PulseIQ Labs, Inc.
Last Updated: June 28, 2026
Corvus is a service provided by PulseIQ Labs, Inc. ('PulseIQ Labs,' 'Corvus,' 'we,' 'us,' or 'our'). Security is foundational to our product: our customers trust us with interview recordings, transcripts, and participant data, and we treat protecting that data as a core responsibility. This page describes our security program, the controls we operate today, and how to reach us about security matters.
For details on what personal data we collect and how we use it, see our Customer Privacy Policy and Respondent Privacy Policy.
1. Our Security Program & Compliance
We maintain a formal information security program led by a designated Security Lead, with policies covering access control, cryptography, data management, incident response, secure development, operations security, business continuity, third-party risk, and human resource security. All policies are approved by management and reviewed at least annually.
We are actively pursuing SOC 2 Type II certification and use Vanta, a continuous compliance platform, to monitor our controls against the SOC 2 framework in real time. We are also engaging an independent firm to perform third-party penetration testing of our platform.
We conduct a formal risk assessment at least annually, based on NIST 800-30 and ISO 27005, and maintain a risk register with documented treatment plans.
2. Infrastructure & Hosting
Corvus is a cloud-native platform. We do not operate our own data centers or physical server infrastructure; production systems run on established cloud providers that maintain industry-leading physical and environmental security and their own independent compliance certifications (such as SOC 2 and ISO 27001). Our primary infrastructure services are:
- Vercel — application hosting and delivery
- Supabase — PostgreSQL database and application data storage, hosted on Amazon Web Services
- LiveKit — real-time voice and video session infrastructure
- Amazon Web Services (S3) — storage for interview recordings and media
- Modal and Render — AI model infrastructure and backend media processing
Application errors and performance are monitored continuously with Sentry, and PostHog provides product analytics. Production logs capture user, administrator, and system activity with timestamps; logs are protected against tampering and retained for a minimum of 30 days.
Production environments are logically segregated from development and staging environments. Production customer data is not used in development or testing without explicit management approval, and is scrubbed of sensitive information wherever feasible when approved.
3. Data Encryption
- In transit: All data transmitted between your browser and Corvus, and between our internal services, is encrypted using TLS.
- At rest: Customer data is encrypted at rest using AES-256.
- Credentials: Passwords are stored using strong one-way hashing algorithms with unique salts. Authentication for the Corvus portal is managed by Clerk, our identity provider; we never store plaintext passwords.
- Backups: Backups of confidential data are encrypted.
Our cryptographic standards follow industry guidance, including NIST recommendations, and access to keys and secrets is restricted under our Access Control Policy.
4. Access Control
We follow the principle of least privilege: personnel are only granted the access required to perform their job function, enforced primarily through role-based access control (RBAC).
- Multi-factor authentication (MFA) is required for privileged access to production infrastructure, and employees use MFA/SSO across company systems.
- Every person has a unique identifier; credential sharing is prohibited.
- Access rights are formally documented, require approval, and are reviewed quarterly.
- Access is revoked promptly upon role change or departure, within 24 business hours at most.
- Administrator access and privileged activity are logged and auditable.
5. Data Retention & Deletion
All customer data is classified at our highest sensitivity tier ("Confidential") and handled accordingly.
- We retain customer data only as long as needed to provide our services or to meet legal and contractual requirements.
- Customer accounts and data are deleted within 90 days of contract termination once the data is no longer needed for business purposes.
- Customers may request deletion of their data at any time, and we honor verified deletion requests from data subjects where we have no overriding legal obligation to retain the data.
- Personally identifiable information is deleted or de-identified when it no longer has a business use.
- Media and devices that stored confidential data are securely erased or destroyed before disposal or reuse, following NIST 800-88 guidelines.
Retention details for specific data categories are documented in our internal Data Retention Matrix and are available to customers on request.
6. Application Security & Secure Development
Security is built into our development lifecycle:
- All code is version-controlled, and significant changes are reviewed and approved before merging to production. No change is deployed by a single individual without oversight.
