Trusted feedback starts with secure foundations.
thankyü Pulse is built to protect review integrity, personal data and organisational insight at every stage, from the moment a QR code is scanned to the point information reaches your dashboards.
Proprietary fraud detection. Proactive review-integrity checks. More credible evidence for better-informed decisions.
- Cyber Essentials Plus certified
- ISO/IEC 27001 certified
- UK data residency
- UK GDPR and Data Protection Act 2018
- ICO registered
High-volume feedback should not mean lower confidence.
Making feedback easy to give increases participation. That value is lost if organisations cannot trust what they receive.
Pulse combines a low-friction, mobile-first review journey with active integrity checks, controlled access and an auditable record of activity. This helps organisations collect more feedback without weakening the quality of the evidence behind their decisions.
Secure capture
Each QR journey is assigned a unique technical identifier, helping Pulse detect duplicate submissions and unusual activity.
Active integrity checks
Submission patterns are assessed for signs of automation, repetition, clustering and other suspicious behaviour.
Controlled access
Role-based permissions determine which information each user can see, from individual staff feedback to organisation-wide reporting.
Auditable governance
Key activity, configuration changes and administrative actions are recorded to support accountability and oversight.
Fraud is challenged before it distorts the picture.
Pulse uses proprietary fraud detection developed from thankyü’s experience in banking and financial technology.
Rather than waiting for suspicious activity to be reported, Pulse proactively assesses reviews throughout the submission process. This protects organisational scores, staff records and management insight from activity that may not represent a genuine experience.
A two-stage integrity process
Check at submission
Automated review-integrity checks run at the point feedback is submitted.
Recheck activity patterns
A further automated sweep assesses patterns across multiple submissions, identifying risks that may only become visible over time.
Separate suspicious submissions
High-risk reviews are isolated from trusted reporting while they are assessed, preventing them from distorting organisational totals.
Apply human review
Flagged activity is referred to the technical team for manual review before it is cleared or rejected.
Pulse can consider combinations of timing, session, device, network and behavioural signals where permitted. The exact thresholds and detection rules remain confidential to protect the integrity of the system.
This means genuine feedback can reach dashboards quickly without making every reviewer wait for a blanket manual verification process.
Your teams make decisions using credible evidence, not unchecked submissions.
Fraud protection does not depend on knowing everything about the reviewer.
Where personal details are requested, they are provided directly by the reviewer as part of the QR feedback journey.
Pulse does not depend solely on names or email addresses to assess review integrity. When those details are unavailable, the system can use a combination of other permitted technical and behavioural signals.
The review journey can also support anonymous feedback where configured, helping organisations balance accessibility, participation and data protection.
Reviewer-led data sharing
Personal details are provided by the person who owns them through the review capture process.
Data minimisation
Pulse is designed to collect and process information for defined purposes rather than gathering data unnecessarily.
Multiple integrity signals
Review assessment can continue when identifying details are unavailable.
Retention and deletion controls
Information can be managed through defined retention, deletion and data-governance processes.
Your Pulse data stays in the UK.
Pulse operates on AWS infrastructure configured for UK data residency. Organisational information, review data and associated platform records are hosted on UK soil.
Pulse is designed and operated in line with the UK GDPR and Data Protection Act 2018. thankyü is also registered with the Information Commissioner’s Office.
Data-protection controls apply throughout the information lifecycle, covering capture, access, storage, analysis, retention and deletion.
Purpose-led processing
Information is collected and used for clearly defined review, recognition, security and reporting purposes.
Restricted access
Access is controlled according to role, organisational level and legitimate operational need.
Secure storage and transfer
Data is encrypted both while stored and while moving between systems.
Accountable processing
Audit records and governance controls help demonstrate how information has been accessed and managed.
Security supported by recognised standards.
Pulse is operated within thankyü’s certified information-security environment, supported by recognised cyber-security standards and ongoing technical assurance.
Cyber Essentials Plus
Cyber Essentials Plus includes technical testing of the controls used to protect an organisation against common cyber threats.
ISO/IEC 27001
ISO/IEC 27001 provides a structured, risk-based approach to managing the confidentiality, integrity and availability of information.
