Rather than make every customer send a spreadsheet, here are the answers. If your form needs
completing on its own template, send it to info@fullpass.ai.
Company
| Question | Answer |
| Legal entity | FULLPASS, Australia — ABN 79 297 751 595 |
| Product | Automated QA for SCORM and Storyline e-learning packages |
| Deployment model | Multi-tenant SaaS |
| Security contact | info@fullpass.ai |
Data handling
| Are customer files stored? | No. Course packages are processed in memory and discarded. Only reports are retained |
| Encryption in transit | TLS 1.2+ throughout, HSTS enabled |
| Encryption at rest | Yes, by the hosting provider, including backups |
| Data residency | European Union (Amsterdam, Netherlands). Note that we are an Australian company hosting in the EU — see the Privacy Policy |
| Retention | Trial 30 days · Solo 180 days · Studio 365 days · Team 365 days. Enforced automatically, daily |
| Deletion on request | Self-service and immediate, from the Account screen |
| Data export | Self-service Excel export of everything held |
| Is customer data used for AI training? | No. Never, under any circumstances |
| Are third-party AI services used? | No. Text and speech analysis of video runs on our own servers |
Access control
| Password storage | bcrypt, cost factor 12 |
| Password policy | Minimum 10 characters; common passwords rejected |
| Multi-factor authentication | Yes — a one-time code emailed to the account on any browser it has not used in the last 30 days. Codes last 10 minutes; five wrong entries end the attempt. Authenticator apps: on the roadmap |
| Single sign-on / SAML | Not yet. Available on request for enterprise agreements |
| Role-based access | Yes — managers and members, with separate visibility of reports |
| Staff access to customer data | Limited to the three named operators of the platform, for support purposes, with actions recorded |
| Session handling | httpOnly, sameSite, secure cookies; all sessions revoked, and every trusted browser forgotten, on password change |
Application security
| Security headers | CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, Referrer-Policy |
| Input handling | Parameterised SQL throughout; upload type and size limits; output escaped |
| Payment data | Never touches our servers. Stripe hosted checkout; PCI scope minimal |
| Dependency policy | Pure JavaScript dependencies only, kept deliberately few |
| Automated testing | Over 300 end-to-end checks across accounts, sign-in, billing, administration, sharing and the analysis engine, run before every change; a further 23 run against Stripe's test API on demand |
Operations
| Backups | Daily automated, with point-in-time recovery |
| RPO / RTO | 24 hours / 8 hours |
| Monitoring | External uptime monitoring; errors alert the team by email |
| Incident notification | Within 72 hours of becoming aware |
| Subprocessors | Listed publicly; 30 days' notice before any change |