Security
Security that followsthe access journey.
PulseHireX is designed around mandatory account 2FA, least-privilege authorization, dedicated secret storage, exact destination checks, short-lived launch authorization, auditable administrative actions and stronger brokered options for high-risk resources.
Controls
The controls behind every session.
Mandatory 2FA
Every interactive account enrols an authenticator app. No role is exempt, and recovery codes are single-use and stored hashed.
Step-up verification
Credential changes, permission changes and recovery actions require a fresh authenticator code.
Least privilege
People see only the resources explicitly assigned to them, enforced in the database itself.
Dedicated secret storage
Credentials sit behind a secret boundary with no reveal, copy or export path in the product interface.
Destination checks
A launch is bound to one exact approved destination, and authorization expires in seconds.
Audit without secrets
Sign-ins, launches, rotations and assignment changes are recorded — secret values never are.
Accuracy statement
What we will not claim.
Hiding a password in the interface is not the same as making it technically impossible to extract. A browser-delivered credential can be recovered by a sufficiently privileged user on their own device. PulseHireX reduces exposure, controls who can launch what, and records the event. Brokered Access, for cases where the credential must never reach the endpoint, is in development and not yet available.
Questions
Security questions buyers ask first.
Does PulseHireX show passwords to team members?
No. The team interface has no reveal, copy or export action. Administrators write and rotate secrets; they are not displayed back afterwards.
What happens when a client website requires its own MFA?
PulseHireX never bypasses third-party MFA, CAPTCHA or anti-bot controls. The user completes the client's own second factor after the controlled sign-in.
What happens when an employee leaves?
Offboarding deactivates the account, revokes every grant and ends active sessions in one workflow, with the change recorded in the audit trail.
How do you handle responsible disclosure?
Report a suspected vulnerability through the contact page and it is routed to the security owner for triage.
Review the architecture with your security team.
We will walk through authentication, launch authorization, the extension model and the brokered boundary.
