Skip to content
Remote Fort logo

Remote Fort B.V.

Trust Center

How we secure the platform we ask customers to trust.

Program reviewed · 19 Aug 2026

Report a vulnerability

Public trust center

Remote Fort runs the same bar we help customers meet.

This is the security, privacy, and compliance record of Remote Fort B.V.—the Amsterdam company behind the product. Formal reports that require an NDA are available to customers and serious prospects. Operational controls below are monitored as part of our ISMS.

Controls passing

57 / 57

Passing

Customer data region

EU (Frankfurt)

AWS

Contracting entity

Remote Fort B.V.

19 Aug 2026

Control ledger

A sample of currently passing tests. Open Controls for the full catalog, including ISO 27001, SOC 2, GDPR, and TISAX mappings.

View all controls →
  1. AC-01

    MFA on every workforce account

    SSO with phishing-resistant or TOTP MFA. Shared passwords for production systems are prohibited.

    ISO 27001SOC 2TISAX

    Passing

  2. AC-02

    MFA and SSO for cloud consoles

    AWS and other admin consoles require SSO plus MFA. Root credentials are vaulted and used only for break-glass.

    ISO 27001SOC 2AWS

    Passing

  3. AC-03

    Role-based access, least privilege

    Production roles are scoped by job function. Standing admin access is not granted by default.

    ISO 27001SOC 2TISAX

    Passing

  4. AC-04

    Quarterly access reviews

    Owners attest that each production and SaaS role is still required. Orphaned accounts are revoked.

    ISO 27001SOC 2

    Passing

  5. AC-05

    Joiner–mover–leaver within 24 hours

    New hires get the minimum role. Movers are recertified. Leavers lose production and email access the same business day.

    ISO 27001SOC 2GDPR

    Passing

  6. AC-06

    Privileged activity is logged

    Assume-role events, production deploys, and datastore access are written to the audit trail.

    ISO 27001SOC 2

    Passing

  7. AC-07

    Admin session timeouts

    Idle and absolute timeouts on administrative surfaces. Re-authentication required for sensitive actions.

    ISO 27001SOC 2

    Passing

  8. AC-08

    Unique IDs — no shared prod logins

    Every human and service account is uniquely attributable. Generic admin users are not used in production.

    ISO 27001SOC 2TISAX

    Passing