Security Roadmap

Last updated: June 1, 2026

BookPulse is an early-stage product built by one founder. We are honest about what we have today and what we are building toward. Our current security posture is documented on the Security Practices page — encryption in transit and at rest, Row-Level Security on every table, server-side enforcement, de-identified AI processing, and US-based infrastructure.

Here is where we stand on the certifications and controls schools commonly evaluate. Dates are targets, not guarantees — we will update this page as items ship.

What we are working toward

ItemStatusTarget
SOC 2 Type II auditNot startedQ3 2027
Third-party penetration testingNot startedQ1 2027
Multi-factor authentication (teacher accounts)In designQ4 2026
Centralized security event monitoring (SIEM)Not startedQ2 2027
Public SLA with uptime guaranteesNot startedQ3 2027
Formal bug bounty programNot startedQ4 2027
Anthropic Data Processing Agreement executionIn progressQ3 2026

If any of these are blockers

If a missing item on this roadmap is a hard requirement for your school or district, that is useful for us to know. Email chris@readbookpulse.com and we will be candid about current status and timing. We would rather have an honest conversation about fit than oversell.