Security & data privacy

Your data never leaves your network.

tracPulse is fully on-premises. The security and compliance questions enterprise teams ask — certifications, SOC 2 and ISO 27001 alignment, application security, data privacy — answered candidly and specifically.

100% on-premises — hosted on your server
Zero vendor access to your data
Ed25519-signed licenses & updates
AI assistant runs locally — no cloud LLM
Certifications

The SOC 2 / ISO 27001 question, answered honestly

A direct answer — and the context that matters when the software runs entirely inside your own network.

Are you SOC 2 or ISO 27001 certified?

Not yet — and we won't pretend otherwise. POWERN Automation has not completed a SOC 2 Type II audit or ISO/IEC 27001 certification today. ISO 27001 is on our roadmap as the company scales; in the meantime we complete customer security questionnaires candidly and support your own assessment of the product.

Why on-premises changes the picture

SOC 2 and ISO 27001 attest to a service organisation's handling of customer data — essential when your data lives in a vendor's cloud. With tracPulse, the database, monitoring credentials and every metric live on your server. There is no vendor account, tunnel or pipeline with access to that data, so tracPulse is assessed like deployed software under your control — not a data processor holding your records.

Our position

Those attestations exist to give you assurance about a vendor who hosts your data. tracPulse is deployed entirely inside your network, on your server — we never see, store or transmit your asset data, so your existing security perimeter and your own certifications continue to govern it. What we show you instead is exactly how the product is built, and how it produces the evidence your SOC 2 and ISO 27001 audits need.

Compliance support

Evidence for your audit program

tracPulse doesn't just avoid adding compliance risk — it generates the operational evidence your auditors ask for. Indicative mapping to ISO/IEC 27001:2022 Annex A and SOC 2 Trust Services Criteria; this describes how tracPulse supports your program, not a certification claim.

tracPulse capabilityEvidence it producesISO 27001:2022SOC 2
Asset inventory & discoveryA complete, continuously refreshed hardware/software register per branchA.5.9 Inventory of assetsCC6.1
Patch visibilityMissing-update status across the fleet; evidence of a managed vulnerability windowA.8.8 Technical vulnerabilitiesCC7.1
Health monitoring, alerts & pulseInsight diagnosticsContinuous monitoring with alert history and investigation trailsA.8.16 Monitoring activitiesCC7.2
Admin action audit logWho did what, when, from which IP — for every privileged action in the consoleA.8.15 LoggingCC4.1 CC7.2
Approved-software allowlistDetection and alerting on unauthorised software appearing on endpointsA.8.19 Software installationCC6.8
Endpoint control (USB block, web allowlisting, camera/mic disable)Enforced technical controls on removable media and peripherals, gated per-command and auditedA.8.1 User endpoint devices A.7.10 Storage mediaCC6.7
TPM & BitLocker posture reportingFleet-wide view of disk-encryption status — flags unencrypted drivesA.8.24 Use of cryptographyCC6.7
Backup, restore & capacity managementScheduled, integrity-manifested backups with restore verification and retention tiersA.8.13 Information backupA1.2 A1.3
Automated remediation scriptsDocumented, repeatable operational procedures with execution logsA.5.37 Operating proceduresCC8.1
Application security

How the product itself is secured

Direct answers to the technical due-diligence questions. Every statement reflects how the shipping code actually works.

SQL injection

All user-supplied values reach the database as bound parameters (prepared statements) — never concatenated into SQL text. Dynamic SQL is limited to code-controlled identifiers that are not reachable from user input.

Passwords & sessions

Passwords are stored only as salted, iterated hashes. Access is role-based (Admin / Support / Management), enforced server-side on every route. Sessions ride an HttpOnly, SameSite cookie signed with a per-installation key, and every state-changing request is CSRF-protected.

Credentials at rest

Monitoring credentials are encrypted at rest (AES with HMAC authentication). The key is a separate restricted file outside the database, so a leaked database or backup does not expose credentials — and a restore under the wrong key is detected, not silently accepted.

Signed licenses & updates

Licenses are Ed25519-signed entitlements — the product holds only the public key and fails closed on tampering. Updates ship with a signed manifest, every component is SHA-256-verified before install, and a failed update rolls back automatically.

Accountable remote actions

Every control command (service restart, USB block, script run…) is individually enabled by an administrator, and every execution lands in the audit log with user, role, target, result and source IP. Detective features are on by default; intrusive ones are opt-in.

AI without the cloud

Ask Pulse runs a local language model on your tracPulse server. Questions, asset names and metrics are processed entirely on-box — no API call to any external AI provider, and it works with no internet connection at all.

Data privacy

What is collected, where it lives, who controls it

Everything stays on your server

The tracPulse database, credentials, telemetry history, reports and AI models all reside on the server you deploy — typically inside your LAN with no inbound internet exposure. Retention is admin-configurable, so you decide how long history is kept.

Data residency

Device data, not personal content

tracPulse collects machine operational data: hardware inventory, OS and patch state, performance metrics, service and software lists. It does not read user documents, e-mail, browsing history or file contents. Personal data is limited to identifiers such as usernames and hostnames.

Data minimisation

You remain the data controller

Because POWERN Automation has no access to the data, you remain the data fiduciary/controller under India's DPDP Act 2023 (and controller under GDPR where applicable). tracPulse is an on-premises tool under your governance — no cross-border transfer is introduced by the product.

Regulatory roles

Phone-home is consent-gated

Optional product-health telemetry to the vendor stays disabled until a named administrator accepts a versioned consent notice stating exactly what is sent. If the notice ever changes, transmission stops until the new version is accepted. Declining never degrades the product.

Vendor telemetry
Due diligence

What we welcome from your security team

Because the product deploys in your environment, your team can evaluate it directly rather than relying on a vendor report.

  • Penetration testingAssess your tracPulse deployment — we support the exercise and remediate what it finds.
  • Security questionnairesSIG, CAIQ or your internal format — we complete them candidly.
  • Deployment hardening reviewHTTPS termination, network segmentation, least-privilege service accounts, key-file protection — reviewed with our team.
Our position

Rather than a certificate about our cloud, you get the software inside your perimeter where your team can test it, firewall it, and audit it. We'll support your assessment and fix what you find — a stronger assurance position for you than a report about someone else's data centre.

Put your security team in the driver's seat

Get the full Security & Data Privacy Q&A, or bring your questions straight to us.