FullSeam processes customer financial data. Its security program is independently audited.
Compliant
Point-in-time audit of control design against the AICPA Trust Services Criteria for Security, Confidentiality, and Availability.
Compliant
Independent audit of the operating effectiveness of those controls over a review period.
Administrative, physical, and technical safeguards aligned with the HIPAA Security Rule.
TLS 1.2+ on every connection. Customer data, databases, and backups are encrypted at rest. Secrets are stored in a managed vault, not in source code.
Production access is limited to authorized personnel, gated by role-based controls, and reviewed periodically. Access is revoked within one business day of a role change.
Isolated VPC on AWS with private application and data tiers, a WAF at the edge, and no public ingress to the database. Production data resides in North America.
Continuous scanning across source code, dependencies, and infrastructure, plus an annual third-party penetration test. Patches are prioritized by exploitability.
Point-in-time recovery with encrypted backups across multiple availability zones. Backups are monitored for completion and restricted to authorized personnel.
A documented plan covering identification, escalation, customer notification, and remediation. The plan is reviewed and rehearsed.
Contact support@fullseam.com.
Vulnerability reports go to the same address.