Trust & Security
Security
VerbaPulse is built for enterprise teams where communications are sensitive. Here is exactly how we handle your data, who has access to it, and what we do to protect it.
🔒
No email storage
Email content is processed in memory and discarded immediately after analysis. Never written to disk.
🔐
Encrypted in transit
All data moves over HTTPS/TLS 1.2+. No plaintext communication at any layer.
📊
No person-level tracking
Analytics are aggregated at the team and department level. We never surface individual user behavior.
Certifications and Independent Assurance
We would rather tell you exactly where we stand than let a logo imply more. Below is what someone other than us has reviewed, what we assess ourselves, and what we do not hold.
Reviewed independently
- Microsoft AppSource. The VerbaPulse Outlook add-in passed Microsoft's validation for the Microsoft 365 App Store and is published there. Microsoft reviews an add-in's manifest, requested permissions, behaviour and content before it may be listed.
- Microsoft AI Cloud Partner Program. VerbaPulse OÜ is an enrolled partner with a verified Partner Center profile, MPN ID 7139156.
Our own assessment, not independently audited
- ISO/IEC 27002 control mapping. We maintain a written mapping of our controls to ISO/IEC 27002 and share it on request. This is a self-assessment. It is not an ISO/IEC 27001 certification and should not be read as one.
- Data Processing Agreement. A signed DPA is available before a trial or pilot starts, not after it ends.
Not held
- ISO/IEC 27001. We are not certified. If certification is a condition of your procurement process, tell us early and we will discuss scope and timing with you directly rather than give you a roadmap slide.
- SOC 2. Not held.
- PCI DSS. Out of scope. VerbaPulse never receives, processes or stores cardholder data.
Security documentation, including the control mapping and our DPA, goes out before a call rather than after one. Request it at [email protected].
How Email Content Is Processed
When you trigger an analysis in the Chrome Extension or Outlook Add-in, the following happens:
Your device
→ HTTPS/TLS
VerbaPulse API
→ HTTPS/TLS
Azure OpenAI (EU)
Text extracted from active compose window only, never background reading
Text held in memory → analysis returned → memory discarded. Nothing written to database.
Only anonymized event metadata (risk type, risk level, accept/dismiss action) is stored, never the email content itself.
- The extension reads only the text field currently in focus, it does not scan other tabs, your inbox, or sent mail.
- Analysis is triggered explicitly by you (on keystroke pause), not passively in the background.
- Email text is never logged, cached, or written to any database at any stage.
- Analysis results (risk positions, suggestions) are held only in browser memory and cleared when you close the compose window.
What We Log
Most vendors describe the database and stop there. Application logs are the other place text can quietly accumulate, so here is that side as well.
- Server logs record the shape of an analysis, never its content: how many findings were returned, which risk categories they fell into, how long the call took, and the HTTP status.
- Analysed text, detected phrases and suggested rewrites are not written to logs. Content-level logging exists only behind a developer flag that is off by default and is not enabled in production.
- Log retention on the application server is capped at 14 days and 200 MB, whichever comes first.
- Anonymous analyses, such as those run from the draft checker on this website, write nothing at all: no database record, no log entry, and no account association.
Transport Security
- All client-to-server communication is enforced over HTTPS with TLS 1.2 minimum (TLS 1.3 preferred).
- HTTP requests are automatically redirected to HTTPS.
- All server-to-model communication is over HTTPS to our dedicated Azure OpenAI endpoint in the EU (Sweden Central).
- HSTS (HTTP Strict Transport Security) is configured on verbapulse.com.
Authentication & Access Control
- Passwords are hashed with bcrypt (cost factor 12, unique per-password salt). Plaintext passwords are never stored or logged.
- Session tokens are cryptographically random and expire after 30 days of inactivity.
- Organization administrators manage team access, they can add and remove users at any time from the Admin panel.
- Role separation: members see only their own usage; admins see organization-level analytics.
- VerbaPulse staff do not have access to your organization's email content, it is never stored.
Infrastructure
- Backend hosted on Microsoft Azure in the EU (Sweden Central) on a dedicated server with automated security updates.
- Database contains only account data, anonymized event logs, and organization policy guidelines, never email content.
- Server access is restricted by SSH key authentication only, no password-based login.
- Firewall rules restrict inbound traffic to HTTPS (443) and SSH (22) only.
- Automated daily database backups with 7-day retention.
Azure OpenAI Integration
VerbaPulse uses Microsoft Azure OpenAI (GPT-5.1) on a dedicated deployment in the EU (Sweden Central) to perform language risk detection. Key facts about this integration:
- Microsoft's Azure OpenAI data privacy terms state that content submitted via the API is not used to train models and is not shared with OpenAI or other customers.
- Email text is sent to the deployment solely to generate a risk analysis response, no other use, and the analysis traffic stays in the EU.
- VerbaPulse does not attach account identifiers (your name, login email, or company name) to the text sent for analysis, only the text itself is transmitted. Note that the message you choose to analyze may itself contain personal data; teams handling regulated or highly sensitive communications should contact us about EU-region processing and zero-retention options.
- Microsoft may retain API inputs for up to 30 days solely for abuse monitoring, after which they are deleted; this content is not used to train models. We intend to move to zero-retention (no abuse-monitoring logging) once we qualify for it with Microsoft. See Azure OpenAI data privacy →
Sub-processors
| Provider |
Purpose |
Data shared |
Region |
| Microsoft Azure |
Application and database hosting |
Account data, anonymized event logs, policy guidelines |
EU (Sweden Central) |
| Microsoft (Azure OpenAI) |
Language risk analysis |
Email body text only (no PII) |
EU (Sweden Central) |
| SendGrid (Twilio) |
Transactional email delivery |
Recipient email address, first name |
United States |
| Google Analytics |
Website traffic measurement |
Anonymized page views (no PII) |
United States |
We maintain a complete and up-to-date list of sub-processors. Enterprise customers may request notification of sub-processor changes by contacting [email protected].
Data Residency
VerbaPulse's application, database, and AI inference all run on Microsoft Azure in the EU (Sweden Central). Account data, anonymized event logs, and uploaded policy guidelines are stored in the EU. Email content is processed transiently and never stored, so data residency requirements related to persistent storage do not apply to email content.
Language risk analysis is performed on Microsoft Azure OpenAI in the EU (Sweden Central), on a dedicated deployment operated by VerbaPulse (see Sub-processors above). Analysis traffic does not leave the EU.
Vulnerability Disclosure
If you discover a security vulnerability in VerbaPulse, please report it responsibly to [email protected] with the subject line "Security Disclosure". We commit to:
- Acknowledge your report within 2 business days.
- Provide an initial assessment within 5 business days.
- Keep you informed of remediation progress.
- Credit researchers who report valid vulnerabilities (with their permission).
We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.