AUMPulse ← Back to Trust
Security and subprocessors

What is true today, including what we don't have yet.

AUMPulse is an early company. This page is for whoever asks the hard questions. If you're evaluating us for a firm, send this to them, then send us their follow-ups.

Last updated · Jul 25, 2026

Where AUMPulse stands

AUMPulse is not SOC 2 certified. We are a small company and have not completed an audit of our own. We'd rather lose a deal to that than surprise you in diligence.

Subprocessors

Certifications below are the vendors' published postures, not AUMPulse company certifications.

Subprocessor Role Data it touches Published posture
Recall.ai Joins the meeting, records, transcribes Meeting audio and transcript, transiently SOC 2 Type 2, ISO 27001 (vendor)
Supabase Application database and authentication Prospect records, briefs, claims, contact details, pipeline data SOC 2 Type 2, ISO 27001; AES-256 at rest, TLS in transit (vendor)
Anthropic Synthesis of briefs and letter drafts Transcript content during processing Commercial API: inputs/outputs not used for model training (vendor terms)
Google / Microsoft Calendar read and mail send, via advisor OAuth Calendar metadata, outbound mail as the advisor Vendor posture
Vercel Application and site hosting HTTP traffic to the app and marketing site SOC 2 Type 2, ISO 27001 (vendor)
Sentry Error monitoring Error metadata only (no prospect content, no request bodies) Vendor posture

The Anthropic row is where call content leaves your control during processing. We do not submit product feedback that would change Anthropic's default no-training terms for API traffic.

What is stored, and for how long

Not retained on AUMPulse

ArtifactLifetime
Meeting audio Held by Recall.ai. Deleted after synthesis succeeds. Timed floor of 24 hours if delete is missed.
Transcript Read in memory during processing. Not written to AUMPulse storage.
Letter subject and body Cleared from our database when you send, discard, or mark sent.
Evidence quotes behind commitments Cleared with the letter. Abandoned unsent quotes may also be stripped after 72 hours.

Retained until you delete the prospect

ArtifactNotes
Prospect records Contact details, stage, outcomes, estimated assets
Briefs, signals, and claims No automatic expiry. Deleting a prospect removes them.
Structured commitments What was promised and by when, without the underlying quote
Send metadata When a letter went and to whom. Not its contents.

Deletion. Deleting a prospect removes that prospect and their meeting history (hard delete via the product delete path).

Backups. Database backups are retained by Supabase for approximately eight days on our current plan, then age out.

Archiving. Inactive prospects are archived automatically after a period that varies by stage. Archiving hides a record; it does not delete it. Those periods are not currently firm-configurable.

Recording and consent

Access

Sending and CRM

Leaving

What this page does not claim

Questions from a compliance officer get a direct answer from a person, usually the founder. Write admin@aumpulse.com.

Related: What we keep · Privacy Policy · Data Processing Agreement