Pulse by Tomera Request early access
Security & data

Built to be trusted with your Asana.

Pulse reads delivery data to do its job, so how it handles that data is part of the product — not an afterthought. Here is exactly what it asks for and how it is kept.

Principles

Trust is a product feature, not a setting.

Read-only

Pulse reads Asana. It never writes back, creates tasks or changes status.

Least-privilege

Six read scopes, and no more. No write scopes are ever requested.

Server-side

Access tokens are encrypted and held server-side. They never reach the browser.

Tenant-isolated

Every customer’s data is scoped to their tenant, resolved on the server.

Signing in

  • Sign-in is through Google Workspace (OpenID Connect), restricted to your organisation’s domain.
  • There is no public sign-up. Unknown accounts are not created automatically.
  • Sessions are opaque and server-side; only a hash of the session token is stored.
  • The session cookie is Secure, HttpOnly, SameSite and uses the __Host- prefix.

Connecting Asana

  • Authorisation uses the OAuth authorisation-code flow with PKCE and one-time state.
  • The six scopes requested are read-only: workspaces, portfolios, projects, tasks, users and teams.
  • Tokens are stored encrypted and used only server-side.
  • You choose which teams, portfolios and projects are in scope — Pulse reads only those.

How your data is handled

  • Pulse reads native Asana fields — dates, status, milestones, dependencies, owners and assignees.
  • It does not require or read custom fields to be useful.
  • Missing, stale or ambiguous data is shown as such. Pulse does not infer certainty Asana doesn’t provide.
  • When the source data is stale, current-action suggestions are held back rather than presented as fresh.

What Pulse never does

  • Write anything back into Asana.
  • Request write or admin scopes.
  • Invent a score, date or status the data doesn’t support.
  • Mix one organisation’s data with another’s.
Early access

Questions before you connect?

If your security team needs detail beyond this page, ask us directly — we’d rather answer than gloss over it.

Read-only Asana access · no pricing commitment · pre-release