Security & Trust

Security built into every layer

Encrypted access, granular permissions, a full audit trail and reversible automation — PulseGuard gives you the control and visibility to run confidently, from SSH sessions to autonomous SEO changes.

Free plan available · No credit card required

ssh · prod-web-01
$ pulseguard ssh prod-web-01
🔒 Quantum Shield · AES-256-GCM channel established
Last login: today 14:32 from pulseguard-portal
$ uptime
14:32:05 up 45 days, load average: 0.18, 0.21, 0.19
$ systemctl status api
● api.service — active (running) since 45d ago
$ tail -f /var/log/nginx/access.log
$

Security pillars

Every control you need to stay in charge

From encrypted SSH to approval-gated automation, PulseGuard is designed so you never have to choose between capability and control.

AES-256-GCM encrypted SSH

Every SSH session opened through PulseGuard's browser portal is protected with Quantum Shield AES-256-GCM encryption — no credentials ever travel in plaintext.

Session recording & playback

Every SSH session is recorded in full and available for playback, giving you a complete, tamper-evident record of every command run on every server.

Role-based access control

Assign one of 10 granular permissions to each team member, or build custom roles — so each person can only access the resources their job requires.

Complete audit log

Every action — from changing a monitor to applying a PulseRank optimisation — is written to an immutable audit log with timestamp, actor and full change detail.

Approval-gated, reversible automation

PulseRank changes are proposed and risk-tiered before being applied. Every change is revertible with one click, and each site has its own kill switch to halt automation instantly.

2FA & brute-force lockout

Two-factor authentication is enforced on all login paths, and accounts are locked after repeated failed attempts — blocking credential-stuffing and brute-force attacks.

You can see and undo everything

Full visibility. Full reversibility.

Every action taken by a team member or PulseRank's automation engine is written to an immutable audit log — timestamped, attributed and fully browseable. When you need to roll something back, a single click reverts any applied change. And if you ever want to pause automation for a site entirely, a per-site kill switch halts it instantly.

Immutable audit log
Every action logged with actor, timestamp and full change detail — nothing is hidden.
One-click revert
Any PulseRank change can be rolled back immediately from the audit log.
Risk-tiered proposals
Automation changes are assessed and tiered by risk before they are applied.
Per-site kill switch
Stop all automation for any single site in one click — no global impact.
prod-web-01 · healthHealthy
24%
CPU
62%
Memory
85%
Disk
AI diagnosis

Disk at 85%/var/log grew 3.2 GB in 24h. Recommend rotating nginx logs; projected full in ~6 days.

Rotate logsDismiss

FAQ

Security questions, answered

How is SSH traffic encrypted?

PulseGuard's browser SSH portal encrypts every session with AES-256-GCM — the same standard used in modern TLS. Your credentials and session data are never transmitted or stored in plaintext, and encryption is applied end-to-end between your browser and the target server.

Are SSH sessions recorded?

Yes. Every session opened through the PulseGuard portal is recorded in full and stored for audit and compliance purposes. Authorised administrators can play back any session to review exactly what commands were run, in what order, and when.

How does role-based access control work?

Each team member is assigned a role that bundles one or more of 10 granular permissions — covering monitors, alerts, PulseRank, SSH, billing and more. You can use the built-in roles or create custom ones, ensuring every person has precisely the access their job requires and nothing more.

Can I undo automated changes made by PulseRank?

Yes. Every change PulseRank proposes is risk-tiered and must pass an approval gate before it is applied. After application, any change can be reverted with a single click from the audit log. Each site also has an individual kill switch that immediately halts all automation for that property.

What account security protections are in place?

Two-factor authentication is enforced across all login flows — there are no paths that bypass 2FA. In addition, accounts are automatically locked for 15 minutes after 8 failed login attempts, which prevents both brute-force and credential-stuffing attacks.

Security you can trust, automation you can control

Start free — encrypted SSH, RBAC, audit logs and reversible automation included.