Trust and security

We ask you to prove your data layer. Here is ours.

Every system Fortis runs, every vendor that could touch client information, and the commitments we make about your environment. Published because a firm that sells provability should be able to demonstrate it.

Ask a security question
Public Trust Eligibility  ·  Federal Civilian
DoD Secret  ·  Founder, active
U.S. persons only  ·  No offshore delivery

This page states the trust posture plainly, including the gaps. Fortis does not hold SOC 2 or ISO 27001 certification. What it has instead is leadership that has spent a career working inside FedRAMP, FISMA, DoD RMF, HIPAA and SOX boundaries, and a firm built to the same standards those programs enforce. The controls and boundaries that apply to an engagement are documented before it starts.

If your procurement process requires a certified provider, tell us early.

01

Subprocessors

Third parties that could process, store or transmit information relating to an engagement. Vendors that handle only Fortis business administration, such as banking and website hosting, are not listed because no client information passes through them.

VendorPurposeData locationClient data
Amazon Web ServicesCloud infrastructure Development, testing and demonstration environments. Client production workloads run in the client's own accounts, not ours. United States Possible, by agreement
Zoho CorporationMail and CRM Business email and contact records. Holds names, business contact details and correspondence. United States Contact data only
AtlassianWork tracking and documentation Internal project tracking and runbooks. Engagement notes may reference a client environment at a general level. United States Engagement notes
Lucid SoftwareArchitecture diagramming Diagrams and design artifacts. May depict a client environment at an architectural level. United States Architecture artifacts
TailscalePrivate network access Coordination and device identity for engineering access. Traffic is end-to-end encrypted and not visible to the vendor. United States Access metadata only
AnthropicGenAI API Used in Fortis internal GenAI development work. Not used on client data or controlled information without written authorization. United States Not without written consent
Current as of 26 August 2026  ·  Clients are notified before a new subprocessor is introduced to an active engagement
02

How we work in your environment

The operational commitments that apply to every engagement, written down so they can be held to rather than assumed.

  • Least privilege by defaultWe ask for the narrowest access that lets the work happen, request read-only where reading is sufficient, and expect access to be revoked when an engagement ends.
  • Your accounts, your controlWork happens in your cloud accounts and your tooling wherever possible. Credentials are never stored outside a managed secret store.
  • Change through code, not consolesInfrastructure and configuration change is delivered as code through your pipeline, so every change is reviewable, attributable and reversible.
  • No production data leaves your estateAnalysis happens where the data lives. Client data stays in the client environment. Fortis does not copy it to its own systems.
  • Synthetic data for anything we build for ourselvesDemonstrations, reference builds and internal testing use synthetic or public data only.
  • U.S. persons onlyAll work is performed inside the United States by U.S. persons. No offshore delivery, no subcontracted labor without your written agreement.
  • Written before signedScope, access requirements and data handling are agreed in writing before an engagement starts, including a business associate agreement where one applies.
  • Prior client confidentiality holdsWhat we learned somewhere else stays there. The patterns travel; the architecture, the configuration and the client name never do.
03

Compliance posture

Stated as it actually is, including the gaps. A firm that sells audit evidence should not be vague about its own.

ItemStatusDetail
Entity registration Active North Carolina LLC, formed 7 August 2026. Federal registration in SAM.gov, UEI VK8XPM3RY365. Full entity and registration detail.
Personnel vetting Active Founder holds a Department of Defense Secret clearance and a favorably adjudicated Public Trust position sensitivity determination, held concurrently. Public Trust is a suitability designation rather than a security clearance. Fortis itself does not currently hold a facility clearance.
Framework fluency Delivered FedRAMP, FISMA, DoD RMF, HIPAA, SOX and SOC 2 environments. Includes remediating a managed database estate against the DoD Database SRG, 142 controls, delivered as infrastructure as code.
Professional and cyber liability In procurement Coverage is being placed. No client engagement will begin before it is bound, and a certificate naming you as additional insured is available on request once it is.
SOC 2 Type II Not held Not certified. Fortis works inside client control environments rather than asking clients to rely on ours.
NIST SP 800-171 self assessment Planned Required for defense subcontracts involving controlled unclassified information. Assessment and SPRS submission planned before any such engagement.
04

Reporting a concern

If you believe Fortis has mishandled information, or you have found a vulnerability in something we built or in this website, tell us directly.

Email info@fortisdatagroup.com or call 910.412.4357. We acknowledge within one business day, and confirm what is known and when you will next hear from us. No disclosure agreement is required to report a concern.

Questions this page does not answer?

Security reviews, vendor questionnaires and data handling requirements are a normal part of getting started. Send yours across and we will complete it honestly, including the parts where the answer is no.

Get in touch