Security at Fortifiers

A factual summary of the controls currently implemented in the platform. Control availability can depend on the deployed environment and contract.

Authenticated sessions

Fortifiers validates signed dashboard sessions and API token issuer and audience before protected requests are accepted.

Workspace-scoped access

Supported customer records and administrative actions are checked against the active organization and role on the server.

Protected integration credentials

Provider credentials are handled by the backend and encrypted when persistent integration storage is required.

Security hardening in progress

We maintain security controls and remediation work, but do not claim an independent compliance certification that has not been completed.

Vulnerability disclosure

If you believe you found a security vulnerability, email security@fortifiers.app. Do not include live customer data, passwords, tokens, or other secrets in the first report.

Compliance requests

Fortifiers does not currently represent that it is SOC 2, HIPAA, GDPR, CCPA, or PIPEDA certified. Contact us for a factual control review and to discuss requirements that may need written contract terms.