Security

Security at FullSeam

FullSeam processes customer financial data. Its security program is independently audited.

Compliance
AICPA SOC 2 Compliant
SOC 2 Type 1

Point-in-time audit of control design against the AICPA Trust Services Criteria for Security, Confidentiality, and Availability.

AICPA SOC 2 Compliant
SOC 2 Type 2

Independent audit of the operating effectiveness of those controls over a review period.

HIPAA Compliant
HIPAA

Administrative, physical, and technical safeguards aligned with the HIPAA Security Rule.

Security program

Controls

01

Encryption in transit and at rest

TLS 1.2+ on every connection. Customer data, databases, and backups are encrypted at rest. Secrets are stored in a managed vault, not in source code.

02

Least-privilege access

Production access is limited to authorized personnel, gated by role-based controls, and reviewed periodically. Access is revoked within one business day of a role change.

03

Cloud infrastructure

Isolated VPC on AWS with private application and data tiers, a WAF at the edge, and no public ingress to the database. Production data resides in North America.

04

Vulnerability management

Continuous scanning across source code, dependencies, and infrastructure, plus an annual third-party penetration test. Patches are prioritized by exploitability.

05

Backups

Point-in-time recovery with encrypted backups across multiple availability zones. Backups are monitored for completion and restricted to authorized personnel.

06

Incident response

A documented plan covering identification, escalation, customer notification, and remediation. The plan is reviewed and rehearsed.

Vendor reviews & disclosure

Security package

Contact support@fullseam.com.

Vulnerability reports go to the same address.