This page describes what is actually implemented, not what is aspired to. If something here matters to a procurement process and you need it in writing, email info@fullpass.ai.
The design decision that matters most
Course files are never stored. An uploaded package is held in memory for the life of the request and discarded when the scan finishes. It is not written to disk, not placed in object storage, and not included in any backup. Even when FULLPASS reads the text inside your videos, the video is streamed through the analysis in memory and never lands on a disk. The same goes for a storyboard or brand palette uploaded alongside a course. The only thing retained is the report.
Access and authentication
- Passwords are hashed with bcrypt at cost factor 12 and are never stored or logged in the clear.
- Signing in on a browser the account has not used in the last 30 days needs a six-digit code sent to the account's email, as well as the password. Codes last ten minutes, are stored only as a hash, and five wrong entries end the attempt.
- Sessions use an httpOnly, sameSite cookie, marked secure in production so it cannot travel over plain HTTP.
- Changing a password invalidates every other session on the account and forgets every trusted browser.
- Sign-in gives the same message for an unknown address as for a wrong password, so the form cannot be used to discover who has an account.
- Members see only their own reports. Managers, who are accountable for the account, see all of them.
The application
- Served over HTTPS, with HSTS and an automatic redirect from HTTP.
- Content Security Policy,
X-Content-Type-Options,X-Frame-Options: DENY, a restrictivePermissions-PolicyandReferrer-Policy. - Upload size limits, and rate limiting on endpoints that send mail.
- Stripe webhooks are verified against their signature before being acted on; an unsigned request is rejected.
- Card details never reach our servers. Payment is taken on Stripe's own hosted page.
Data
- Postgres, encrypted at rest by the hosting provider, reachable only from the application.
- Reports are deleted automatically once past the retention period for the plan: Trial 30 days · Solo 180 days · Studio 365 days · Team 365 days.
- Customers can export everything held about them, and delete their account and all its data, without contacting us.
- Shared report links are single-purpose: they open one report, expire after 30 days, can be revoked instantly, and give access to nothing else.
Operations
- Automated daily database backups taken by the hosting provider, with point-in-time recovery.
- A health endpoint monitored externally; errors raise an alert to the team.
- Dependencies are pure JavaScript, which keeps the supply chain small and auditable.
Reporting a vulnerability
Email info@fullpass.ai with "Security" in the subject. We will acknowledge within two working days and keep you informed. Please give us a reasonable opportunity to fix an issue before disclosing it publicly. We will not pursue anyone acting in good faith under this policy.
