Trust & Security

Security

VerbaPulse is built for enterprise teams where communications are sensitive. Here is exactly how we handle your data, who has access to it, and what we do to protect it.

🔒
No email storage
Email content is processed in memory and discarded immediately after analysis. Never written to disk.
🔐
Encrypted in transit
All data moves over HTTPS/TLS 1.2+. No plaintext communication at any layer.
📊
No person-level tracking
Analytics are aggregated at the team and department level. We never surface individual user behavior.

How Email Content Is Processed

When you trigger an analysis in the Chrome Extension or Outlook Add-in, the following happens:

Your device
→ HTTPS/TLS
VerbaPulse API
→ HTTPS/TLS
Azure OpenAI (EU)
Text extracted from active compose window only, never background reading
Text held in memory → analysis returned → memory discarded. Nothing written to database.
Only anonymized event metadata (risk type, risk level, accept/dismiss action) is stored, never the email content itself.

Transport Security

Authentication & Access Control

Infrastructure

Azure OpenAI Integration

VerbaPulse uses Microsoft Azure OpenAI (GPT-5.1) on a dedicated deployment in the EU (Sweden Central) to perform language risk detection. Key facts about this integration:

Sub-processors

Provider Purpose Data shared Region
Microsoft Azure Application and database hosting Account data, anonymized event logs, policy guidelines EU (Sweden Central)
Microsoft (Azure OpenAI) Language risk analysis Email body text only (no PII) EU (Sweden Central)
SendGrid (Twilio) Transactional email delivery Recipient email address, first name United States
Google Analytics Website traffic measurement Anonymized page views (no PII) United States

We maintain a complete and up-to-date list of sub-processors. Enterprise customers may request notification of sub-processor changes by contacting [email protected].

Data Residency

VerbaPulse's application, database, and AI inference all run on Microsoft Azure in the EU (Sweden Central). Account data, anonymized event logs, and uploaded policy guidelines are stored in the EU. Email content is processed transiently and never stored, so data residency requirements related to persistent storage do not apply to email content.

Language risk analysis is performed on Microsoft Azure OpenAI in the EU (Sweden Central), on a dedicated deployment operated by VerbaPulse (see Sub-processors above). Analysis traffic does not leave the EU.

Vulnerability Disclosure

If you discover a security vulnerability in VerbaPulse, please report it responsibly to [email protected] with the subject line "Security Disclosure". We commit to:

We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.

Security questions? Email [email protected]

Enterprise security review? We are happy to complete security questionnaires and provide additional documentation for enterprise procurement. Contact us to get started.