tracPulse is fully on-premises. The security and compliance questions enterprise teams ask — certifications, SOC 2 and ISO 27001 alignment, application security, data privacy — answered candidly and specifically.
A direct answer — and the context that matters when the software runs entirely inside your own network.
Not yet — and we won't pretend otherwise. POWERN Automation has not completed a SOC 2 Type II audit or ISO/IEC 27001 certification today. ISO 27001 is on our roadmap as the company scales; in the meantime we complete customer security questionnaires candidly and support your own assessment of the product.
SOC 2 and ISO 27001 attest to a service organisation's handling of customer data — essential when your data lives in a vendor's cloud. With tracPulse, the database, monitoring credentials and every metric live on your server. There is no vendor account, tunnel or pipeline with access to that data, so tracPulse is assessed like deployed software under your control — not a data processor holding your records.
Those attestations exist to give you assurance about a vendor who hosts your data. tracPulse is deployed entirely inside your network, on your server — we never see, store or transmit your asset data, so your existing security perimeter and your own certifications continue to govern it. What we show you instead is exactly how the product is built, and how it produces the evidence your SOC 2 and ISO 27001 audits need.
tracPulse doesn't just avoid adding compliance risk — it generates the operational evidence your auditors ask for. Indicative mapping to ISO/IEC 27001:2022 Annex A and SOC 2 Trust Services Criteria; this describes how tracPulse supports your program, not a certification claim.
| tracPulse capability | Evidence it produces | ISO 27001:2022 | SOC 2 |
|---|---|---|---|
| Asset inventory & discovery | A complete, continuously refreshed hardware/software register per branch | A.5.9 Inventory of assets | CC6.1 |
| Patch visibility | Missing-update status across the fleet; evidence of a managed vulnerability window | A.8.8 Technical vulnerabilities | CC7.1 |
| Health monitoring, alerts & pulseInsight diagnostics | Continuous monitoring with alert history and investigation trails | A.8.16 Monitoring activities | CC7.2 |
| Admin action audit log | Who did what, when, from which IP — for every privileged action in the console | A.8.15 Logging | CC4.1 CC7.2 |
| Approved-software allowlist | Detection and alerting on unauthorised software appearing on endpoints | A.8.19 Software installation | CC6.8 |
| Endpoint control (USB block, web allowlisting, camera/mic disable) | Enforced technical controls on removable media and peripherals, gated per-command and audited | A.8.1 User endpoint devices A.7.10 Storage media | CC6.7 |
| TPM & BitLocker posture reporting | Fleet-wide view of disk-encryption status — flags unencrypted drives | A.8.24 Use of cryptography | CC6.7 |
| Backup, restore & capacity management | Scheduled, integrity-manifested backups with restore verification and retention tiers | A.8.13 Information backup | A1.2 A1.3 |
| Automated remediation scripts | Documented, repeatable operational procedures with execution logs | A.5.37 Operating procedures | CC8.1 |
Direct answers to the technical due-diligence questions. Every statement reflects how the shipping code actually works.
All user-supplied values reach the database as bound parameters (prepared statements) — never concatenated into SQL text. Dynamic SQL is limited to code-controlled identifiers that are not reachable from user input.
Passwords are stored only as salted, iterated hashes. Access is role-based (Admin / Support / Management), enforced server-side on every route. Sessions ride an HttpOnly, SameSite cookie signed with a per-installation key, and every state-changing request is CSRF-protected.
Monitoring credentials are encrypted at rest (AES with HMAC authentication). The key is a separate restricted file outside the database, so a leaked database or backup does not expose credentials — and a restore under the wrong key is detected, not silently accepted.
Licenses are Ed25519-signed entitlements — the product holds only the public key and fails closed on tampering. Updates ship with a signed manifest, every component is SHA-256-verified before install, and a failed update rolls back automatically.
Every control command (service restart, USB block, script run…) is individually enabled by an administrator, and every execution lands in the audit log with user, role, target, result and source IP. Detective features are on by default; intrusive ones are opt-in.
Ask Pulse runs a local language model on your tracPulse server. Questions, asset names and metrics are processed entirely on-box — no API call to any external AI provider, and it works with no internet connection at all.
The tracPulse database, credentials, telemetry history, reports and AI models all reside on the server you deploy — typically inside your LAN with no inbound internet exposure. Retention is admin-configurable, so you decide how long history is kept.
Data residencytracPulse collects machine operational data: hardware inventory, OS and patch state, performance metrics, service and software lists. It does not read user documents, e-mail, browsing history or file contents. Personal data is limited to identifiers such as usernames and hostnames.
Data minimisationBecause POWERN Automation has no access to the data, you remain the data fiduciary/controller under India's DPDP Act 2023 (and controller under GDPR where applicable). tracPulse is an on-premises tool under your governance — no cross-border transfer is introduced by the product.
Regulatory rolesOptional product-health telemetry to the vendor stays disabled until a named administrator accepts a versioned consent notice stating exactly what is sent. If the notice ever changes, transmission stops until the new version is accepted. Declining never degrades the product.
Vendor telemetryBecause the product deploys in your environment, your team can evaluate it directly rather than relying on a vendor report.
Rather than a certificate about our cloud, you get the software inside your perimeter where your team can test it, firewall it, and audit it. We'll support your assessment and fix what you find — a stronger assurance position for you than a report about someone else's data centre.
Get the full Security & Data Privacy Q&A, or bring your questions straight to us.