Security & Compliance

SOC 2 Type II compliant.
Your data, encrypted and protected.

Brands like HexClad, Mejuri, dbrand, and Wild trust Fulfil with their inventory, orders, and financials. Here's why.

SOC 2

Type II Compliant.

Security controls independently audited and verified as effective over time. Not just designed well, but actually working.

99.9%

Uptime.

Consistent availability your operations depend on. Track it yourself at status.fulfil.io.

AES-256

Encrypted at rest.

All data encrypted at rest and in transit. TLS for every connection.

GCP

Google Cloud.

Multiple US data centers. Physical security, redundancy, and disaster recovery built in.

Compliance

SOC 2 Type II. Not just Type I.

SOC 2 Type I checks whether security controls are designed properly at a single point in time. Type II goes further: it verifies those controls are actually working, consistently, over 6–12 months.

What this means for you

  • An independent auditor verified our security controls are working, not just documented
  • Data handling, access controls, and operational procedures meet the standards your finance and compliance teams expect
  • We undergo regular re-audits to maintain compliance as our systems evolve

Trust Center access

Need our full SOC 2 Type II report for your audit? Merchants can create a support ticket to request access to our Trust Center and complete compliance documentation.

Financial Controls

SOC 1 Type II. For customers with financial reporting requirements.

SOC 1 covers internal controls over financial reporting (ICFR). Type II means those controls have been tested and verified as operating effectively over time, not just documented.

Who needs this

Public companies, PE-backed brands, and any merchant whose auditors need assurance that financial data processed through Fulfil is accurate and protected from unauthorized changes.

How to get the report

Our SOC 1 Type II report is available to merchants on request. Create a support ticket to request access through our Trust Center.

Audits & Training

Independent audits. Annual training.

Regular security reviews across infrastructure, applications, and operational procedures. Plus training for every employee and partner.

01 / AUDITS

Regular security audits.

Independent SOC 1 and SOC 2 Type II audits plus regular security audits with Amazon covering infrastructure, application security, and operational procedures.

02 / PENTEST

Penetration testing.

Regular third-party penetration testing simulating real-world attacks against our infrastructure and application.

03 / TRAINING

Security training.

Annual security training for all Fulfil employees. We also provide training for customers and third-party partners.

Access Control

You control who can access what.

Fulfil gives you the tools to enforce it.

01

Two-Factor Authentication

Enforce 2FA for all employees on your account. Supports authenticator apps and hardware security keys like YubiKeys.

02

Single Sign-On

SSO via Google or Microsoft. One login, centralized access management, fewer passwords to worry about.

03

Role-Based Permissions

Granular access controls so each team member only sees and does what they need to. No more shared admin accounts.

Your Data

Portable. Protected. Yours.

You own your data. We make it accessible and secure.

Data Portability

Full BigQuery dataset export if you leave. Not a CSV dump. Your complete data in a format built for long-term retention and analysis.

GDPR & Data Protection

We work with customers in the EU and UK. We can put in place a Data Processing Addendum (DPA) incorporating Standard Contractual Clauses (SCCs) to facilitate lawful data transfers under GDPR.

Best Practices

What we recommend to every merchant.

Fulfil handles platform security. These are things you should be doing on your end.

01

Credential Management

  • ·Use a password vault like 1Password for all credentials
  • ·Never share API keys or tokens in plain text via email
  • ·Use hardware security keys like YubiKeys where possible
  • ·Enable 2FA and use SSO for all your software
02

Key & Token Hygiene

  • ·Rotate API keys and tokens on a regular schedule
  • ·Rotate immediately when employees with access leave
  • ·Regularly audit the scope of existing API keys
  • ·Downgrade to read-only access where full access isn't needed
03

Access Auditing

  • ·Regularly audit who has access to your accounts
  • ·Remove access for former employees and contractors promptly
  • ·Audit browser extensions being used by employees
  • ·Limit admin-level access to people who truly need it
04

Vulnerability Reporting

  • ·Found a security issue? Report it to security@fulfil.io
  • ·We maintain a responsible vulnerability disclosure program
  • ·Every report is taken seriously and investigated promptly
View vulnerability reporting policy →

FAQ

Security questions. Answered.

Is Fulfil SOC 2 Type II compliant?
Yes. An independent auditor has verified our security controls are not only properly designed but operating effectively over time. Our full SOC 2 Type II report is available through our Trust Center — create a support ticket to request access.
Where is my data hosted?
Fulfil runs on Google Cloud infrastructure across multiple US data centers. All data is encrypted at rest and in transit. Google Cloud provides enterprise-grade physical security, redundancy, and disaster recovery.
Can I export my data if we leave Fulfil?
Yes. You get a full BigQuery dataset export. Not a CSV dump. Your complete data in a format built for long-term retention and analysis.
Does Fulfil support SSO and 2FA?
Yes. You can enforce two-factor authentication for all employees on your account, and use single sign-on via Google or Microsoft for centralized access management.
Does Fulfil support GDPR compliance?
Yes. We work with customers in the EU and UK and can put in place a Data Processing Addendum (DPA) incorporating Standard Contractual Clauses (SCCs) to facilitate lawful data transfers under GDPR. Contact our team to request a DPA.
How do I report a security vulnerability?
We maintain a responsible vulnerability disclosure program. Visit our Vulnerability Reporting page at fulfil.io/responsible-vulnerability-disclosure/ to learn how to report issues to security@fulfil.io.
Does Fulfil go through regular security audits?
Yes. Fulfil undergoes regular security audits with Amazon, regular third-party penetration testing, and maintains SOC 2 Type II compliance through independent auditors. All employees complete annual security training.

Questions about security?
Our team can walk you through it.

We're happy to share compliance documentation and discuss our security practices.