Security
Security & Trust Center
Trust is not a feature. It is the foundation of everything FullyKnow builds.
Security principles
- Protect the individual.
- Privacy and security by design.
- Least privilege.
- Defense in depth.
- Continuous improvement.
Data protection
- Encryption in transit and at rest.
- Secure key management.
- Backups and recovery.
- Data integrity controls.
- Role-based access.
Identity and access
- Multi-factor authentication where available.
- Strong password and session controls.
- Access logging and periodic review.
- Production access limited to authorized personnel with a legitimate need.
Infrastructure and software security
- Network segmentation, hardened configurations, firewalls, and monitoring.
- Secure coding, peer review, dependency scanning, application testing, and release controls.
- Vulnerability management and penetration testing appropriate to maturity and risk.
Monitoring and incident response
FullyKnow seeks to detect, contain, investigate, recover from, and learn from security incidents, and to notify affected parties when required by law.
Third-party risk
Providers are evaluated based on security, privacy, contractual, regulatory, and operational considerations appropriate to their role.
Responsible disclosure
Report suspected vulnerabilities to security@fullyknow.com. Please avoid public disclosure until FullyKnow has had a reasonable opportunity to investigate and address the issue.