Trust & Security at LicensePulse
LicensePulse helps engineering and IT teams understand their software license usage. That means we receive sensitive operational data — license logs, seat counts, contract details. We take that responsibility seriously. This page is the one-stop summary of how we protect your data.
Last updated: July 31, 2026
1. What data we receive
| Category | Examples | How it gets to us |
|---|---|---|
| Account data | Your name, work email, company name | When you sign up |
| License usage data | Daily counts of seats in use, peak concurrency, denial events, usernames | Smart Upload (file drop), OAuth integrations (M365, Salesforce, Jira, GitHub, Slack, Google Workspace), or our on-prem agent |
| Contract metadata | Vendor names, renewal dates, costs, contract documents you upload | You enter or upload it |
| Telemetry | Page views, funnel events, error stacks — first-party only, stored in our own database. No third-party analytics or error-monitoring service. | Automatic |
We do not receive your source code, your engineering models, your project files, or anything outside what your license daemon emits.
2. Where data lives
- Application runs on Render.com (US data center, Oregon region)
- Database is PostgreSQL, hosted by Render, encrypted at rest by default
- Customer-uploaded contract documents are stored as binary blobs inside the same Postgres instance
- AI-assisted file classification sends file metadata + small content samples to Anthropic (model: Claude). Anthropic does not train on your data.
- No data leaves these providers. No third-party analytics, no ad networks, no AWS or self-hosted machines outside Render.
3. Encryption
- In transit: TLS 1.2+ on every endpoint (
https://app.licensepulse.app,https://licensepulse.app, agent ↔ API). HTTPS-only — no plaintext fallback. - At rest: AES-256 on the Postgres volume (Render-provided).
- API keys for the on-prem agent are stored as SHA-256 hashes — even we cannot recover the plaintext.
- Passwords are hashed with bcrypt.
4. Access controls
- Authentication — email + password, JWT-based session tokens. SSO (SAML/OIDC) on the roadmap.
- Authorization — role-based: Owner, Admin, Viewer. Multi-tenant isolation by
org_idon every query — there is no shared dataset. - Internal access — production access is held by the smallest number of operators the service can run with, under least privilege. There is no shared administrative account and no support back door. Every access is logged.
- API keys are scoped to a single organization, can be revoked instantly, and are never shown twice (only on creation).
5. Sub-processors
We use a small set of vendors. The full list with locations and purposes is at https://licensepulse.app/subprocessors. Summary:
- Render (USA) — hosting + Postgres
- Anthropic (USA) — AI classification of uploaded files
- Stripe (USA) — payments (we never see card numbers)
- Slack / Microsoft / Google / Atlassian / Salesforce / GitHub — only when you connect them via OAuth, and only the scopes you authorize
6. Incident response
- We follow a documented incident-response playbook with defined severity levels.
- Affected customers are notified within 72 hours of confirmed incident discovery (GDPR-aligned, faster than CCPA's "without unreasonable delay").
- Notification channels: email to the primary contact + status banner in-app.
- A post-mortem with root cause and remediation plan is shared within 14 days.
Report a vulnerability to security@licensepulse.app. We do not yet run a paid bug-bounty program but we do publicly credit responsible disclosure and respond within 5 business days.
7. Backups & disaster recovery
- Daily automated backups of the Postgres database, retained 7 days.
- Point-in-time recovery within the last 24 hours.
- Restore drills quarterly from launch. A backup is not a backup until the data has been watched coming back; we do not claim a drill history we do not have.
- RTO (recovery time objective): 4 hours.
- RPO (recovery point objective): 24 hours.
8. Compliance posture
| Standard | Status |
|---|---|
| GDPR | ✅ Compliant — DPA available, EU SCCs incorporated, no transfers outside US/EU adequacy |
| CCPA / CPRA | ✅ Compliant — disclosures in Privacy Policy, request handling within 45 days |
| SOC 2 Type 1 | Planned — not certified. The controls an audit examines are built and running. We begin the audit when a customer requires it. |
| ISO 27001 | Not yet pursued |
| HIPAA / PHI | Not in scope — do not upload Protected Health Information |
| FedRAMP | Not in scope |
9. Your rights & how to reach us
- Data subject requests (GDPR Articles 15–22, CCPA equivalent): email privacy@licensepulse.app
- Security disclosures: security@licensepulse.app
- Legal notices: legal@licensepulse.app
- General inquiries: support@licensepulse.app
10. Changes to this page
When the underlying practice changes, we update this page and update the "Last updated" date. Material changes are also announced by email.
Meridian Vertex LLC, doing business as LicensePulse 817 S MacArthur Blvd, Ste 115 #1040, Coppell, TX 75019, USA https://licensepulse.app