Skip to content
FortaRisks

Security and sovereignty by design

We sell to security teams, so we hold ourselves to their standards. Here is how we protect your data.

How we protect your data

  • Canadian residency, outside the CLOUD Act

    Your data is hosted in Canada by default, with a Canadian operator. That is the difference that matters against US vendors: the CLOUD Act lets authorities compel a vendor subject to US law to hand over data it holds, including data hosted abroad. US or EU hosting is available at onboarding depending on your requirements.

  • Encryption and access control

    Encryption in transit and at rest, single sign-on, multi-factor authentication and granular role-based access. Managed-service tenants are isolated at the database level.

  • Monitoring and response

    Audit logging, continuous monitoring, encrypted backups, vulnerability management and a documented incident response process.

  • Privacy and consent

    No fingerprinting and no silent third-party tracking. Analytics and chat load only with your consent. We never sell personal data.

  • Transparent and explainable

    Our risk scoring is decomposable and traceable, not a black box. Recommendations are explainable, and your content is never used to train models for other customers.

  • We meet the frameworks we help you meet

    FortaRisks is run against the standards we measure for you, including SOC 2 and ISO 27001 practices, with audit-ready evidence.

Security controls

  • Encryption in transit and at rest
  • Single sign-on (SSO) and MFA
  • Granular role-based access control
  • Audit logging and monitoring
  • Encrypted backups
  • Vulnerability management
  • Documented incident response
  • Database-level tenant isolation

Where your data lives, and which law reaches it

Data residency is only half the answer. The other half is jurisdictional: the CLOUD Act follows the provider, not the server. Canadian company, Canadian hosting by default, European adequacy, and EU or US hosting available at onboarding.

See our jurisdictional position

What we never do

  • Sell or rent your personal data
  • Train models served to other customers on your content
  • Store your application data outside Canada without your agreement
  • Set a non-essential third-party cookie before your consent
  • Fingerprint your browser
  • Send you to a chatbot instead of a real person

What security teams ask us

Who at FortaRisks can access my data?

Access is role-based and limited to the people who need it to operate the service, with multi-factor authentication and logging. Managed-service tenants are isolated at the database level.

How do I get your security dossier?

On request and under NDA: security dossier, sub-processor list and framework mapping. Write to us and a person answers.

Are you SOC 2 or ISO 27001 certified?

We operate to those practices and measure ourselves against the same frameworks as our customers, with audit-ready evidence. Our security dossier states exactly where we stand, rather than a logo on a page.

Is your scoring a black box?

No. Every score breaks down to its inputs and its exact calculation, and stays exportable with that breakdown. A grade you cannot defend is of no use to you.

Need our security documentation?

Request our security package, sub-processor list and framework mapping under NDA.

Request security docs