How PulseROI protects your research data, ensures Mumbai data residency, prevents AI model training on your inputs, and implements defense-in-depth architecture.
All primary databases and object storage reside in Supabase's South Asia region (AWS ap-south-1 Mumbai). Your creator lists and brand profiles never leave Indian territory for storage.
We use commercial API inference endpoints exclusively. Providers (Groq, Mistral, Cerebras, Google) process requests ephemerally and are contractually prohibited from training on your queries.
PostgreSQL Row-Level Security policies are strictly enforced on all database tables. It is mathematically impossible for one authenticated tenant to access or view another user's reports.
PulseROI is hosted on modern cloud infrastructure where our upstream providers maintain rigorous global compliance certifications:
We operate under the framework of India's Digital Personal Data Protection (DPDP) Act, 2023:
I believe in radical transparency and welcome reports from ethical security researchers. If you discover a vulnerability or security flaw in PulseROI:
Please include reproducible steps and allow 48 hours for a direct founder response before public disclosure. Valid, responsible vulnerability reports receive acknowledgment and public credit.
I personally answer all enterprise security questionnaires and technical inquiries.