Security

Last updated 1 July 2026

Security

Last reviewed: July 1, 2026.

FeedbackPulse is an employee-feedback and HR workflow platform. Customer data held in the platform is internal HR, employee profile, survey, review, recognition, and feedback data. FeedbackPulse does not connect to a customer's production systems, end-customer systems, security infrastructure, source code repositories, or cloud control planes.

Hosting and Residency

The default FeedbackPulse production hosting location is the European Union (EU).

The primary production data center is Hetzner EU Data Centers. The live application, database, required uploaded and generated files, and database backups are on EU infrastructure.

Database backups are written to a Cloudflare R2 bucket configured for the EU jurisdiction. Cloudflare edge services, DNS, CDN, DDoS protection, and WAF metadata are separate from the EU origin-hosting claim because Cloudflare operates a global network.

Infrastructure Certifications

Infrastructure certifications apply to the provider layer. They do not certify FeedbackPulse as an organization or application vendor.

Hetzner is FeedbackPulse's primary infrastructure provider for production hosting. Hetzner's provider-level controls cover physical data center security, network operations, environmental controls, and infrastructure operations. Hetzner holds:

  • ISO/IEC 27001:2022
  • BSI C5 Type 2

Cloudflare provides CDN, DDoS protection, web application firewall, DNS, and Cloudflare R2 storage services. Cloudflare maintains SOC 2 Type II, ISO 27001, and additional certifications for Cloudflare's services and control environment.

Stripe processes FeedbackPulse payments. Stripe is certified as a PCI DSS Level 1 service provider for payment processing. FeedbackPulse does not store card numbers.

We rely on provider certifications at the infrastructure, edge, and payment layers, and on FeedbackPulse's own technical and organizational controls at the application and operating layer.

Application and Organizational Controls

FeedbackPulse's own controls apply above the infrastructure layer. These controls cover the application, customer accounts, operational access, maintenance, incident handling, and support practices.

  • Data residency and hosting: Production hosting defaults to the EU on Hetzner Nuremberg infrastructure. New production database backups are stored in Cloudflare R2 with EU jurisdiction configured.
  • Access model: Customer users can access only the tenant account they belong to. Account admins manage employee access and permissions inside their own account.
  • Role-based permissions: The application separates admin and employee capabilities. Admin-only actions such as employee management, settings, review-cycle configuration, and account-level controls are protected by application authorization checks.
  • Production access: Production database and server access is restricted to authorized FeedbackPulse personnel with a support, maintenance, or incident-response need. Production access follows least-privilege practice and is used only when application-level support or operational work requires it.
  • Patching and maintenance: FeedbackPulse applies operating system, framework, dependency, and application updates through controlled maintenance and deployment workflows.
  • Backups and disaster recovery: Automated database backups support incident response and disaster recovery. Backup objects include checksum verification. Restore rehearsal evidence is maintained for the EU backup path.
  • Vulnerability disclosure: Security reports can be submitted through the Vulnerability Disclosure process.

Encryption

Customer data is encrypted in transit using TLS.

Stored data is encrypted at rest using AES-256 on the infrastructure and storage services used by FeedbackPulse. Database backups are encrypted at rest and protected by access controls. Backup integrity is checked with checksum sidecars.

Authentication and Access

FeedbackPulse supports SSO-style social authentication through configured providers, including Google and Microsoft. Users are invited or created inside a customer account before they can access account data.

The authentication provider associated with a user is recorded. Subsequent login attempts must use the same provider for that user. Customer admins control which users belong to their account and which users have admin permissions.

GDPR and DPA

FeedbackPulse operates as a GDPR-compliant processor for Customer Data processed on behalf of customer organizations. Customers act as controllers for their employee and workplace data.

FeedbackPulse offers a Data Processing Agreement. The DPA includes defined technical and organizational measures, including encryption in transit, access controls, role-based restrictions, logging and monitoring, patching and maintenance, backup and recovery processes, incident response, and operational safeguards.

Sub-Processors

FeedbackPulse maintains a current Sub-Processors page with each provider's function and location. The main production infrastructure provider is Hetzner in EU Data Centers.

Breach Notification

If FeedbackPulse becomes aware of a confirmed personal data breach affecting Customer Data, FeedbackPulse will notify affected customers without undue delay and within 72 hours where GDPR Article 33 applies. Notifications will include the nature of the breach, the data affected where known, and measures taken or planned to address the breach.

Requesting Security Information

To request the DPA, ask for security review materials, or report a vulnerability, contact: