OPENPULSEEDGE: PROBING—ms

OpenPulseHome
Security

Clients seal. Operators route opaque bytes.

OpenPulse is an encrypted communication wire. Message keys stay on client devices. Identity, login, and payment confirmation run on our EU origin. Regional couriers carry sealed traffic — not plaintext product trust.

01 · Separation

Trust stays home

Account, directory, and payment confirmation live on the origin we operate in the EU. Optional regional couriers terminate TLS and forward sealed payloads only.

Marketing pages are not on the product-data processor list.

02 · Encryption

Honesty over slogans

Production traffic is sealed end to end when configured — operators see opaque bodies and routing metadata, not message plaintext. Demo and staging environments may use plaintext modes for debugging; those are not production privacy claims.

Messaging targets established protocols for 1:1 and group sessions. Transitional modes are labeled until production ratchets are complete.

03 · Auth & Pay

Confirmation on origin

Passkeys and sign-in terminate on our origin Auth service. Payment confirmation UI asks Auth to verify factors — signing secrets never leave Auth. Checkout HTML is not a second trust plane.

04 · Subprocessors

Product data path only

Updated 2026-07-27

ProcessorRoleSeesRegionRemovable
HetznerEU origin — identity, auth, payment confirmation, durable recordsIdentity, account bindings, Checkout UX, sealed routing metadataEUNo (origin)
Fly.ioRegional sealed-traffic couriersTLS + sealed ciphertext + routing metadataMulti-regionYes
ResendTransactional emailEmail addresses and mail contentProviderYes

Omitted: marketing hosts, DNS-only providers, CI tooling, bot widgets.

05 · Data

What we process

Handles and account bindings, claim/verify email, session bindings, sealed traffic and routing metadata, and payment step-up session metadata. Application data stays with the integrator — OpenPulse is the wire, not your product database.

06 · Controls

What you can run

Self-host relays, fence traffic with your own realm keys, and prefer sealed production modes. Public capacity claims follow published gates — not marketing copy.

07 · Contact

Security disclosure

Report issues to security@openpulse.org. Scope: OpenPulse wire, Auth, Pay Checkout, and official managed couriers. No public bounty program is claimed here.

Privacy / Terms / Impressum require counsel review before publication.