Remote Fort B.V.
Trust Center
How we secure the platform we ask customers to trust.
Program reviewed · 19 Aug 2026
Report a vulnerabilityPublic trust center
Remote Fort runs the same bar we help customers meet.
This is the security, privacy, and compliance record of Remote Fort B.V.—the Amsterdam company behind the product. Formal reports that require an NDA are available to customers and serious prospects. Operational controls below are monitored as part of our ISMS.
Controls passing
57 / 57
Passing
Customer data region
EU (Frankfurt)
AWS
Contracting entity
Remote Fort B.V.
19 Aug 2026

GDPR
Applies
TISAX
Certified

Allianz für Cyber-Sicherheit
Member
PROKS
Certified

ISO 27001:2022
Mapped & monitored

SOC 2 Type II
Mapped & monitored
AWS Security
Mapped & monitored
VAPT
Mapped & monitored
Control ledger
A sample of currently passing tests. Open Controls for the full catalog, including ISO 27001, SOC 2, GDPR, and TISAX mappings.
- AC-01
MFA on every workforce account
SSO with phishing-resistant or TOTP MFA. Shared passwords for production systems are prohibited.
ISO 27001SOC 2TISAXPassing
- AC-02
MFA and SSO for cloud consoles
AWS and other admin consoles require SSO plus MFA. Root credentials are vaulted and used only for break-glass.
ISO 27001SOC 2AWSPassing
- AC-03
Role-based access, least privilege
Production roles are scoped by job function. Standing admin access is not granted by default.
ISO 27001SOC 2TISAXPassing
- AC-04
Quarterly access reviews
Owners attest that each production and SaaS role is still required. Orphaned accounts are revoked.
ISO 27001SOC 2Passing
- AC-05
Joiner–mover–leaver within 24 hours
New hires get the minimum role. Movers are recertified. Leavers lose production and email access the same business day.
ISO 27001SOC 2GDPRPassing
- AC-06
Privileged activity is logged
Assume-role events, production deploys, and datastore access are written to the audit trail.
ISO 27001SOC 2Passing
- AC-07
Admin session timeouts
Idle and absolute timeouts on administrative surfaces. Re-authentication required for sensitive actions.
ISO 27001SOC 2Passing
- AC-08
Unique IDs — no shared prod logins
Every human and service account is uniquely attributable. Generic admin users are not used in production.
ISO 27001SOC 2TISAXPassing