Request a security review

Trust Center

Everything a customer, or their security and procurement team, might reasonably ask about how FULLPASS handles their courses and their data — in one place, written from what the system actually does.

Overview Documents Controls Subprocessors Updates

Overview

The four things that most often decide a security review.

Course files are never storedPackages are analysed in memory and discarded when the scan ends. Only the report is kept.
Hosted in the European UnionApplication and database in Amsterdam, Netherlands, encrypted at rest and reachable only from the application.
No content leaves our serversText and speech inside your videos are read on our own machines, not by an external AI service.
Retention is enforced, not promisedReports are deleted automatically. Trial 30 days · Solo 180 days · Studio 365 days · Team 365 days.

Documents

Open access — nothing here is gated behind a request form.

Controls

Implemented today. Anything on the roadmap rather than in the product is marked as such on the security questionnaire.

Infrastructure

  • Application and database hosted in the European Union
  • Database encrypted at rest and reachable only from the application
  • Automated daily backups with point-in-time recovery, retained 7 days
  • HTTPS everywhere, with HSTS and an automatic redirect from HTTP
  • External uptime monitoring; errors raise an alert to the team

Access control

  • Passwords hashed with bcrypt at cost factor 12, never stored or logged in the clear
  • A code sent to the account's email is needed to sign in on a new browser
  • Minimum ten characters, with common passwords rejected
  • Sessions held in an httpOnly, sameSite, secure cookie
  • Every other session is revoked when a password changes
  • Sign-in cannot be used to discover who holds an account
  • Role-based visibility — members see their own reports, managers see the organisation’s
  • Staff access limited to the three named operators of the platform

Product security

  • Content Security Policy, X-Frame-Options, X-Content-Type-Options, Permissions-Policy and Referrer-Policy
  • Parameterised SQL throughout; upload type and size limits; output escaped
  • Rate limiting on the endpoints that send mail
  • Stripe webhooks verified against their signature before being acted on
  • Card details never reach our servers — payment is taken on Stripe’s hosted page
  • Over 300 automated end-to-end checks across accounts, sign-in, billing, administration, sharing and the analysis engine run before every change ships
  • Pure-JavaScript dependencies, kept deliberately few

Data and privacy

  • Course files are held in memory for the life of the request and never written to disk
  • Text and speech inside videos are analysed on our own servers — no content is sent to any external AI service
  • Product analytics are first-party: no cookie, no device identifier, no IP address, and no third-party analytics service
  • Reports are deleted automatically at the end of the plan’s retention window (Trial 30 days · Solo 180 days · Studio 365 days · Team 365 days)
  • Customers can export everything we hold without contacting us
  • Customers can delete their account and all its data without contacting us
  • Shared report links expire after 30 days and can be revoked instantly
  • Subprocessors published, with 30 days’ notice before the list changes
  • Security incidents notified within 72 hours of our becoming aware

Subprocessors

The only third parties involved in running FULLPASS. None of them ever receives a course file. We give 30 days' notice before adding one — see the full list.

Stripe

Payments, invoices, billing portal

Data processed
Name, email, billing address, card details (entered directly with Stripe — never through us)
Region
US / EU
Resend

Transactional email — confirmations, sign-in codes, invitations, alerts

Data processed
Recipient name and email, message content
Region
US / EU
SMTP2GO

Backup transactional email, used only if Resend cannot send

Data processed
Recipient name and email, message content
Region
EU
Railway

Application hosting and the Postgres database

Data processed
All stored account data and reports
Region
European Union
Cloudflare

DNS, and TLS for fullpass.ai

Data processed
Connection metadata only
Region
Global

Updates

Changes to anything published on this page.

Trust Center

Trust Center published

Published 23 September 2026

This page, the eight documents behind it and the self-service export and deletion tools went live together. Retention windows are now enforced automatically rather than being a stated intention.

Questions, or reporting a vulnerability

For a security review, a signed DPA naming your organisation, or a completed copy of your own questionnaire, email info@fullpass.ai.

To report a vulnerability, email the same address with "Security" in the subject. We acknowledge within two working days and will not pursue anyone acting in good faith.