Skip to content
fullCircle GRC

Security

The proof of your security deserves protection.

fullCircle holds some of your most sensitive information. Here's how we protect it — and the independent certifications behind it.

ISO27001CERTIFIEDISO27701CERTIFIEDISO22301CERTIFIED

Certified

We run our program on fullCircle — and get audited on it.

risk3sixty is certified to ISO 27001 (information security), ISO 27701 (privacy) and ISO 22301 (business continuity), and manages that program in fullCircle the same way our clients do.

SSO and MFA

SAML 2.0 single sign-on with any identity provider, plus multi-factor authentication.

Role-based access

Analyst, manager and admin roles, module permissions and assignment-based access to controls and evidence.

Encryption

Sensitive credentials are encrypted at the application level with AES-256 before they're stored.

Malware scanning

Uploaded files pass through malware scanning before they reach your program.

Audit logging

An audit log records user activity across your organization.

AWS infrastructure

Hosted on AWS behind a CDN and web application firewall.

Backups and recovery

Automated backups and a disaster-recovery failover capability.

Segmented tenants

Firms can manage each client in its own sub-organization; dedicated instances are available.

Need our security documentation for a vendor review? Ask your account team, or email support@risk3sixty.com.

Come full circle.

Stop rebuilding compliance for every framework and audit. Run one program — and prove it anytime.

Or see how audit-ready you are