Dock Pulse
← Back to dock-pulse.com Sign in

Security & Trust

Last updated: 20 June 2026

This page summarises how Dock Pulse protects your data and runs the Service — written to give security and procurement teams what they need at a glance. We're an early-access product and describe our posture honestly: what is in place today, not aspirations. For formal due diligence we can share more under NDA (see the last section).

1. Our approach

Our security practices are aligned to ISO/IEC 27001:2022 (Annex A) and the UK NCSC Cloud Security Principles. We are not formally certified to ISO 27001 and don't claim to be — instead we hold ourselves to its controls and can evidence how each is met. We keep an internal register of those controls and any known gaps, and close them on a prioritised basis.

2. Read-only by design

Dock Pulse is a monitoring layer, not a control system. We read telemetry from the FlightHub API keys you connect and present it back to you. The Service never commands, dispatches or lands aircraft, and never changes anything inside your FlightHub organisation. That deliberate limit keeps the security blast-radius small: a problem on our side cannot affect your flight operations.

3. Data protection & privacy

  • We comply with UK GDPR. For your account data we are the data controller; for the operational telemetry your fleet exposes we act as processor.
  • Your data is hosted in the UK/EU. Snapshot imagery is stored on our own servers — never on third-party object storage.
  • Each workspace's data is isolated: one customer can never see another's, even where two organisations legitimately monitor the same shared dock.
  • On closure our default is to de-identify rather than destroy, with full erasure available on request — see our Privacy Policy and Terms.

4. Accounts & access

  • Passwordless sign-in: we email a one-time code, so there is no password to steal — and we never store one.
  • Role-based access (Owner / Admin / Viewer), re-checked on every request, so permissions never carry across workspaces.
  • Append-only audit log of authentication, account and data-change events.
  • Administrative access to the platform is limited to a small number of named operators.

5. Application & data security

  • Encryption in transit (TLS/HTTPS) for everything.
  • The FlightHub keys you connect are encrypted at rest.
  • CSRF protection on every state-changing action, and least-privilege throughout.
  • We set only a strictly necessary session cookie — no advertising, analytics or tracking cookies, which is why there's no cookie banner.

6. Hosting & resilience

The platform runs on UK/EU infrastructure with isolated tenancy. We take regular backups of the platform's metadata database and monitor service health. As an early-access product we don't offer a contractual uptime SLA, but we work to restore any interruption promptly.

7. How we operate

  • Change management: changes are tracked in version control, assessed for security impact, tested away from production, and carry a rollback path before release.
  • Incident response: we run a documented, severity-graded process. If an incident affects you we notify you without undue delay; where personal data may be involved we follow the UK GDPR breach-assessment process.

8. Sub-processors

We never sell your data, and share it only with the providers needed to run the Service, under contract:

  • Lemon Squeezy — payments (Merchant of Record).
  • Resend — transactional email (sign-in codes, alerts, reports).
  • Our UK/EU hosting provider — infrastructure.
  • Open-Meteo — weather context, fetched using a dock's coordinates only; no personal data leaves with it.
  • A large-language-model provider — engaged only if a workspace turns on the optional AI assistant, which is off by default.

9. Reporting a vulnerability

If you believe you've found a security issue, please email admin@dock-pulse.com. We'll acknowledge it and work with you. Please don't access other customers' data or run destructive tests — responsible disclosure only.

10. Due diligence & documentation

For procurement or vendor assessment we can provide further detail under NDA — including our incident-response and change-management processes, a fuller control mapping, a sub-processor list, and a Data Processing Agreement. Contact admin@dock-pulse.com.

News · Terms of Service · Refund & Cancellation Policy · Privacy Policy · Security & Trust · Compliance · dock-pulse.com
© 2026 Dock Pulse. Not affiliated with DJI. FlightHub is a trademark of DJI.
Dock Pulse™ is a trademark and trading name of 56SV Ltd, registered in England and Wales (Company No. 17323675). Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.