Security
Security is the product. Fortanixor is built for banks and regulated enterprises on a Zero Trust foundation, so protecting customer identities and data is engineered into every layer, from phishing-resistant authentication to encrypted infrastructure and continuous threat detection. This page summarizes the controls behind the platform.
Last updated: August 9, 2026
Zero Trust by design
We assume no implicit trust anywhere in the system. Every request between users, services, and infrastructure is authenticated, authorized, and continuously evaluated against risk signals, and we apply defense-in-depth and least-privilege throughout. Security is treated as a design constraint, not an add-on, so a single failure never exposes customer data.
Phishing-resistant authentication
FortAuth is passkey-based and phishing-resistant. Credentials are bound to the user’s device and to the origin they were created for, and private keys and biometrics never leave the device, so there is no shared secret to phish, replay, or breach at scale. Adaptive, risk-based step-up is applied when signals such as a new device, impossible travel, or elevated risk warrant it.
Encryption
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Encryption keys are managed through a hardened key-management service with strict separation of duties, access logging, and regular rotation. Secrets are never stored in source code or logs.
Access control
Access to production systems is least-privilege, granted just-in-time, and requires phishing-resistant multi-factor authentication over managed devices. Entitlements are reviewed on a regular cadence and revoked promptly when a role changes or access is no longer required. All privileged activity is logged and monitored.
Infrastructure and change management
The platform runs on hardened cloud infrastructure with network segmentation, isolated environments, and infrastructure-as-code so that every change is peer-reviewed, tested, and auditable. Deployments run through automated pipelines with security checks, and production is separated from development and staging. Enterprise customers can deploy on-premise, in the cloud, or hybrid with regional data residency.
Threat detection and monitoring
We continuously monitor for identity and infrastructure threats and correlate risk signals across sign-ins to surface anomalies early. We patch on a defined, severity-based schedule, and run regular vulnerability scans and independent penetration tests. Findings are triaged and remediated against timelines tied to their severity.
Resilience and availability
The platform is designed for high availability with redundancy, horizontal scaling, and safe fallbacks that fail closed rather than fake a success. We maintain backup and recovery processes and test them so that service can be restored within defined objectives.
Secure development
Security is built into our development lifecycle: code review, dependency and secret scanning, automated testing, and threat modeling for significant changes. Engineers receive ongoing security training, and we design new features against our Zero Trust and least-privilege principles.
Incident response
We maintain a documented incident-response plan with defined roles, escalation paths, and customer notification commitments. If an incident affects your data, we will notify you in line with our obligations and provide the information you need. Every incident is followed by a post-incident review whose findings are fed back into the platform.
Compliance and certifications
Our controls are independently validated and mapped to recognized standards, including ISO/IEC 27001 and FIDO2. See our Compliance page for the full list and for how to request reports.
Responsible disclosure
If you believe you have found a vulnerability, report it to security@fortanixor.com. We investigate every report and will not pursue action against good-faith research conducted under our disclosure guidelines.