Vendor drift
Classified material changes to FusionAuth’s public trust documents, from continuous monitoring.
Data as of 2026-09-22 — refreshed on a rolling bake, not live. · fusionauth.io
Documents are silent on training
as of 2026-09-22
medium · Terms changed · 2026-09-22 · privacy_policy
FusionAuth's privacy policy changed its notification channels for policy updates from email and on-page notice to on-page notice only. The policy now states that if any changes are made, FusionAuth will notify users by revising the "Effective Starting" date at the top of the Privacy Policy, whereas it previously said it would provide additional notice, such as by sending an email notification.
medium · Terms changed · 2026-09-15 · dpa
FusionAuth's DPA removed several security controls from its security controls listing, including the Automated Backup Process, Complex Passwords, Personnel Acknowledge Security Policies, Advisor Meetings on Security, and Organizational Chart controls, and renamed one control to Information Security Program Review. This weakens the vendor's stated security commitments (notably backup and password/authentication controls) in a document covering customer data.
medium · Terms changed · 2026-09-07 · dpa
FusionAuth's DPA added several new security controls/commitments, including approval for system changes, an automated backup process, personnel acknowledging security policies, advisor meetings on security, retention of customer data procedures, encryption-in-transit, complex passwords, and a description of services. The compliance and subprocessor sections were converted from images to text (AWS remains the sole subprocessor), so no subprocessor or AI-related change occurred.
Paste your vendor list, confirm your email, and our engine builds your report automatically — the material changes across your vendors in the last 12 months, which of them added AI subprocessors or reserved the right to train on your data, and where your nth-party exposure concentrates. Free, delivered during your working day.