01

Local document processing

Customer files are parsed in the browser. The platform does not need the complete raw document to calculate or save a compact workspace summary.

02

Data minimisation

Saved records contain user-selected summaries, mappings, decisions, scenario parameters, and audit events—not the original spreadsheet payload.

03

Authenticated workspaces

Workspace pages use platform-managed sign-in. API writes require an authenticated identity and enforce ownership server-side.

04

Human approval boundary

Recommendations cannot become purchases or payments automatically. Approval Lock keeps operational authority with an identified user.

05

Payment isolation

Payment details are handled by the merchant-of-record checkout. VarePulse stores provider references and subscription state, not card numbers.

06

Auditability

Saved actions are attributed with timestamps and concise metadata so teams can review what changed without exposing unnecessary document content.

Protect the highest-risk boundaries first.

Found a security issue?

Do not include customer data or exploit production accounts. Email support.varepulse@gmail.com or use the public contact form, choose “Security”, and include only the details needed to investigate safely.