Security, stated plainly

What we encrypt, where your data lives, who can reach it, and which certifications we hold today rather than intend to. The rows that say no are the point.

Certifications and compliance

The full list, including the ones we do not hold. Each row says what the standard actually covers, because a badge with no explanation is decoration.

  • GDPR

    In progressUnder way, not finished

    The UK and EU regime covering how personal data is collected, stored, and deleted. Candidate data is personal data, so this is the one that governs day-to-day use of an ATS. Our data lives in the EU, deletion and export are built in, and the formal documentation set is being completed.

  • SOC 2 Type II

    PlannedIntended, not started

    A US audit of security controls observed over a period of months, commonly requested by enterprise buyers. Not started. It requires an observation window, so the earliest honest date is well after the founding pilot.

  • ISO 27001

    PlannedIntended, not started

    An international standard for running an information security management system. Not started, and sequenced after SOC 2 because the underlying controls overlap heavily.

  • HIPAA

    Not pursuedA deliberate decision not to

    The US regime for protected health information. Pulse is not built for healthcare records and we do not accept them, so pursuing this would imply a use we do not support.

Every status on this list is the real one. A certification we do not hold is not listed as held, and we do not describe ourselves as aligned with a standard we have not been audited against.

How your data is handled

Encryption

In transit
Every connection to Pulse runs over TLS 1.2 or better. There is no unencrypted route into the product.
At rest
Data at rest is encrypted with AES-256 by our database and storage provider, including automated backups.
Keys and secrets
API keys and integration credentials are encrypted before they are stored and are never sent to the browser.

Where your data lives

Regioneu-west-2 (London)

Your workspace data is stored and processed in the United Kingdom, in a dedicated database project. We do not offer a choice of region today, so if your policy requires a specific one, tell us before you start a pilot rather than after.

Who can reach your data

Row level security

Access is scoped to your workspace and enforced in the database itself, not only in the application. Every table carries a row-level policy that checks workspace membership on every read and every write, so a bug in the interface cannot return another agency's records.

Internal access

Inside RecruiterGTM, production data access is limited to the engineer who maintains the platform, is used only to investigate a fault you have reported, and is not used for support browsing.

Testing and disclosure

Reporting a vulnerability

If you find a security issue in Pulse, tell us before you tell anyone else and we will work it with you.

Email operations@recruitergtm.com
Acknowledgement
We acknowledge every report within 5 business days.
Safe harbour
We will not pursue or support legal action against anyone who reports an issue in good faith, avoids privacy violations and service disruption, and gives us reasonable time to fix it before disclosing publicly.
Bounty
We do not run a paid bug bounty yet. Reports are still welcome and still get worked.

Third-party testing

We have not commissioned an independent penetration test. When we do, the date and a summary will appear here, and pilot customers under NDA will be able to request the report.

This section does not say we run regular security reviews. A reviewer reads that phrase as no, so the answer is written as no.

Incident history

No incidents recorded

Nothing has been recorded against Pulse Recruit since the service opened on 2 August 2026. The live log is on the status page, and anything we record appears there first.

Run your security review against the real thing.

Start a pilot on your own pipeline. If your policy needs something this page does not cover, tell us before you start rather than after.