Security Overview

Effective and last updated: September 26, 2026 · Version 2026-09-26

This page describes security practices for CultureNest Pulse as of the effective date. It is an informational overview, not a warranty or contractual commitment, unless a Signed Agreement or security addendum expressly incorporates it, in which case that agreement controls.

1. Controls in the Service

  • Practice separation: each record belongs to a practice, and database access rules limit users to data of the practices they belong to, according to their role.
  • Role-based access: users, practice admins, and CultureNest superadmins have different permissions. Superadmin privileges can be granted only by an existing, signed-in superadmin; public registration never grants roles.
  • Controlled registration: new accounts can register only with email domains an administrator has approved.
  • Encrypted connections: the Service is served over HTTPS.
  • Server-side secrets: integration credentials and scheduling secrets are kept on the server and are not sent to the browser. Scheduled background tasks require a secret credential, which is checked on every call.
  • Integration safeguards: the BlueJay integration is read-only, stores only an approved list of work-related fields, never creates accounts or changes roles, and records link, disconnect, and sync history.
  • Delivery safeguards: digest sending uses locking and per-recipient identifiers designed to prevent duplicate sends.
  • Audit history: administrative events such as sends, test sends, integration links, and sync runs are recorded.

Multi-factor authentication is not currently offered inside Pulse. If your organization uses Google sign-in, controls configured on your Google account (such as two-step verification) apply to that sign-in.

2. Shared responsibility

CultureNest uses reasonable measures for systems within its control. Customers and Users share responsibility for security, including managing who has access and removing access promptly when people leave; approving only appropriate email domains; assigning roles carefully; protecting passwords and devices; choosing appropriate recipients and content; and securing their own systems and connected third-party services.

CultureNest makes no representation that Pulse complies with HIPAA or that CultureNest is or is not a business associate. Contract language alone does not determine business-associate status under applicable law. Customer must determine whether its intended use involves protected health information (PHI), whether a business associate agreement (BAA) is required, and whether Pulse and Customer's safeguards are appropriate for that use. Unless a required BAA is in effect, Customer must not submit PHI to Pulse.

3. Reporting a security issue

Report suspected vulnerabilities or incidents to hello@culturenest.io with enough detail to reproduce the issue. Do not access data that is not yours, disrupt the Service, or publicly disclose the issue before we have had a reasonable chance to address it. Security testing requires our prior written authorization.

4. Limits

No system is completely secure, and we cannot guarantee that security measures will prevent every incident. We may change our controls over time, provided changes do not materially reduce protections committed in a Signed Agreement.