to your workspace administrator, or contact the WorkPulse team through your account channels. This page is not a certification and does not constitute a legal audit statement.
Sign in to your workspace