MazylonPulse
Security & compliance

Built for European enterprise from the first line of code.

Your data matters. We treat it that way: encrypted, EU-hosted, traceable, deletable on request.

Security

End-to-end encrypted. Continuously audited.

Your data is encrypted in transit (TLS 1.3) and at rest (AES-256). OAuth tokens are encrypted column-by-column via pgcrypto. Immutable audit log for every action.

  • TLS 1.3 on all communications
  • AES-256 at rest (PostgreSQL + S3)
  • OAuth tokens encrypted via pgcrypto
  • Append-only audit log + S3 WORM copy
  • Automatic secret rotation (Doppler)
  • MFA required for admins
Compliance

Native GDPR. SOC 2 in progress.

Built for European enterprise from the first line of code. GDPR, records of processing, DPA ready, right-to-be-forgotten implemented.

  • GDPR: records of processing up to date
  • DPA signable online (Enterprise template)
  • Right to be forgotten: cascade purge per tenant
  • Configurable retention policy
  • SOC 2 Type 1: Vanta audit started, delivery M9
  • ISO 27001: targeting Y2
Sovereignty

Hosted in France. EU sub-processors.

All your data stays in the European Union. Scaleway (Paris) or OVHcloud hosting, EU-managed databases, GDPR-compliant sub-processors.

  • Scaleway Paris hosting (PAR1/PAR2)
  • Aiven managed databases (Frankfurt / Paris)
  • Anthropic API: EU residency as soon as available
  • No transfer outside the EU without your explicit consent
  • Sub-processors: up-to-date public list
Isolation & access

Tenant isolation. Granular access.

Your data never crosses another customer's — isolation is enforced at 2 levels: application filter (Hibernate) AND Row-Level Security (RLS) policy directly in Postgres. No application code can read another tenant.

  • Postgres Row-Level Security: DB-level isolation
  • Tenant roles: Owner / Admin / Manager / Member
  • Project roles: LEAD (gets alerts) / MEMBER (read)
  • Read-only OAuth on Jira / GitHub / GitLab / Bitbucket / Confluence
  • No write to your tools without user confirmation (V2)
  • Per-project quiet mode (DORMANT) — immediate PM kill-switch

Data handling

Strict minimum. Always traceable.

We only collect what's directly useful to analyze your delivery. Nothing more.

Data collected

Delivery metadata only: tickets, statuses, assignees, messages, commits, PRs. Not your source code, not attachments, not personal data beyond professional identity.

Data sent to LLM

Only fragments needed for the requested analysis. No source code sent. Meeting transcripts are anonymized before analysis. 'On-premise LLM' mode (vLLM/RunPod) available in Enterprise.

Your keys, your rules

OAuth only, no password storage. You can revoke access at any time from your Jira/GitHub/Microsoft admin. Full data export available on request.

Sub-processors

Public list. Real-time updates.

You have the right to know who touches your data. Here's the exhaustive list of our sub-processors — modified only with 30-day notice.

Sub-processorPurposeRegion
ScalewayCompute + storage hostingFrance (PAR1/PAR2)
AivenManaged PostgreSQL + KafkaEU (Frankfurt / Paris)
AnthropicLLM (Claude API)EU residency enablable
RunPodGPU for self-hosted models (option)EU (NL / DE)
Microsoft Azure ADOAuth Teams / Graph APIEU
AtlassianOAuth Jira (outbound only)EU instance possible
GitHubOAuth GitHub (outbound only)Depends on your instance
DopplerSecret managementUS (client-side encryption)
Grafana CloudMetrics + logs + tracesEU

Last update: 2026-06-19. Email notification for any addition / removal.

Trust center

Documents available on request.

For security teams that need more.

  • DPA template (PDF)
  • Information security policy
  • Incident response procedure
  • SOC 2 Type 1 report (from M9)
  • Annual pen test report (Enterprise)
  • Security architecture (deep dive)