Legal

Data processing addendum

Last updated August 2026. This addendum forms part of the Fortify Core terms of service and applies where we process personal data on your behalf. A counter-signed copy is available on request.

1. Roles and scope

You act as the controller and Fortify Core acts as the processor for personal data contained in account records, audit metadata and infrastructure plan output that you choose to route through the platform. We process that data only to provide the service, to secure it, and to comply with law.

2. Categories of data

Account identity data (name, work email, organisation, authentication identifiers), usage and audit metadata (scan schedules, drift records, actions taken), and technical data present in Terraform plan output. Fortify Core does not require special categories of personal data and asks customers not to submit them.

3. Security measures

Encryption in transit with TLS 1.3 and at rest with AES-256-GCM; least-privilege access with mandatory multi-factor authentication for staff; segregated production environments; automated secret redaction on ingest of plan output; logging of all administrative access; annual penetration testing and continuous dependency scanning.

4. Sub-processing

We engage the providers listed on the sub-processors page under written terms no less protective than this addendum, and we remain responsible for their performance. Customers on annual agreements receive 30 days' notice of additions.

5. International transfers

Where personal data is transferred outside the EEA or UK, transfers are made under the European Commission's standard contractual clauses together with the UK international data transfer addendum, supported by a transfer impact assessment available on request. EU data residency is available on the Enterprise plan.

6. Assistance and data subject rights

We assist you in responding to access, correction, deletion, restriction and portability requests, and in carrying out data protection impact assessments and prior consultations, taking into account the nature of the processing and the information available to us.

7. Personal data breach

We notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with the information reasonably available at the time and updates as the investigation progresses.

8. Retention and deletion

Drift records are retained according to your plan's retention setting. On termination we delete or return customer data within 30 days, except where retention is required by law, and purge encrypted backups within a further 60 days.

9. Audit

On request and no more than once per year, we provide our current third-party audit report and complete a reasonable security questionnaire. On-site audits are available to Enterprise customers subject to confidentiality and reasonable notice.

10. Contact

Data protection enquiries: privacy@fortifycore.io