Security

Security

Security

Fulcrum runs on the policies, client documents, and systems of record that insurance brokerages depend on every day. We built the platform to earn that trust: audited controls, encryption everywhere, and a hard line on how your data is used with AI.

Fulcrum runs on the policies, client documents, and systems of record that insurance brokerages depend on every day. We built the platform to earn that trust: audited controls, encryption everywhere, and a hard line on how your data is used with AI.

Compliance & Certifications

Compliance & Certifications

Compliance & Certifications

SOC 2 Type II

SOC 2 Type II

Fulcrum holds a SOC 2 Type II attestation, independently audited by CertPro against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. Unlike a point-in-time audit, Type II tests our controls over an extended period, so it reflects how the platform actually operates, not just how it’s designed. We complete this audit annually, and our full report is available to customers and prospects on request.

Fulcrum holds a SOC 2 Type II attestation, independently audited by CertPro against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. Unlike a point-in-time audit, Type II tests our controls over an extended period, so it reflects how the platform actually operates, not just how it’s designed. We complete this audit annually, and our full report is available to customers and prospects on request.

Independent penetration testing

Independent penetration testing

A third-party security firm tests Fulcrum’s web application, API, and AI-specific attack surface every year. Every finding gets a named engineering owner and a fixed remediation timeline, from seven days for critical issues down to the normal release cycle for low-severity ones.

A third-party security firm tests Fulcrum’s web application, API, and AI-specific attack surface every year. Every finding gets a named engineering owner and a fixed remediation timeline, from seven days for critical issues down to the normal release cycle for low-severity ones.

HIPAA

HIPAA

Fulcrum supports HIPAA-compliant workflows and maintains safeguards designed to protect sensitive health information. We use encryption, strict access controls, audit logging, and documented security practices to keep protected health information secure throughout its lifecycle. We also work with customers to meet applicable HIPAA requirements, including entering into Business Associate Agreements when appropriate.

Fulcrum supports HIPAA-compliant workflows and maintains safeguards designed to protect sensitive health information. We use encryption, strict access controls, audit logging, and documented security practices to keep protected health information secure throughout its lifecycle. We also work with customers to meet applicable HIPAA requirements, including entering into Business Associate Agreements when appropriate.

What’s next

What’s next

We review new certifications and frameworks as our customers’ and regulators’ requirements evolve, and we’ll add them here as we complete them.

We review new certifications and frameworks as our customers’ and regulators’ requirements evolve, and we’ll add them here as we complete them.

Data Handling & Privacy

Data Handling & Privacy

Data Handling & Privacy

Your data is never used to train AI models

Your data is never used to train AI models

Fulcrum uses two AI providers, OpenAI and Anthropic, and both operate under signed Zero Data Retention agreements. Your prompts, documents, and the AI’s output exist only for the length of the request. They’re never stored by the provider, never used to train or improve their models, and never visible to any other customer. Once a request finishes processing, neither provider retains anything from it.

The one exception: if a customer specifically asked us to fine-tune a model on their own data, we’d only do it with that customer’s explicit consent. Otherwise, nothing you send through Fulcrum ever becomes training data.

Fulcrum uses two AI providers, OpenAI and Anthropic, and both operate under signed Zero Data Retention agreements. Your prompts, documents, and the AI’s output exist only for the length of the request. They’re never stored by the provider, never used to train or improve their models, and never visible to any other customer. Once a request finishes processing, neither provider retains anything from it.

The one exception: if a customer specifically asked us to fine-tune a model on their own data, we’d only do it with that customer’s explicit consent. Otherwise, nothing you send through Fulcrum ever becomes training data.

Encryption, everywhere

Encryption, everywhere

Data at rest is encrypted with AES-256 across every store we use, including the database, document storage, and backups. Everything in transit runs over TLS 1.2+, from your browser to the platform, between our own services, and out to our AI providers and Applied Epic. Key management runs through Google Cloud KMS and falls inside the scope of our SOC 2 audit.

Data at rest is encrypted with AES-256 across every store we use, including the database, document storage, and backups. Everything in transit runs over TLS 1.2+, from your browser to the platform, between our own services, and out to our AI providers and Applied Epic. Key management runs through Google Cloud KMS and falls inside the scope of our SOC 2 audit.

You own your data

You own your data

Everything you put into Fulcrum, and everything Fulcrum produces for you, belongs to you. We claim no ownership over your documents, your configurations, or your work products. Your data is retained for the life of your agreement and deleted from production systems once it ends, and you can delete it yourself at any time before that.

Everything you put into Fulcrum, and everything Fulcrum produces for you, belongs to you. We claim no ownership over your documents, your configurations, or your work products. Your data is retained for the life of your agreement and deleted from production systems once it ends, and you can delete it yourself at any time before that.

Access is scoped and audited

Access is scoped and audited

Access inside Fulcrum is organized by team: your admins decide who can see which accounts, workflows, and documents, and every change is logged. Sign-on runs through your own identity provider over SAML or OIDC, with MFA support, so we never see or store your users’ passwords. On our side, only a small number of engineers can reach production data, only when needed for support or incident response, and every instance of that access is logged and reviewed.

Access inside Fulcrum is organized by team: your admins decide who can see which accounts, workflows, and documents, and every change is logged. Sign-on runs through your own identity provider over SAML or OIDC, with MFA support, so we never see or store your users’ passwords. On our side, only a small number of engineers can reach production data, only when needed for support or incident response, and every instance of that access is logged and reviewed.

Built for enterprise isolation

Built for enterprise isolation

Our standard environment is multi-tenant with strict, server-enforced isolation between customers. For brokerages that need physical separation, we offer a single-tenant option. That’s a fully dedicated GCP project, cluster, database, and storage, with no shared infrastructure at all.

Our standard environment is multi-tenant with strict, server-enforced isolation between customers. For brokerages that need physical separation, we offer a single-tenant option. That’s a fully dedicated GCP project, cluster, database, and storage, with no shared infrastructure at all.