Security at PulseFormCreator

Last updated: 17 September 2026

PulseFormCreator stores form and survey content and respondent answers on your behalf. This page explains how we protect that data and what we do not claim.

§1 Encryption

Data is encrypted in transit and at rest. In transit: TLS 1.2 or higher on every endpoint. At rest: AES-256 encryption by our infrastructure providers (PulseFormCreator's managed Supabase Postgres database for survey and response data; Cloudflare R2 for uploaded files).

§2 Access control

Access to production data is scoped per-account via row-level security (RLS) in Postgres. Only the survey owner can read their own surveys and responses. PulseFormCreator staff access is logged and only used to investigate reported incidents.

§3 Authentication

Magic-link email authentication via Supabase Auth. No password to leak. No third-party social login at launch.

§4 Backups

Daily automated database backups retained for 7 days. Point-in-time recovery available for 24 hours. Disaster recovery testing reviewed quarterly.

§5 Hosting and data residency

App servers: Vercel, in Vercel's Sydney region. Survey and response data: PulseFormCreator's managed Supabase (Postgres) database. Uploaded files: Cloudflare R2. All of it is encrypted in transit and at rest. Some processors may store data outside Australia, for example in the US or EU. See privacy policy §8.

§6 Respondent IP addresses

Raw respondent IPs are not stored. We store a one-way hashed IP for abuse and duplicate detection only. When a survey has anonymous responses turned on, not even the hash is stored, and neither is the respondent's browser or device information.

§7 Third-party processors

We use Supabase (database), Vercel (hosting), Cloudflare R2 (file storage), SendGrid (email), OpenAI (AI builder only, see the AI data policy), and Stripe (billing for paid plans). Each has its own security posture, all under contractual data-processing agreements.

§8 Responsible disclosure

If you believe you've found a security issue, please report it via the in-product feedback channel marked SECURITY. We aim to acknowledge reports within 5 business days. We will not pursue legal action against good-faith researchers who follow standard responsible-disclosure practice.

§9 What we don't claim

PulseFormCreator is not SOC 2, ISO 27001, HIPAA or PCI-DSS certified. If your use case requires one of those certifications, PulseFormCreator is not the right product for it.