Every system Fortis runs, every vendor that could touch client information, and the commitments we make about your environment. Published because a firm that sells provability should be able to demonstrate it.
Ask a security questionThis page states the trust posture plainly, including the gaps. Fortis does not hold SOC 2 or ISO 27001 certification. What it has instead is leadership that has spent a career working inside FedRAMP, FISMA, DoD RMF, HIPAA and SOX boundaries, and a firm built to the same standards those programs enforce. The controls and boundaries that apply to an engagement are documented before it starts.
If your procurement process requires a certified provider, tell us early.
Third parties that could process, store or transmit information relating to an engagement. Vendors that handle only Fortis business administration, such as banking and website hosting, are not listed because no client information passes through them.
| Vendor | Purpose | Data location | Client data |
|---|---|---|---|
| Amazon Web ServicesCloud infrastructure | Development, testing and demonstration environments. Client production workloads run in the client's own accounts, not ours. | United States | Possible, by agreement |
| Zoho CorporationMail and CRM | Business email and contact records. Holds names, business contact details and correspondence. | United States | Contact data only |
| AtlassianWork tracking and documentation | Internal project tracking and runbooks. Engagement notes may reference a client environment at a general level. | United States | Engagement notes |
| Lucid SoftwareArchitecture diagramming | Diagrams and design artifacts. May depict a client environment at an architectural level. | United States | Architecture artifacts |
| TailscalePrivate network access | Coordination and device identity for engineering access. Traffic is end-to-end encrypted and not visible to the vendor. | United States | Access metadata only |
| AnthropicGenAI API | Used in Fortis internal GenAI development work. Not used on client data or controlled information without written authorization. | United States | Not without written consent |
The operational commitments that apply to every engagement, written down so they can be held to rather than assumed.
Stated as it actually is, including the gaps. A firm that sells audit evidence should not be vague about its own.
| Item | Status | Detail |
|---|---|---|
| Entity registration | Active | North Carolina LLC, formed 7 August 2026. Federal registration in SAM.gov, UEI VK8XPM3RY365. Full entity and registration detail. |
| Personnel vetting | Active | Founder holds a Department of Defense Secret clearance and a favorably adjudicated Public Trust position sensitivity determination, held concurrently. Public Trust is a suitability designation rather than a security clearance. Fortis itself does not currently hold a facility clearance. |
| Framework fluency | Delivered | FedRAMP, FISMA, DoD RMF, HIPAA, SOX and SOC 2 environments. Includes remediating a managed database estate against the DoD Database SRG, 142 controls, delivered as infrastructure as code. |
| Professional and cyber liability | In procurement | Coverage is being placed. No client engagement will begin before it is bound, and a certificate naming you as additional insured is available on request once it is. |
| SOC 2 Type II | Not held | Not certified. Fortis works inside client control environments rather than asking clients to rely on ours. |
| NIST SP 800-171 self assessment | Planned | Required for defense subcontracts involving controlled unclassified information. Assessment and SPRS submission planned before any such engagement. |
If you believe Fortis has mishandled information, or you have found a vulnerability in something we built or in this website, tell us directly.
Email info@fortisdatagroup.com or call 910.412.4357. We acknowledge within one business day, and confirm what is known and when you will next hear from us. No disclosure agreement is required to report a concern.
Security reviews, vendor questionnaires and data handling requirements are a normal part of getting started. Send yours across and we will complete it honestly, including the parts where the answer is no.