Clients seal. Operators route opaque bytes.
OpenPulse is an encrypted communication wire. Message keys stay on client devices. Identity, login, and payment confirmation run on our EU origin. Regional couriers carry sealed traffic — not plaintext product trust.
Trust stays home
Account, directory, and payment confirmation live on the origin we operate in the EU. Optional regional couriers terminate TLS and forward sealed payloads only.
Marketing pages are not on the product-data processor list.
Honesty over slogans
Production traffic is sealed end to end when configured — operators see opaque bodies and routing metadata, not message plaintext. Demo and staging environments may use plaintext modes for debugging; those are not production privacy claims.
Messaging targets established protocols for 1:1 and group sessions. Transitional modes are labeled until production ratchets are complete.
Confirmation on origin
Passkeys and sign-in terminate on our origin Auth service. Payment confirmation UI asks Auth to verify factors — signing secrets never leave Auth. Checkout HTML is not a second trust plane.
Product data path only
Updated 2026-07-27
| Processor | Role | Sees | Region | Removable |
|---|---|---|---|---|
| Hetzner | EU origin — identity, auth, payment confirmation, durable records | Identity, account bindings, Checkout UX, sealed routing metadata | EU | No (origin) |
| Fly.io | Regional sealed-traffic couriers | TLS + sealed ciphertext + routing metadata | Multi-region | Yes |
| Resend | Transactional email | Email addresses and mail content | Provider | Yes |
Omitted: marketing hosts, DNS-only providers, CI tooling, bot widgets.
What we process
Handles and account bindings, claim/verify email, session bindings, sealed traffic and routing metadata, and payment step-up session metadata. Application data stays with the integrator — OpenPulse is the wire, not your product database.
What you can run
Self-host relays, fence traffic with your own realm keys, and prefer sealed production modes. Public capacity claims follow published gates — not marketing copy.
Security disclosure
Report issues to security@openpulse.org. Scope: OpenPulse wire, Auth, Pay Checkout, and official managed couriers. No public bounty program is claimed here.
Privacy / Terms / Impressum require counsel review before publication.