Last updated: August 6, 2026
How the service is designed
- Authenticated product routes validate the current account session.
- Workspace records are scoped to the owning user or organization.
- Sensitive server credentials are not shipped to browser or mobile clients.
- Production traffic uses HTTPS on the public and application domains.
- Generated artifacts include integrity metadata where the workflow supports it.
- Web card details are entered on the payment provider's hosted domain.
- Apple subscriptions are purchased and restored through Apple in the native app.
AI-assisted features
Public chat is for product questions. Authenticated assistance can use bounded page and workspace context to help explain a workflow. Do not enter classified information, CUI, export-controlled information, passwords, secrets, or information you are not authorized to share. AI output must be reviewed by a qualified person before it is used as compliance evidence or policy.
Your responsibilities
- Use a unique password and protect access to your email account.
- Give workspace access only to authorized personnel.
- Review generated content against the organization's real environment.
- Remove data that does not belong in the service.
- Notify us promptly if you suspect account compromise or misuse.
Responsible disclosure
Report a suspected vulnerability privately to contact@federalbidpartners.com with “CMMCPulsar security report” in the subject. Include enough detail to reproduce the issue without accessing, altering, downloading, or deleting another person's data. Do not perform denial-of-service testing, social engineering, credential attacks, or destructive testing.
Security questions
For security questionnaires or data-handling questions, use the consultation page or call (877) 420-8206.