Legal

Privacy policy

Last updated August 2026. Fortify Core Inc. operates the drift detection and remediation platform described at fortifycore.io. This policy explains what we collect, why, and what control you keep.

1. Who we are

Fortify Core Inc., 2261 Market Street, San Francisco, CA. For customers in the EEA and UK we act as processor for infrastructure data you route through the platform and as controller for account and billing records. Contact: privacy@fortifycore.io.

2. Data we collect

Account data: name, work email, organisation, role, authentication identifiers and, for paid plans, billing contact details handled by our payment processor.

Infrastructure metadata: resource identifiers, attribute values returned by refresh-only Terraform plans, severity classifications, remediation pull request references and the actions your team takes on each finding.

Product telemetry: pages visited, features used, error traces and performance timings, collected in aggregate to operate and improve the service.

3. Data we deliberately do not collect

We do not store cloud secrets, private keys, database contents or your application data. Values flagged as sensitive by the Terraform provider, and values matching known secret patterns, are redacted at ingest before anything is written to disk. We do not buy data about you, and we never sell or share personal data for advertising.

4. Why we process it

To provide the service you contracted for (performance of a contract); to keep the platform secure and prevent abuse (legitimate interests); to comply with tax, accounting and legal obligations; and, where required, on the basis of your consent, which you can withdraw at any time.

5. Sharing

We share data with the sub-processors listed on our sub-processors page, each under written data protection terms. We disclose data to authorities only where legally compelled, and we notify you unless prohibited by law.

6. Security

TLS 1.3 in transit, AES-256-GCM at rest, isolated production environments, mandatory multi-factor authentication and least-privilege access for staff, continuous dependency scanning and annual third-party penetration testing. Details on the security page.

7. Retention

Drift history follows your plan's retention setting — 30 days on Team, one year on Scale, configurable on Enterprise. Account records are kept for the life of the subscription and for 90 days afterwards. Invoices are retained for seven years to meet tax obligations. Deleting a workspace purges associated records within 30 days and backups within a further 60.

8. International transfers

Data is hosted in the United States and Ireland. Transfers out of the EEA and UK rely on the European Commission's standard contractual clauses and the UK addendum. EU-only data residency is available on the Enterprise plan.

9. Your rights

Depending on where you live you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. California residents may request disclosure of categories collected and opt out of sharing — we do not sell or share personal information as those terms are defined by the CCPA. Email privacy@fortifycore.io and we respond within 30 days. You may also complain to your local supervisory authority.

10. Cookies

We use a small set of strictly necessary, preference and aggregate analytics cookies, all documented in the cookie policy. No advertising or cross-site tracking cookies are used.

11. Children

The service is intended for organisations and is not directed to anyone under 16. We do not knowingly collect data from children.

12. Changes

Material changes are announced by email to workspace administrators at least 30 days before they take effect, and the revision date at the top of this page is updated.