FullyRamped logoFullyRamped

FullyRamped Trust Center

FullyRamped is in compliance with security best practices, has implemented and is monitoring comprehensive controls, and maintains policies to outline its security procedures.

Compliance

Resources

SOC 2 Type I Report
ISO 27001 Certificate
SOC 2 Type II Report
Incident Response Policy
Data Retention and Disposal Policy

Controls

Access control procedures
Access review of infrastructure
VPN access
Multifactor authentication
Physical access control systems
Encryption of data
Data protection policy
Data transfers covered by approved safeguards
Data transfer agreement
Cooperation agreements/data sharing frameworks
Source code tool
Business continuity and disaster recovery testing
Web application firewall
Vulnerability scanning
Outsourced Development Management
Intrusion detection tool
Infrastructure baseline hardening policy
SSL/TLS certificates for infrastructure
Network diagram
Monitoring, measurement, analysis and evaluation
Incident response and breach notification policy
Alerts and remediation
Breach notification communication
Security incident list
Internal GDPR compliance assessments performed
Binding corporate rules policy
Whistleblower policy
Rectification request policy
Objection handling policy and systems generated
Log management tool
Vendor management program
Vendor onboarding
Vendor list
Vendor termination
Consent for processing captured via explicit opt-in mechanisms
Age verification and parental/guardian consent process enforced
New employee and contractor agreements
Existing employee and contractor agreements
Customer onboarding
Security awareness training implemented
Employee handbook
Records of Processing Activities (RoPA) maintained
Multi-availability zones
Asset register maintaining
Notification workflows regarding rectification or erasure maintained
Risk management program
Risk and Governance Executive Committee meeting minutes
Lawful basis assessment
Legitimate interest assessment
Patch management
Antivirus and malware configurations
Board charter
Asset register list
Termination checklist