LegalData & Security
Security Overview
Version 1.0 · Effective 21 July 2026 · Last updated 21 July 2026
Security is a design constraint at Fulcrum, not an afterthought. This page summarizes the controls that protect customer data across the platform.
1. Governance (link to this section)
Security responsibilities are owned at the leadership level, controls are documented, and data is classified so that stricter rules apply to more sensitive information.
2. Encryption (link to this section)
Data is encrypted in transit using TLS and at rest using industry-standard encryption. Especially sensitive fields receive additional protection.
3. Access control (link to this section)
Access follows least privilege, enforced through role-based access control. Multi-factor authentication is required for administrative access. Customer data is isolated per tenant, enforced at the database layer with row-level security.
4. Application and network security (link to this section)
Input validation, security headers, CSRF protection, and dependency scanning are part of the development pipeline. The platform sits behind DDoS protection and a web application firewall.
5. Logging and monitoring (link to this section)
Errors and security-relevant events are logged and monitored, with audit trails for sensitive actions so activity can be reconstructed when needed.
6. Payment security (link to this section)
Payments are fully outsourced to our payment processor. Card data does not touch Fulcrum infrastructure, and payment webhooks are signature-verified.
7. Incident response (link to this section)
We maintain an incident response process with severity levels, defined responsibilities, and customer notification timelines. Personal data breaches are handled as described in the DPA Summary.
8. Testing (link to this section)
We test our own defenses, including penetration testing against recognized methodologies, and fix findings on severity-based timelines.
9. Continuity and backups (link to this section)
Data is backed up regularly and recovery procedures are tested, with defined recovery time and recovery point objectives.
10. Reporting a vulnerability (link to this section)
Found something? We want to know. See the Vulnerability Disclosure Policy, or email [email protected].
Related policies
This policy is issued by Altnativ Pty Ltd (ABN 52 681 839 029), trading as Fulcrum, registered in Victoria, Australia.
Websites: tryfulcrum.ai · www.altnativ.co
Legal contact: Legal and Privacy, Altnativ Pty Ltd, Victoria, Australia. Email [email protected].
© 2026 Altnativ Pty Ltd. All rights reserved.