Where AUMPulse stands
AUMPulse is not SOC 2 certified. We are a small company and have not completed an audit of our own. We'd rather lose a deal to that than surprise you in diligence.
- The infrastructure we run on publishes independent certifications (below).
- Our data handling is described precisely and is verifiable in the product.
- We have not announced a date for our own SOC 2 Type 2 audit.
Subprocessors
Certifications below are the vendors' published postures, not AUMPulse company certifications.
| Subprocessor | Role | Data it touches | Published posture |
|---|---|---|---|
| Recall.ai | Joins the meeting, records, transcribes | Meeting audio and transcript, transiently | SOC 2 Type 2, ISO 27001 (vendor) |
| Supabase | Application database and authentication | Prospect records, briefs, claims, contact details, pipeline data | SOC 2 Type 2, ISO 27001; AES-256 at rest, TLS in transit (vendor) |
| Anthropic | Synthesis of briefs and letter drafts | Transcript content during processing | Commercial API: inputs/outputs not used for model training (vendor terms) |
| Google / Microsoft | Calendar read and mail send, via advisor OAuth | Calendar metadata, outbound mail as the advisor | Vendor posture |
| Vercel | Application and site hosting | HTTP traffic to the app and marketing site | SOC 2 Type 2, ISO 27001 (vendor) |
| Sentry | Error monitoring | Error metadata only (no prospect content, no request bodies) | Vendor posture |
The Anthropic row is where call content leaves your control during processing. We do not submit product feedback that would change Anthropic's default no-training terms for API traffic.
What is stored, and for how long
Not retained on AUMPulse
| Artifact | Lifetime |
|---|---|
| Meeting audio | Held by Recall.ai. Deleted after synthesis succeeds. Timed floor of 24 hours if delete is missed. |
| Transcript | Read in memory during processing. Not written to AUMPulse storage. |
| Letter subject and body | Cleared from our database when you send, discard, or mark sent. |
| Evidence quotes behind commitments | Cleared with the letter. Abandoned unsent quotes may also be stripped after 72 hours. |
Retained until you delete the prospect
| Artifact | Notes |
|---|---|
| Prospect records | Contact details, stage, outcomes, estimated assets |
| Briefs, signals, and claims | No automatic expiry. Deleting a prospect removes them. |
| Structured commitments | What was promised and by when, without the underlying quote |
| Send metadata | When a letter went and to whom. Not its contents. |
Deletion. Deleting a prospect removes that prospect and their meeting history (hard delete via the product delete path).
Backups. Database backups are retained by Supabase for approximately eight days on our current plan, then age out.
Archiving. Inactive prospects are archived automatically after a period that varies by stage. Archiving hides a record; it does not delete it. Those periods are not currently firm-configurable.
Recording and consent
- The assistant joins your Zoom meeting as a visible, named participant: AUM Pulse Assistant
- Zoom's own recording notification is what participants see. AUMPulse does not make a separate announcement and does not record an attestation of consent.
- Obtaining consent, and any disclosure your firm requires, remains the advisor's responsibility.
- We recommend telling the prospect the assistant is present and why, before it joins.
Access
- Advisors can read and write only their own book.
- Firm owners, admins, and managers can read across their firm's book. Team views are read-only.
- Database-level isolation between firms is enforced for ordinary advisor sessions.
- A small number of AUMPulse operators can access production systems for support and incident response, via an allowlisted operator path and service-role edge jobs. Ordinary advisor sessions do not get cross-firm access.
Sending and CRM
- Letters send from your own connected mailbox after you confirm review. The copy of record is your mailbox, under your firm's retention and journaling tools.
- Nothing sends without your explicit review and confirmation. Additional send checks can block a letter that fails validation.
- AUMPulse does not write to your CRM. Export produces a file that you import. There is no automatic sync or background write.
Leaving
- Export your pipeline at any time as a Wealthbox file, a Redtail file, or a complete CSV.
- Exports include contacts, stages, outcomes, attribution, claims, and notes (Full CSV is widest).
- Exports do not include transcripts, purged letter content, authentication tokens, or audio.
- For full account closure, contact us. We will confirm the deletion path and timeline with you in writing.
What this page does not claim
- That AUMPulse is SOC 2 certified
- That no PII is stored (prospect names, emails, phones, and briefs are stored)
- HIPAA coverage (AUMPulse is not configured as a HIPAA-covered service)
- That consent is captured, announced, or attested by AUMPulse
- Firm-configurable retention periods (not shipped today)
Related: What we keep · Privacy Policy · Data Processing Agreement