- Changes are tested in environments segregated from production before deployment.
- Our engineering practices follow secure-by-design principles, including least privilege, defense-in-depth, secure defaults, and minimizing attack surface.
- Automated tests run as part of our build pipeline, and failing tests block production deploys.
7. Vulnerability Management & Penetration Testing
- Vulnerability scans are performed on public-facing production systems at least quarterly.
- Identified vulnerabilities are triaged by severity and remediated within defined timeframes — critical vulnerabilities within 30 days and high-severity vulnerabilities within 60 days.
- Anti-malware and threat detection controls are deployed across company systems as appropriate.
- We are engaging an independent security firm to conduct third-party penetration testing, and will make summary results available to customers under NDA on request.
8. Incident Response
We maintain a documented Incident Response Plan that defines how security events are reported, triaged by severity, investigated, contained, and remediated.
- All personnel are trained and required to report suspected security events immediately.
- Critical incidents trigger immediate escalation to senior management, a dedicated response team, and a documented root cause analysis.
- If an incident results in unauthorized access to customer data, we will notify affected customers, individuals, and regulators without undue delay, in accordance with our contractual commitments and applicable law.
To report a security incident or concern, contact security@meetcorvus.ai.
9. Business Continuity & Backups
- Production data is backed up on an ongoing basis, with backups encrypted and stored separately from the production data location.
- We maintain a Business Continuity and Disaster Recovery Plan with documented recovery objectives and continuity procedures for infrastructure, communications, and support scenarios.
- Disaster recovery testing, including backup restoration testing, is performed at least annually.
- As a remote-first company running on distributed cloud infrastructure, we are not dependent on any single physical location to operate.
10. Subprocessors & Vendor Management
We assess every vendor before they may access, store, or process confidential data. Our third-party risk program includes security due diligence prior to engagement, written agreements covering confidentiality and security obligations, review of vendors' own audit reports and certifications (such as SOC 2 and ISO 27001), and at least annual review of supplier security and service delivery.
A current list of the subprocessors that support the Corvus platform is maintained in our Customer Privacy Policy.
11. People & Organizational Security
- All employees and contractors sign confidentiality agreements and formally acknowledge our information security policies.
- Security awareness training is completed at hire and annually thereafter.
- Employees access company systems with MFA/SSO, and company devices are required to use encryption, screen locks, and anti-malware protections.
- Access is fully revoked and equipment returned as part of a documented offboarding process.
12. AI & Data Handling
Corvus uses large language models and AI services to conduct, transcribe, and analyze interviews:
- Deepgram — speech-to-text transcription of interview audio
- OpenAI, Anthropic, and Google Gemini — LLM-based summarization, analysis, and AI moderation of transcripts and text responses
- ElevenLabs — text-to-speech voice synthesis for the AI moderator
- Modal — AI model infrastructure and video processing
Each of these providers is listed as a subprocessor in our Customer Privacy Policy, operates under agreements that restrict their use of your data to providing services to Corvus, and is subject to the same vendor risk assessment as any other subprocessor. For details on how customer and respondent data is used, see our privacy policies.
13. Responsible Disclosure
We welcome reports from security researchers who believe they have found a vulnerability in Corvus.
If you discover a potential security issue, please email security@meetcorvus.ai with a description of the issue and steps to reproduce it. We ask that you:
- Give us a reasonable opportunity to investigate and remediate before any public disclosure.
- Act in good faith: avoid accessing, modifying, or destroying data that is not yours, and do not degrade the service for others.
- Do not use social engineering, physical attacks, or denial-of-service techniques.
We will acknowledge your report, keep you informed of our progress, and will not pursue legal action against researchers who follow these guidelines in good faith.
14. Contact Us
For security questions, documentation requests (including policies, penetration test summaries, or due-diligence questionnaires), or to report a concern:
For privacy-related requests, contact privacy@meetcorvus.ai.