Skip to content
SeamSetTalk to us

Security review

The answers your security review needs, on one page

A model writes the code. Every change is tested before it goes live and approved by your NetSuite admin. By default, what SeamSet builds runs in your NetSuite account.

By default, what SeamSet builds runs in your NetSuite account

What sits outside your account:

  • SeamSet and the model. Both run outside your account. SeamSet keeps the code it writes and the log of every change. What SeamSet can access and what the model reads, we go through in your security review.
  • Outside screens. By default, what SeamSet builds runs inside your NetSuite account. Outside for two reasons only: portals for people with no NetSuite login, and screens NetSuite's pages handle badly. A portal reads from your NetSuite account when a customer or vendor opens it, and keeps no copy of your records.

If you stop using SeamSet, what runs inside your NetSuite account keeps running. Portals stop.

Your admin decides what SeamSet can access

  • Your admin connects SeamSet to your account and decides what it can access.
  • Any role that can deploy code holds broad power in NetSuite. That is why every change waits for your admin's approval.
  • Nobody approves their own request: when your admin is the one asking, a second approver they name signs off.
  • No admin in-house? Approval goes to whoever holds that role: a controller, an IT lead, or your NetSuite partner.

Tested before it goes live, approved by your NetSuite admin, then deployed

Changes are SDF projects, with a SeamSet prefix in every object ID, linked to its request.

  1. Connect. Your admin connects SeamSet to your account.

  2. Describe. Someone describes the need. SeamSet first checks what NetSuite and your account already do. Native first, with pragmatism. If a native feature covers the need, SeamSet sets it up (a saved search, a workflow, an approval rule), through the same approval, and writes no code. If the native route would cost more to set up and run than the need is worth, SeamSet says so and proposes the lighter option. Account features stay your admin's switch.

  3. Test it before it goes live. Every change is tested before it goes live. We go through how in your security review.

  4. Your NetSuite admin approves. Your admin sees what changes, in plain words, and approves it, sends it back or rejects it. Nothing reaches production without a recorded approval.

Requested by Marta Kovac, controller · Approver: Daan Achterberg, NetSuite admin

Holds this month's journal file until every entry passes the controller's checks, and gives the fix for each failing entry. Posts the file once every entry passes. Removes the old "Batch note" field on journal entries.

  • Adds the check "Hold the file until every entry passes" to journal importscustomscript_seam_0147_hold · customdeploy_seam_0147_hold
    Reversible
  • Adds the field "Check result" on journal entriescustbody_seam_0147_check
    Reversible
  • Removes the old field "Batch note" on journal entriescustbody_batch_note
    Removes stored data
  • Posts the file once every entry passescustomscript_seam_0147_post · customdeploy_seam_0147_postPosted journals are corrected by reversing entries.
    Cannot be undone

Code, folded: 2 scripts · SDF project

ApproveSend backReject

Who asked, who approved, what changed

The log records who asked, who approved, what changed and when. SeamSet keeps it, and you can export it at any time. NetSuite also logs each deployment in your account.

What can be undone, and what cannot

Before your admin approves, every line of a change carries one tag: Reversible, Removes stored data or Cannot be undone. Deleting a custom field, for example, removes the data it holds. Records written and messages sent cannot be undone.

Certifications and documents

As of [date], SeamSet holds no security certification or attestation report.

Data processing agreement
Shared during your security review, and signed before SeamSet processes any personal data for you
Subprocessors, including the model provider
Listed in your security review and in the data processing agreement. We tell you before adding or replacing one

SeamSet works with NetSuite. SeamSet is not affiliated with, sponsored by or endorsed by Oracle.

It goes through the change process you already audit

Each object SeamSet adds is a customization in your account, and each deployment is logged by NetSuite. It arrives with its evidence: the request, the approval, what changed and its documentation.

What we walk you through in a security review

We cover each topic on the call and in your questionnaire, as it stands on that date:

  • What SeamSet can access
  • What the model reads
  • How changes are tested
  • Encryption and key management
  • Token storage and rotation
  • Sign-in and multi-factor authentication
  • Staff access
  • Data residency
  • Model provider terms and training
  • Subprocessors
  • Penetration testing

A named person for your review

Send us your security questionnaire. The founder answers it, not a sales team.

Contact[Named contact: to be confirmed], security@seamset.com

Or tell us about one change your teams want in NetSuite. We'll talk through how it would go through your review.