Security review
The answers your security review needs, on one page
A model writes the code. Every change is tested before it goes live and approved by your NetSuite admin. By default, what SeamSet builds runs in your NetSuite account.
- By default, what SeamSet builds runs in your NetSuite account
- Your admin decides what SeamSet can access
- Tested before it goes live, approved by your NetSuite admin, then deployed
- Who asked, who approved, what changed
- What can be undone, and what cannot
- Certifications and documents
- It goes through the change process you already audit
- What we walk you through in a security review
- A named person for your review
By default, what SeamSet builds runs in your NetSuite account
What sits outside your account:
- SeamSet and the model. Both run outside your account. SeamSet keeps the code it writes and the log of every change. What SeamSet can access and what the model reads, we go through in your security review.
- Outside screens. By default, what SeamSet builds runs inside your NetSuite account. Outside for two reasons only: portals for people with no NetSuite login, and screens NetSuite's pages handle badly. A portal reads from your NetSuite account when a customer or vendor opens it, and keeps no copy of your records.
If you stop using SeamSet, what runs inside your NetSuite account keeps running. Portals stop.
Your admin decides what SeamSet can access
- Your admin connects SeamSet to your account and decides what it can access.
- Any role that can deploy code holds broad power in NetSuite. That is why every change waits for your admin's approval.
- Nobody approves their own request: when your admin is the one asking, a second approver they name signs off.
- No admin in-house? Approval goes to whoever holds that role: a controller, an IT lead, or your NetSuite partner.
Tested before it goes live, approved by your NetSuite admin, then deployed
Changes are SDF projects, with a SeamSet prefix in every object ID, linked to its request.
Connect. Your admin connects SeamSet to your account.
Describe. Someone describes the need. SeamSet first checks what NetSuite and your account already do. Native first, with pragmatism. If a native feature covers the need, SeamSet sets it up (a saved search, a workflow, an approval rule), through the same approval, and writes no code. If the native route would cost more to set up and run than the need is worth, SeamSet says so and proposes the lighter option. Account features stay your admin's switch.
Test it before it goes live. Every change is tested before it goes live. We go through how in your security review.
Your NetSuite admin approves. Your admin sees what changes, in plain words, and approves it, sends it back or rejects it. Nothing reaches production without a recorded approval.
Holds this month's journal file until every entry passes the controller's checks, and gives the fix for each failing entry. Posts the file once every entry passes. Removes the old "Batch note" field on journal entries.
- Adds the check "Hold the file until every entry passes" to journal importsReversible
customscript_seam_0147_hold · customdeploy_seam_0147_hold - Adds the field "Check result" on journal entriesReversible
custbody_seam_0147_check - Removes the old field "Batch note" on journal entriesRemoves stored data
custbody_batch_note - Posts the file once every entry passesCannot be undone
customscript_seam_0147_post · customdeploy_seam_0147_postPosted journals are corrected by reversing entries.
Code, folded: 2 scripts · SDF project
Who asked, who approved, what changed
The log records who asked, who approved, what changed and when. SeamSet keeps it, and you can export it at any time. NetSuite also logs each deployment in your account.
What can be undone, and what cannot
Before your admin approves, every line of a change carries one tag: Reversible, Removes stored data or Cannot be undone. Deleting a custom field, for example, removes the data it holds. Records written and messages sent cannot be undone.
Certifications and documents
As of [date], SeamSet holds no security certification or attestation report.
- Data processing agreement
- Shared during your security review, and signed before SeamSet processes any personal data for you
- Subprocessors, including the model provider
- Listed in your security review and in the data processing agreement. We tell you before adding or replacing one
SeamSet works with NetSuite. SeamSet is not affiliated with, sponsored by or endorsed by Oracle.
It goes through the change process you already audit
Each object SeamSet adds is a customization in your account, and each deployment is logged by NetSuite. It arrives with its evidence: the request, the approval, what changed and its documentation.
What we walk you through in a security review
We cover each topic on the call and in your questionnaire, as it stands on that date:
- What SeamSet can access
- What the model reads
- How changes are tested
- Encryption and key management
- Token storage and rotation
- Sign-in and multi-factor authentication
- Staff access
- Data residency
- Model provider terms and training
- Subprocessors
- Penetration testing
A named person for your review
Send us your security questionnaire. The founder answers it, not a sales team.
Contact[Named contact: to be confirmed], security@seamset.com
Or tell us about one change your teams want in NetSuite. We'll talk through how it would go through your review.