Five modules that act, two views that decide
Posture, Compliance, CTI, EASM and TPRM are five complete products: each detects, scores and drives remediation in its own domain, continuously. Two cross-module views then serve two audiences on the same foundation: the Risk Engine carries the decisions of CISOs, executives and risk managers; the Action Center carries the prioritized work queue for operational teams. What one module detects feeds both views. One platform, not seven tools.
Security posture
A guided assessment, one question per control, against the framework that matters to you. You get an A-F grade and a CMMI maturity level from 0 to 5. No external questionnaire to start, and no misleading composite score: posture measures operational risk, compliance measures regulatory risk.
- A-F
- Posture grade
- 0 to 5
- CMMI maturity
- 40+
- Frameworks assessable natively

Compliance
A single baseline of 1,534+ SCF controls acts as the pivot language: a control validated once advances every framework that requires it. Each framework shows its real compliance rate, materiality, readiness, gap count and a compliance path costed in person-days.
- 40+
- Frameworks covered
- 1,534+
- Pivot SCF controls
- person-days
- Costed roadmap

Threat Intelligence
50M+ IOCs and 100+ sources, correlated every day and filtered to what targets your country, sector and stack. Pull IOCs and YARA rules to block threats proactively, before they reach you.
- 100+
- Intelligence sources
- 2,000+
- Threat actors tracked
- 50M+
- Correlated IOCs

Attack Surface
See your entire external attack surface the way an attacker does, monitored continuously. Domains, services, certificates, leaked data and look-alike domains, plus the OT/ICS protocols generic scanners miss, all in read-only.
- 500+
- Finding types
- 15+
- OT/ICS ports monitored
- 30 min
- To full surface

Third-Party Risk
The questionnaire your vendor fills in, continuously cross-checked against a scan of their real attack surface. The gap between what they declare and what their surface shows becomes an explicit signal, and the scan covers a perimeter they validated themselves, so it can be challenged and re-run after remediation.
- 7 days
- To first alert
- 0 to 100
- Vendor score, A+ to F
- 500+
- Finding types per vendor

Risk Engine
No questionnaire to get started: the register feeds continuously from the five modules and from your integrations, across a taxonomy of 9 domains and 52 sub-domains. Every risk carries its inherent and residual level, and the residual is derived from controls instead of being typed in by hand.
- 5
- Modules correlated
- 30 sec
- Board briefing
- 30/60/90
- Day trajectory

30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.