Skip to content
SeamSetTalk to us

Security review

The answers your security review needs, on one page

A model writes the code. Every change is tested before it goes live and approved by your NetSuite admin.

By default, what SeamSet builds runs in your NetSuite account

What sits outside your account:

  • SeamSet and the model. SeamSet keeps the code it writes and the log of every change. What the model reads, we go through in your security review.
  • Outside screens. Two cases only: portals, and screens NetSuite's pages handle badly. The Customer Center and Vendor Center need a NetSuite login. For customers and vendors without one, the portal runs outside NetSuite, and each sees only their own records. It keeps no copy of your records.

If you stop using SeamSet, what runs inside NetSuite keeps running; portals stop.

Your admin decides what SeamSet can access

  • Your admin connects SeamSet to your account.
  • Any role that can deploy code holds broad power in NetSuite. That is why every change waits for your admin's approval.
  • When your admin is the one asking, a second approver they name signs off.
  • No admin in-house? Approval goes to whoever holds that role: a controller, an IT lead, or your NetSuite partner.

How a change reaches production

Changes inside NetSuite are SDF projects, with a SeamSet prefix in every object ID, linked to its request.

  1. Describe. Someone describes the need.

  2. SeamSet builds it. Native first: if NetSuite already does it, SeamSet sets it up and writes no code. Otherwise it builds only what is missing: a scheduled export, a custom screen, a portal. Account features stay your admin's switch.

  3. Test it before it goes live. The requester checks a first version, and every change is tested. We go through how in your security review.

  4. Your NetSuite admin approves. Your admin sees each change in plain words, then approves it, sends it back or rejects it. Nobody approves their own request.

Requested by Marta Kovac, controller · Approver: Daan Achterberg, NetSuite admin

At every month-end, holds each journal file until every entry passes the controller's checks, and gives the fix for each failing entry. Posts the file once every entry passes. Removes the old "Batch note" field on journal entries.

  • Adds the check "Hold the file until every entry passes" to journal importscustomscript_seam_0147_hold · customdeploy_seam_0147_hold
    Reversible
  • Adds the field "Check result" on journal entriescustbody_seam_0147_check
    Reversible
  • Removes the old field "Batch note" on journal entriescustbody_batch_note
    Removes stored data
  • Posts the file once every entry passescustomscript_seam_0147_post · customdeploy_seam_0147_postPosted journals are corrected by reversing entries.
    Cannot be undone

Code, folded: 2 scripts · SDF project

ApproveSend backReject

Who asked, who approved, what changed

The log records who asked, who approved, what changed and when. You can export it at any time.

What can be undone, and what cannot

Each line of a change is tagged Reversible, Removes stored data or Cannot be undone. Deleting a custom field, for example, removes the data it holds. Records written and messages sent cannot be undone.

Agreements for your review

Data processing agreement
Signed before SeamSet processes any personal data for you
Subprocessors, including the model provider
Listed in the data processing agreement. We tell you before adding or replacing one

SeamSet works with NetSuite. SeamSet is not affiliated with, sponsored by or endorsed by Oracle.

It goes through the change process you already audit

Each object SeamSet adds is a customization in your account, and each deployment is logged by NetSuite. It arrives with its evidence: the request, the approval, what changed and its documentation.

What we walk you through in a security review

We cover each topic on the call and in your questionnaire, as it stands on that date:

  • What SeamSet can access
  • What the model reads
  • How changes are tested
  • Encryption and key management
  • Token storage and rotation
  • Sign-in and multi-factor authentication
  • Staff access
  • Data residency
  • Model provider terms and training
  • Subprocessors
  • Penetration testing

A named person for your review

Send us your security questionnaire. The founder answers it, not a sales team.

ContactArnaud de Turckheim, [email protected]

Or tell us about one change your teams want in NetSuite. We'll talk through how it would go through your review.