Security & trust

Security is our foundation.

As an autonomous security platform, we understand that our customers trust us with their most sensitive security data. That trust is earned through transparency, rigorous security practices, and unwavering commitment to data protection.

Our security principles.

Six core principles that guide every security decision we make

Security by design

Security is embedded into every layer of our platform from day one, not bolted on as an afterthought.
  • Threat modeling during architecture design
  • Secure coding standards and practices
  • Defense in depth architecture
  • Regular security architecture reviews

Data encryption

Your data is encrypted at rest and in transit using industry-standard encryption protocols.
  • AES-256 encryption for data at rest
  • TLS 1.3 for data in transit
  • Encrypted backups and snapshots
  • Key management best practices

Data privacy

We follow strict data minimization principles and give you complete control over your data.
  • Data residency controls
  • EU/UK data subject rights honored (access, portability, deletion)
  • Customer data isolation
  • Data minimization by default

Secure development

Our development practices ensure code security through automation and rigorous review processes.
  • Automated security scanning (SAST/DAST)
  • Dependency vulnerability monitoring
  • Code review requirements
  • Secure CI/CD pipeline

Audit evidence

Every autonomous action is logged with its reasoning, so your auditors can trace what happened and why.
  • Complete audit trail of AI decisions
  • Exportable evidence for your audits
  • Configurable retention windows
  • Data Processing Agreement on request

Transparency & accountability

We believe in radical transparency about our security practices and incident response.
  • Clear security documentation
  • Public security roadmap
  • Incident response plan
  • Regular security updates

Infrastructure security.

Enterprise-grade infrastructure security built for mission-critical operations

Cloud infrastructure

  • Deployed on enterprise-grade cloud infrastructure
  • Multi-region availability for resilience
  • Automated security patching
  • Network segmentation and isolation
  • DDoS protection and WAF

Access control

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA)
  • Audit logging for all access
  • Least privilege principle

Monitoring & response

  • 24/7 security monitoring
  • Automated threat detection
  • Incident response procedures
  • Continuous vulnerability scanning
  • Security event logging

Our commitments to you.

Clear, non-negotiable promises about how we handle your data

We never sell your data. Period. You retain full ownership and control of all security data processed by FortMind.

We collect only what we need to provide our service effectively. No unnecessary data collection or retention.

Export your data anytime in standard formats. No vendor lock-in, no data hostage situations.

Request deletion of your data at any time. We'll remove it from our systems within 30 days.

Ongoing security practices.

Security is not a one-time checklist—it's a continuous commitment

Regular security testing

  • Continuous automated vulnerability scanning
  • Dependency and container scanning in CI
  • Third-party penetration test planned before GA
  • Bug bounty program not yet launched

Engineering practices

  • Security review required on every pull request
  • Least-privilege access to production
  • Secrets managed outside source control
  • Documented incident response plan

Monitoring & detection

  • 24/7 security monitoring and alerting
  • Automated anomaly detection
  • Comprehensive audit logging
  • SIEM integration for security events

Incident response

  • Documented incident response plan
  • On-call rotation for security incidents
  • Transparent communication during incidents
  • Post-incident reviews and improvements

Responsible disclosure.

Found a security vulnerability? We want to hear from you.

We value the security community's efforts to help keep FortMind secure. If you've discovered a security vulnerability, please report it responsibly:

01

Report via email

Send details to security@fortmind.ai
02

Give us time to respond

We'll acknowledge within 48 hours and provide a fix timeline
03

No public disclosure

Please don't disclose publicly until we've had a chance to fix it

Bug bounty program: Coming soon! We're working on launching a formal bug bounty program with rewards for qualifying vulnerabilities.

Questions about our security?

We believe in transparency. If you have questions about our security practices, compliance status, or data handling, we're happy to discuss them.