Security, stated plainly
What we encrypt, where your data lives, who can reach it, and which certifications we hold today rather than intend to. The rows that say no are the point.
Certifications and compliance
The full list, including the ones we do not hold. Each row says what the standard actually covers, because a badge with no explanation is decoration.
GDPR
In progressUnder way, not finishedThe UK and EU regime covering how personal data is collected, stored, and deleted. Candidate data is personal data, so this is the one that governs day-to-day use of an ATS. Our data lives in the EU, deletion and export are built in, and the formal documentation set is being completed.
SOC 2 Type II
PlannedIntended, not startedA US audit of security controls observed over a period of months, commonly requested by enterprise buyers. Not started. It requires an observation window, so the earliest honest date is well after the founding pilot.
ISO 27001
PlannedIntended, not startedAn international standard for running an information security management system. Not started, and sequenced after SOC 2 because the underlying controls overlap heavily.
HIPAA
Not pursuedA deliberate decision not toThe US regime for protected health information. Pulse is not built for healthcare records and we do not accept them, so pursuing this would imply a use we do not support.
Every status on this list is the real one. A certification we do not hold is not listed as held, and we do not describe ourselves as aligned with a standard we have not been audited against.
How your data is handled
Encryption
- In transit
- Every connection to Pulse runs over TLS 1.2 or better. There is no unencrypted route into the product.
- At rest
- Data at rest is encrypted with AES-256 by our database and storage provider, including automated backups.
- Keys and secrets
- API keys and integration credentials are encrypted before they are stored and are never sent to the browser.
Where your data lives
Your workspace data is stored and processed in the United Kingdom, in a dedicated database project. We do not offer a choice of region today, so if your policy requires a specific one, tell us before you start a pilot rather than after.
Who can reach your data
Row level security
Access is scoped to your workspace and enforced in the database itself, not only in the application. Every table carries a row-level policy that checks workspace membership on every read and every write, so a bug in the interface cannot return another agency's records.
Internal access
Inside RecruiterGTM, production data access is limited to the engineer who maintains the platform, is used only to investigate a fault you have reported, and is not used for support browsing.
Testing and disclosure
Reporting a vulnerability
If you find a security issue in Pulse, tell us before you tell anyone else and we will work it with you.
Email operations@recruitergtm.com- Acknowledgement
- We acknowledge every report within 5 business days.
- Safe harbour
- We will not pursue or support legal action against anyone who reports an issue in good faith, avoids privacy violations and service disruption, and gives us reasonable time to fix it before disclosing publicly.
- Bounty
- We do not run a paid bug bounty yet. Reports are still welcome and still get worked.
Third-party testing
We have not commissioned an independent penetration test. When we do, the date and a summary will appear here, and pilot customers under NDA will be able to request the report.
This section does not say we run regular security reviews. A reviewer reads that phrase as no, so the answer is written as no.
Incident history
No incidents recorded
Nothing has been recorded against Pulse Recruit since the service opened on 2 August 2026. The live log is on the status page, and anything we record appears there first.
Run your security review against the real thing.
Start a pilot on your own pipeline. If your policy needs something this page does not cover, tell us before you start rather than after.