Skip to content
FortaRisks

Security and sovereignty by design

We sell to security teams, so we hold ourselves to their standards. Here is how we protect your data.

How we protect your data

  • Data residency in Canada

    Your data is hosted in Canada by default. United States or European Union hosting is available at onboarding. No application data leaves the region you choose.

  • Encryption and access control

    Encryption in transit and at rest, single sign-on, multi-factor authentication and granular role-based access. Managed-service tenants are isolated at the database level.

  • Monitoring and response

    Audit logging, continuous monitoring, encrypted backups, vulnerability management and a documented incident response process.

  • Privacy and consent

    No fingerprinting and no silent third-party tracking. Analytics and chat load only with your consent. We never sell personal data.

  • Transparent and explainable

    Our risk scoring is decomposable and traceable, not a black box. Recommendations are explainable, and your content is never used to train models for other customers.

  • We meet the frameworks we help you meet

    FortaRisks is run against the standards we measure for you, including SOC 2 and ISO 27001 practices, with audit-ready evidence.

Security controls

  • Encryption in transit and at rest
  • Single sign-on (SSO) and MFA
  • Granular role-based access control
  • Audit logging and monitoring
  • Encrypted backups
  • Vulnerability management
  • Documented incident response
  • Database-level tenant isolation

Need our security documentation?

Request our security package, sub-processor list and framework mapping under NDA.

Request security docs