UK GDPR and Data Protection Act 2018
Pulse applies data-protection principles across its platform, operational processes and information lifecycle.
ICO registered
thankyü is registered with the UK's independent data-protection regulator.
Protection across the whole platform.
Pulse combines preventative, detective and recovery controls to protect data, accounts and service availability.
Encryption
Data is encrypted in transit and at rest to reduce the risk of unauthorised access or interception.
Multi-factor authentication
Multi-factor authentication adds an additional layer of protection to account access.
Single sign-on
Single sign-on can support centralised identity management and help organisations apply their existing access policies.
Role-based access control
Permissions are assigned according to role and organisational hierarchy, from individual employees to site, regional and head-office users.
Audit logging
Administrative actions, significant system activity and configuration changes are recorded to support investigation and accountability.
Vulnerability management
Routine vulnerability scanning helps identify technical weaknesses before they can be exploited.
Independent penetration testing
Independent testing provides additional assurance that platform controls are working as intended.
Automated backups
Regular backups protect against accidental deletion, corruption and operational disruption.
Disaster recovery
Documented recovery arrangements help restore critical services following a significant incident.
Incident response
Defined procedures support the identification, escalation, containment and resolution of security events.
Data-retention controls
Retention and deletion processes help prevent information from being stored for longer than required.
Access follows responsibility.
Pulse uses hierarchical, role-based permissions so that users see the information required for their role without gaining unnecessary access to sensitive data.
Staff members
Staff can access their own recognition, feedback history and relevant personal insight through a secure, read-only view.
Managers
Authorised managers can view feedback and reporting for the people, teams, locations or services within their permitted organisational level.
Senior leaders
Regional and organisation-level users can access aggregated trends, comparisons and performance insight according to their permissions.
Technical team
Sensitive review-integrity signals and the detailed fraud-review workflow are restricted to the technical team.
Access to data remains subject to role, purpose and audit. Technical fraud-detection information is not exposed through general staff or management dashboards.
AI supports human judgement. It does not replace it.
Pulse uses AI to help authorised users interpret large volumes of feedback. It can surface themes, sentiment, emerging patterns and recommended actions that would be difficult to identify through manual analysis alone.
This insight can support management conversations, appraisals, workforce development and service-improvement planning.
AI outputs are presented as decision support. Suspicious reviews are referred for human assessment and access to AI-generated insight is governed by the same permissions and data-protection controls as the rest of the platform.
Pattern identification
Identify recurring themes across people, teams, services and locations.
Sentiment analysis
Understand how experiences and perceptions are changing over time.
Recommended actions
Turn recurring feedback into practical areas for management attention and improvement.
Human oversight
Keep authorised people responsible for interpretation, review and action.
Evidence designed around the way care quality is assessed.
Pulse helps care providers collect and organise timely evidence around the CQC’s five key questions: Safe, Effective, Caring, Responsive and Well-led.
Configurable question sets, dashboards, audit records and reporting can be aligned with relevant quality statements, organisational policies and underpinning best-practice guidance.
Safe
Surface concerning patterns, unusual activity and experiences that may require investigation or action.
Effective
Track feedback, trends and improvement over time to help demonstrate whether services are achieving better outcomes.
Caring
Capture direct evidence of kindness, empathy, dignity, respect and the difference individual staff members make.
Responsive
Make it easier for people to share their experiences in the moment, then identify where teams need to respond or adapt.
Well-led
Give leaders a timely, auditable view of culture, quality, performance and improvement across teams and locations.
Supporting evidence categories
Pulse can strengthen several evidence categories used within the CQC assessment approach, particularly:
- People's experience of health and care services
- Feedback from staff and leaders
- Processes
- Outcomes
Dashboards turn this evidence into measurable indicators that can support governance meetings, quality reviews, inspection preparation and continuous-improvement planning.
Important clarification
Pulse does not replace a CQC assessment, statutory records or professional judgement. It helps organisations build a stronger, more current evidence base but cannot guarantee a particular inspection outcome or rating.
Accessible, mobile-first journeys.
Pulse is designed around accessible, mobile-first journeys, with accessibility testing continuing as the product develops.
The feedback process is designed to be clear and concise. Reviewers can scan a QR code and complete the journey on their smartphone without downloading an app or creating an account.
