Your documents are your business. Here's how we treat them.
W-9s carry tax IDs. Certificates carry your coverage. We'd rather tell you exactly how they're handled than ask you to assume.
What we can state today
- Encrypted in transit
- Every connection to Fulcrum is HTTPS-only and negotiated at TLS 1.2 or higher. Plain-text requests are redirected, never served.
- Encrypted at rest
- Your documents are stored with AES-256 server-side encryption, enforced at the storage layer so an object cannot be written unencrypted.
- Where it lives
- Fulcrum runs on Amazon Web Services in the United States (US East, Ohio). Your documents do not leave that region.
- Your documents are not training data
- We do not use your documents to train AI models. Fulcrum does let you label and correct what it extracts, and that labeled data may be used to train the models behind the product later — we're telling you before it happens, not after. You can opt out at any time by emailing privacy@smbfulcrum.com, and opting out keeps your data out of training entirely without changing how you use Fulcrum.
- Access is scoped to your company
- Every request is bound to your company's tenant. The rare administrative access that crosses that boundary is written to a dedicated security audit log that services are prevented from disabling.
Where we are, honestly
Fulcrum is pre-launch. Formal certification takes time and real operating history, and we'd rather name that than imply a maturity we haven't reached yet. We're building toward SOC 2 with our founding customers' timelines in mind, and we'll publish the target window here once we can commit to it.
If your evaluation needs an answer we haven't published, ask — we'll tell you what's true today rather than what sounds best.