Everything a customer, or their security and procurement team, might reasonably ask about how FULLPASS handles their courses and their data — in one place, written from what the system actually does.
The four things that most often decide a security review.
Open access — nothing here is gated behind a request form.
Implemented today. Anything on the roadmap rather than in the product is marked as such on the security questionnaire.
The only third parties involved in running FULLPASS. None of them ever receives a course file. We give 30 days' notice before adding one — see the full list.
Payments, invoices, billing portal
Transactional email — confirmations, sign-in codes, invitations, alerts
Backup transactional email, used only if Resend cannot send
Application hosting and the Postgres database
DNS, and TLS for fullpass.ai
Changes to anything published on this page.
This page, the eight documents behind it and the self-service export and deletion tools went live together. Retention windows are now enforced automatically rather than being a stated intention.
For a security review, a signed DPA naming your organisation, or a completed copy of your own questionnaire, email info@fullpass.ai.
To report a vulnerability, email the same address with "Security" in the subject. We acknowledge within two working days and will not pursue anyone acting in good faith.