Responsive layouts, focused questions and straightforward navigation help reduce barriers to participation across different devices and levels of digital confidence.
- No reviewer app required
- Mobile-first QR journey
- Clear, focused interaction
- Responsive across screen sizes
- Continuing accessibility testing and improvement
Secure without becoming difficult to deploy.
Pulse can be introduced without a complex systems project. QR journeys, configured staff records and role-based dashboards allow organisations to begin collecting feedback without requiring an immediate integration.
For larger or more connected deployments, optional APIs can support integration with HRIS, LMS, shift-scheduling, business-intelligence and data-warehousing platforms.
Security and governance remain central as the deployment expands.
No-integration deployment
Begin with QR journeys and configured user records, without connecting Pulse to core organisational systems.
Secure APIs
Exchange agreed information through controlled and authenticated integration points.
Centralised identity
Single sign-on can support existing organisational identity and account-management processes.
Scoped permissions
Limit each integration and user account to the information required for its defined purpose.
Auditable change history
Maintain records of important user, configuration and system changes.
Independent oversight at board level.

Mark Frost serves as thankyü’s Cyber and Compliance NED, providing independent oversight and strategic advice across cyber security, compliance, technology risk and digital assurance.
Mark has more than 25 years’ experience across IT, digital transformation, cyber security, governance and business assurance. His experience includes supporting organisations across UK Government, Ministry of Defence and Ministry of Justice environments.
His role helps ensure that security and compliance remain board-level responsibilities rather than purely technical considerations.
Professional credentials
- MCIIS: Member of the Chartered Institute of Information Security
- CSTM: Cyber Scheme Team Member
- Cyber Essentials Plus Lead Assessor
- Defence Cyber Certification Auditor
- ISO/IEC 27001 Lead Auditor
- ISO 9001 Lead Implementer
- Professional training in ethical hacking
A stronger evidence base, protected from capture to decision.
Pulse gives organisations more than a stream of comments.
It creates a secure and auditable route from real-world experience to operational evidence, combining proactive review-integrity checks, controlled access, responsible analysis and regulatory alignment.
The result is feedback that can be collected at scale, trusted by leaders and used responsibly to recognise staff and improve care.
Frequently asked questions
Where is Pulse data hosted?
Pulse operates on AWS infrastructure configured for UK data residency. Pulse data is hosted on UK soil.
Is thankyü certified to recognised security standards?
Yes. thankyü holds Cyber Essentials Plus and ISO/IEC 27001 certification.
How does Pulse detect fraudulent reviews?
Pulse uses a proprietary two-stage review-integrity process. Checks run when a review is submitted, followed by further automated assessment of activity patterns. The system considers combinations of technical and behavioural signals without publicly disclosing the thresholds or detection rules.
What happens when a review is flagged?
A high-risk review is separated from trusted reporting and referred to the technical team for manual assessment. It does not contribute to trusted organisational totals while it remains under review.
Does fraud detection depend on names or email addresses?
No. Personal details can support the review-integrity process, but Pulse can also use other permitted technical and behavioural signals when identifying information is unavailable.
Any personal details collected through the review journey are provided directly by the reviewer.
Can reviewers submit feedback anonymously?
The Pulse journey can support anonymous feedback where this is enabled within the organisation's configuration.
Who can access fraud-detection data?
Detailed fraud-detection signals and the manual review workflow are restricted to the technical team. Other users receive access according to their role and organisational permissions.
How does Pulse support CQC compliance?
Pulse helps organisations collect structured and timely evidence aligned with the CQC's five key questions, relevant quality statements and several evidence categories. It supports compliance preparation and continuous improvement but does not replace a CQC assessment or guarantee a rating.
Does Pulse use AI to make decisions about staff?
Pulse uses AI to surface themes, sentiment, patterns and recommended actions for authorised users. These outputs support management judgement rather than replacing it.
Is Pulse accessible?
Pulse is designed around accessible, mobile-first journeys, with accessibility testing continuing as the product develops.
Can Pulse integrate with our existing systems?
Yes. Optional APIs can support HRIS, LMS, shift-scheduling, business-intelligence and data-warehousing platforms. Pulse can also be introduced without an integration for simpler initial deployments.