Security at Fortifiers
A factual summary of the controls currently implemented in the platform. Control availability can depend on the deployed environment and contract.
Authenticated sessions
Fortifiers validates signed dashboard sessions and API token issuer and audience before protected requests are accepted.
Workspace-scoped access
Supported customer records and administrative actions are checked against the active organization and role on the server.
Protected integration credentials
Provider credentials are handled by the backend and encrypted when persistent integration storage is required.
Security hardening in progress
We maintain security controls and remediation work, but do not claim an independent compliance certification that has not been completed.
Vulnerability disclosure
If you believe you found a security vulnerability, email security@fortifiers.app. Do not include live customer data, passwords, tokens, or other secrets in the first report.
Compliance requests
Fortifiers does not currently represent that it is SOC 2, HIPAA, GDPR, CCPA, or PIPEDA certified. Contact us for a factual control review and to discuss requirements that may need written contract terms.

