Compliance
Fortanixor is built to meet the standards our customers are held to. We maintain independent certifications and align our controls with the regulations that govern financial services and personal data, so identity security and compliance advance together rather than at odds.
Last updated: August 9, 2026
Certifications and attestations
Our security program is validated by independent third parties against recognized standards:
- ISO/IEC 27001: a certified information-security management system (ISMS) covering risk assessment, controls, and continual improvement.
- FIDO2 / FIDO Alliance: certified passwordless, phishing-resistant authentication.
Regulatory alignment
We design and operate the platform to help regulated institutions meet their obligations:
- PCI DSS: controls aligned to payment-card data security for financial workflows.
- GDPR: data processing agreements, data-subject rights, and lawful cross-border transfer mechanisms.
- UAE PDPL: alignment with the UAE Personal Data Protection Law in our home region.
Governance and audit
Role-based audit trails span authentication and AI activity, giving regulated institutions end-to-end visibility for governance, access reviews, and reporting. Logs are tamper-evident and exportable to your SIEM, so you can demonstrate who did what, when, and under which policy, and support internal and external audits with evidence rather than assertions.
Data residency and sovereignty
Enterprise customers can pin data to a specific region and deploy on-premise, in the cloud, or hybrid, so residency and sovereignty requirements are met without a rip-and-replace. This lets institutions keep regulated data within approved jurisdictions while still adopting modern identity security.
Data processing and subprocessors
We enter into data processing agreements with enterprise customers that set out our obligations as a processor. We maintain a current list of the subprocessors that host or support the platform, bind them to obligations no less protective than our own, and provide advance notice of material changes so customers can review them under their agreements. See our Privacy Policy for how personal data is handled.
Vendor due diligence
We support the procurement and risk-assessment processes of regulated buyers with security questionnaires, evidence packages, and reference architectures. Where a standardized questionnaire (such as a CAIQ or SIG) is required, we can typically map our controls to it.
Request documentation
To request our compliance reports, certifications, a data processing agreement, a subprocessor list, or a completed security questionnaire, contact compliance@fortanixor.com.