A monitor shouldn't be a risk.
Pulse is designed so that even a compromised Pulse account can't change anything on your servers.
One-way, read-only
The agent only sends data out. It has no way to receive or run commands, and opens no ports.
Redacted at the source
Error-log lines are scrubbed on your server: passwords, tokens, keys, cookies, long random strings and emails are removed before sending.
An agent you can read
The agent is one readable Python file using only the standard library. Read it before installing.
Hashed credentials
Server tokens and API keys are stored only as SHA-256 hashes; passwords with scrypt. We can't show them again — only replace them.
Short retention
Metric history is kept for 3 days. Deleting a server deletes its data.
Encrypted in transit
Every request uses HTTPS with a valid certificate. Sessions are HttpOnly, Secure, SameSite cookies.
AI diagnosis and Anthropic
When you or an alert request a diagnosis, Pulse sends that server's latest redacted snapshot, its open alerts and a 6-hour metric trend to Anthropic's API, which runs Claude to write the explanation. Nothing else is sent, and Pulse never sends data to any other AI provider.
Reporting a vulnerability
Email hello@visionstack.space with "Security" in the subject. Please don't access other users' data or disrupt the service while testing. We'll reply within two working days.
Beta status
Pulse is a young product run by a small team. We don't hold security certifications yet. If you need them, tell us what you need.