Security and data practices

Trust starts with labelled facts.

This public-beta trust center states what is true now and separates current website behavior from product commitments quoted before onboarding. It does not borrow badges, uptime promises, or legal language from a future product.

Current control matrix

Reviewed August 8, 2026 for public-beta accuracy.

Unknown production facts are not omitted. They are marked as scoped product terms so buyers know what must be settled before onboarding.

TopicCurrentConfigurableNot offered
Hosting and infrastructurePublic site is static HTML/CSS/JS on the Pursenda host.Product hosting provider, regions, isolation, and environment ownership are named in the customer scope.No public multi-tenant architecture claim.
AuthenticationPublic site has no login, signup, billing, or admin surface.Product login, session handling, MFA status, password policy, SSO, and roles are named in the customer scope.No self-serve product account.
AuthorizationPublic website content is crawlable and has no visitor permissions model.Least-privilege admin access, configured roles, history, and audit logging are named in the customer scope.No broad enterprise RBAC claim.
EncryptionThe public URL is served over HTTPS.Product transport, storage, key ownership, and exclusions are named in the customer scope.No encryption-at-rest claim until storage is known.
Backups and recoveryPublic website source and generated output are versioned for rollback.Product backup scope, frequency, retention, restore testing, RPO, and RTO are named in the customer scope.No uptime or restore-time SLA.
Monitoring and incidentsPublic site has no published incident SLA.Logging, alerting, vulnerability handling, incident contacts, severity definitions, and notification process are named in the customer scope.No response-time guarantee.
Data lifecycleWorking-session form data and attribution are handled by the first-party form route described in the privacy notice.Product collection, purpose, retention, correction, suppression, export, deletion, and legal holds are named in the customer scope.No product data processing before scope approval.
AI and modelsNo public product-data training claim is made.Approved model providers, data sent, retention, training policy, and human oversight are named in the customer scope.No claim that customer data trains or never trains models without approval.
VendorsNo analytics, form vendor, chat, scheduler, or tracker is intentionally used on the public site.Product vendors, purposes, data categories, geography, and change-notice process are named in the customer scope.No verified integration or subprocessor catalog beyond the scoped register.
AssuranceNo SOC 2, ISO, HIPAA, GDPR compliance, or similar certification badge is claimed.Questionnaire responses, audit evidence, or negotiated assessments are handled from actual controls.No borrowed certification language.

Data-practice disclosure worklist

Prospecting and intent claims need provenance.

Before public product launch, Pursenda publishes data categories, sources, purpose, identity level, update/freshness, retention, customer controls, correction/deletion route, suppression/opt-out route, geography limits, subprocessors, and whether product data trains models.

Source visibility

Every surfaced signal should carry source category, freshness, confidence, and reason code.

Identity boundary

Anonymous account activity must not be described as a named person's private search history.

Customer control

Correction, suppression, opt-out, deletion, and export routes need scoped process language.

Questionnaire path

Security questionnaires can be requested by email during public beta.

Learn more

Trust documents

Legal and trust routes are public and crawlable.

Each route says what is true on the website and what belongs in the quoted product scope.

Privacy

Static-site behavior, product data boundaries, and contact path.

Learn more

Terms

Published starter price, no self-serve access, and quoted commercial terms.

Learn more

Cookie policy

No analytics, trackers, pixels, embeds, chat widgets, or tracking cookies on this public-beta site.

Learn more

DPA

Data-processing addendum route and product-processing scope before customer records move.

Learn more

Subprocessors

Public-beta register for future vendors, purposes, data categories, and notice process.

Learn more

Acceptable use

Outreach and data-use boundaries before users send from the product.

Learn more