Fullness · Trust CenterUpdated August 31, 2026
Fullness governance

Trust Center · Track. Prove. Unlock.

Controls you can inspect

Fullness is the financial operating system for people and growing businesses. This center publishes the security, privacy, approval, evidence, and responsible-agent controls behind that promise.


Security

Defense in depth

Encryption in transit and at rest, tenant isolation, role-based access, row-level controls, audit records, and release gates protect financial data and consequential actions. Certifications are stated only after they are independently attained and published.

Machine-readable security practices

Privacy

Export, revoke and delete

People and organizations control consent and access. Fullness supports account export, connection revocation, and deletion requests, with retention limited where law or financial-record obligations require it.

Privacy policy · Delete an account · Control summary

Responsible AI

Assistive by default

AI output is not an authoritative accounting, tax, payroll, legal, or credit decision. Tools are capability- and tenant-gated; consequential writes require policy checks and, where configured, approval. External agents cannot approve their own requests.

Responsible AI controls

Approvals and evidence

No silent consequential action

Risk classification, scoped authorization, approval state, idempotency, audit events, and linked evidence travel with supported actions. Denied or unavailable capabilities fail closed.

Approval and evidence contract

Regional controls

Country packs are release-gated

Released payroll baselines and candidate country packs are disclosed separately. Candidate packs remain fail-closed until independent review is recorded; marketing copy does not convert a candidate into a release.

Payroll country-pack availability

Subprocessors

Named service providers

The current privacy disclosure identifies providers used for infrastructure, bank connectivity, payments, communications, distribution, analytics, monitoring, and hosting. The machine-readable register records categories and a review date; the privacy policy remains controlling.

Subprocessor register

Vulnerability reporting

Report security issues privately

Use the published security channel for suspected vulnerabilities. Do not access data that is not yours, disrupt service, or publicly disclose an unresolved issue.

Reporting policy · Service status

Public register

Documents and change dates

PathPurposeUpdatedSignature

Machine-readable manifest · Change log