Transparency is a design principle at PulseSafety. This page lists every third-party service that may process agency data, along with their purpose and data scope.
PulseSafety uses a limited set of trusted third-party service providers to operate our platform. We are committed to transparency about who has access to data and why.
Effective date: April 23, 2026
We share only the data each subprocessor strictly needs to perform their service. Every provider is evaluated against CJIS-alignment requirements before onboarding.
This list reflects services active in our production environment. We update it within 30 days of adding or removing a provider.
| Subprocessor | Category | Purpose | Location | Data Types |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Infrastructure | Primary hosting, compute, storage, and networking for all CommandCORE environments. | United States | All platform data (encrypted at rest and in transit) |
| Railway | Database Hosting | Managed PostgreSQL databases for CommandCORE operational data. | United States | Operational and configuration data |
| Vercel | Application Delivery | Web application hosting and edge delivery for the PulseSafety marketing site. | United States | Public site content only — no agency data |
| Resend | Transactional Email | Delivery of system notifications and account emails. | United States | Email address, notification content |
If you have questions about our subprocessors or want to request an updated list, reach out to our privacy team.
Authorized agency contacts may request a full data-flow diagram and subprocessor DPA within 10 business days.
We notify customers of material subprocessor changes at least 30 days in advance.
Review our full security posture, CJIS alignment status, and responsible disclosure policy.