Institutional controls for institutional data.
This page describes Fortivant's security design intent and current controls. Certifications are represented only where achieved.
Data encrypted in transit and at rest using industry-standard algorithms.
Role-based access controls, per-organization scoping, and least-privilege defaults.
Multi-factor authentication and session management.
Structured activity logging for organizational actions.
Data export and deletion controls at the organization level.
Secure document storage architecture with versioning and access records.
Regional privacy controls and future regional hosting options.
Private workspace data is not used to train public AI models without explicit authorization.
Fortivant is designed for SOC 2-aligned controls. Fortivant does not currently represent that it has completed SOC 2, ISO 27001, HIPAA, FedRAMP, or similar certifications unless separately confirmed in writing.
