Trust & security
You’re handing us read access to your money.
That deserves more than a badge on a pricing page. Here is what COVIS Pulse can see, what it cannot do, and how the credentials are held.
Access
Read-only, always.
Pulse exists to show you numbers. It has no reason to move money or change your books, so it is not built to.
It can read
Metrics only
Charge and payout totals, subscription counts, invoice balances, visitor and conversion counts, review scores, and calendar event counts. Enough to answer "how did the week go".
It cannot write
By design
No refunds, no transfers, no edits to your ledger, no cancelling subscriptions, no posting on your behalf. Where a provider offers scoped keys, we ask for the read-only scope and nothing more.
You revoke it, not us
Your account, your control
Access is granted from your own provider account and can be withdrawn there at any time without asking us. If you revoke it, syncing stops immediately.
Storage
How the credentials are held.
Encrypted at rest
AES-256-GCM
Connection credentials are encrypted before they touch the database. The browser never receives them — only the server-side sync workers can decrypt, and only to run a sync.
Isolated per business
Enforced in the database
Every row carries its owner, and the isolation rules live in the database itself rather than in application code. A bug in a page cannot leak another business's numbers, because the query never returns them.
Signed, expiring authorisation
OAuth & client links
OAuth state and the links we send owners to approve access are cryptographically signed and expire. Payment webhooks are signature-verified per connection before anything is written.
Paired devices, not shared logins
TV mode
A screen on your wall authenticates with its own single-use pairing code and a device-specific token. It cannot be used to sign in anywhere else, and you can unpair it without touching your password.
Being straight with you
What we are not claiming.
Plenty of companies imply certifications they don't hold. We'd rather list ours honestly — which currently means listing none.
No SOC 2 or ISO 27001
Not yet audited
We have not completed a third-party security audit. The controls above are real and implemented, but they are our description of our own system, not an auditor's. If you need certification for procurement, tell us and we'll be straight about the timeline.
We're a small team
Know the trade-off
There is no 24/7 security operations centre here. What there is: a small surface area, few dependencies, and no incentive to hold data we don't need.
Report something
We'll respond
Found a vulnerability? Email us and we'll acknowledge within one business day. We won't threaten anyone acting in good faith.
Questions
Ask before you connect anything.
If there's something here you need clarified for your own compliance, ask — a real person answers.