Request a security review

Security Questionnaire

The answers procurement usually asks for, ready in advance.

Last updated 1 October 2026

Overview Terms Privacy DPA Refunds Security Subprocessors SLA Questionnaire

Rather than make every customer send a spreadsheet, here are the answers. If your form needs completing on its own template, send it to info@fullpass.ai.

Company

QuestionAnswer
Legal entityFULLPASS, Australia — ABN 79 297 751 595
ProductAutomated QA for SCORM and Storyline e-learning packages
Deployment modelMulti-tenant SaaS
Security contactinfo@fullpass.ai

Data handling

Are customer files stored?No. Course packages are processed in memory and discarded. Only reports are retained
Encryption in transitTLS 1.2+ throughout, HSTS enabled
Encryption at restYes, by the hosting provider, including backups
Data residencyEuropean Union (Amsterdam, Netherlands). Note that we are an Australian company hosting in the EU — see the Privacy Policy
RetentionTrial 30 days · Solo 180 days · Studio 365 days · Team 365 days. Enforced automatically, daily
Deletion on requestSelf-service and immediate, from the Account screen
Data exportSelf-service Excel export of everything held
Is customer data used for AI training?No. Never, under any circumstances
Are third-party AI services used?No. Text and speech analysis of video runs on our own servers

Access control

Password storagebcrypt, cost factor 12
Password policyMinimum 10 characters; common passwords rejected
Multi-factor authenticationYes — a one-time code emailed to the account on any browser it has not used in the last 30 days. Codes last 10 minutes; five wrong entries end the attempt. Authenticator apps: on the roadmap
Single sign-on / SAMLNot yet. Available on request for enterprise agreements
Role-based accessYes — managers and members, with separate visibility of reports
Staff access to customer dataLimited to the three named operators of the platform, for support purposes, with actions recorded
Session handlinghttpOnly, sameSite, secure cookies; all sessions revoked, and every trusted browser forgotten, on password change

Application security

Security headersCSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy
Input handlingParameterised SQL throughout; upload type and size limits; output escaped
Payment dataNever touches our servers. Stripe hosted checkout; PCI scope minimal
Dependency policyPure JavaScript dependencies only, kept deliberately few
Automated testingOver 300 end-to-end checks across accounts, sign-in, billing, administration, sharing and the analysis engine, run before every change; a further 23 run against Stripe's test API on demand

Operations

BackupsDaily automated, with point-in-time recovery
RPO / RTO24 hours / 8 hours
MonitoringExternal uptime monitoring; errors alert the team by email
Incident notificationWithin 72 hours of becoming aware
SubprocessorsListed publicly; 30 days' notice before any change