Security at DawnPulse

Your marketing data is sensitive. Here is exactly how we protect it — from the moment you upload a file to the moment your briefing is delivered.

Encryption

  • TLS 1.2+ for all data in transit, with HSTS enforced.
  • AES-256 encryption for all data at rest.
  • Encrypted database connections (TLS required).
  • Signed JWT session cookies (HttpOnly, Secure, SameSite=Strict).

Infrastructure and access controls

  • Hosted on ISO 27001-certified cloud infrastructure in Singapore (AP-Southeast).
  • Role-based access — users can only access their own data, with strict tenant isolation.
  • Automated daily database backups with 30-day retention.

Your uploaded files

CSV uploads are parsed in memory and never stored as raw files. Parsed data rows are stored per-user with strict tenant isolation, and files you delete are removed from storage within 24 hours.

Incident response and disclosure

Breach notification within 72 hours as required by GDPR Art. 33. Report vulnerabilities responsibly to support@dawnpulse.org — we acknowledge reports within 48 hours.

See our Privacy Policy and Trust & Data Handling pages for full details.