FullSeam handles the financial data your business runs on. We built our security program around that responsibility from day one — independently audited, continuously verified.
Certified
Point-in-time audit of our control design against the AICPA Trust Services Criteria for Security, Confidentiality, and Availability.
Certified
Independently audited for the operating effectiveness of our controls over an extended review period.
Implementing administrative, physical, and technical safeguards aligned with the HIPAA Security Rule.
TLS 1.2+ on every connection. Customer data, databases, and backups encrypted at rest. Secrets stored in a managed vault — never in source code.
Production access is restricted to a small set of authorized personnel, gated by role-based controls and reviewed on a regular cadence. Access is revoked within one business day of any role change.
Isolated VPC on AWS with private application and data tiers, a WAF at the edge, and no public ingress to the database. Production data stays in North America.
Continuous scanning across source code, dependencies, and infrastructure, plus an annual third-party penetration test. Patches prioritized by exploitability.
Point-in-time recovery with encrypted backups across multiple availability zones. Backups are monitored for completion and restricted to key personnel.
A documented plan covering identification, escalation, customer notification, and remediation — kept current and rehearsed.
We're happy to share our SOC 2 report, security questionnaire, or DPA under NDA. Reach out to support@fullseam.com and we'll respond within one business day.
Found a vulnerability? Please disclose it responsibly to the same address.