Remote Fort B.V.
Trust Center
How we secure the platform we ask customers to trust.
Program reviewed · 19 Aug 2026
Report a vulnerabilityISMS
Every listed control is currently passing.
IDs follow our internal catalog. Framework tags show where the same control is reused—exactly the model we sell to customers.
- AC-01
MFA on every workforce account
SSO with phishing-resistant or TOTP MFA. Shared passwords for production systems are prohibited.
ISO 27001SOC 2TISAXPassing
- AC-02
MFA and SSO for cloud consoles
AWS and other admin consoles require SSO plus MFA. Root credentials are vaulted and used only for break-glass.
ISO 27001SOC 2AWSPassing
- AC-03
Role-based access, least privilege
Production roles are scoped by job function. Standing admin access is not granted by default.
ISO 27001SOC 2TISAXPassing
- AC-04
Quarterly access reviews
Owners attest that each production and SaaS role is still required. Orphaned accounts are revoked.
ISO 27001SOC 2Passing
- AC-05
Joiner–mover–leaver within 24 hours
New hires get the minimum role. Movers are recertified. Leavers lose production and email access the same business day.
ISO 27001SOC 2GDPRPassing
- AC-06
Privileged activity is logged
Assume-role events, production deploys, and datastore access are written to the audit trail.
ISO 27001SOC 2Passing
- AC-07
Admin session timeouts
Idle and absolute timeouts on administrative surfaces. Re-authentication required for sensitive actions.
ISO 27001SOC 2Passing
- AC-08
Unique IDs — no shared prod logins
Every human and service account is uniquely attributable. Generic admin users are not used in production.
ISO 27001SOC 2TISAXPassing
- CR-01
TLS 1.2+ in transit
Public and private service traffic uses modern TLS. Weak ciphers and plain HTTP on product surfaces are disabled.
ISO 27001SOC 2GDPRPassing
- CR-02
Encryption at rest (AES-256)
Datastores and object storage use provider-managed AES-256. Snapshots inherit encryption.
ISO 27001SOC 2GDPRTISAXPassing
- CR-03
Secrets never live in git
API keys, tokens, and certificates are stored in a managed vault. Secret scanning runs on every push.
ISO 27001SOC 2Passing
- CR-04
Keys in cloud KMS
Application encryption keys are generated and stored in AWS KMS. Rotation follows the key policy.
ISO 27001SOC 2AWSPassing
- CR-05
Full-disk encryption on endpoints
Company laptops require FileVault/BitLocker (or equivalent) before they can reach corporate systems.
ISO 27001SOC 2TISAXPassing
- LG-01
Centralized audit logging
Authentication, authorization, and data-access events from the product and cloud accounts land in a central store.
ISO 27001SOC 2Passing
- LG-02
Log retention of at least 12 months
Security-relevant logs are retained for a minimum of twelve months to support investigations and Type II evidence windows.
ISO 27001SOC 2Passing
- LG-03
Alerts on anomalous authentication
Impossible travel, repeated failures, and privilege escalation generate paging alerts for on-call.
ISO 27001SOC 2Passing
- LG-04
Trusted time on systems
Production systems synchronize clocks so audit events can be correlated across services.
ISO 27001SOC 2Passing
- LG-05
Log integrity protections
Log destinations restrict delete/modify to a break-glass role. Application roles are write-only.
ISO 27001SOC 2Passing
- VM-01
Dependency scanning on every build
CI fails closed on known-critical issues in application dependencies, with a documented exception path.
ISO 27001SOC 2Passing
- VM-02
Image and infrastructure scanning
Container images and infrastructure definitions are scanned before they are promoted to production.
ISO 27001SOC 2AWSPassing
- VM-03
Independent pentest at least annually
An external firm tests the product and selected infrastructure. Findings are tracked to closure. Summary under NDA.
ISO 27001SOC 2VAPTPassing
- VM-04
Patch SLAs for critical issues
Critical remotely exploitable issues are targeted for mitigation within 72 hours of a stable fix, sooner when feasible.
ISO 27001SOC 2TISAXPassing
- VM-05
Change management for production
Production changes go through reviewed pull requests and CI. Emergency changes are retrospectively documented.
ISO 27001SOC 2Passing
- VM-06
Separated production and staging
Non-production environments do not share credentials or customer data with production.
ISO 27001SOC 2GDPRPassing
- HR-01
Background verification where lawful
Roles with production access are screened in line with Dutch and EU employment law.
ISO 27001SOC 2TISAXPassing
- HR-02
Security awareness on hire and annually
Training covers phishing, data handling, and incident reporting. Completion is tracked.
ISO 27001SOC 2GDPRPassing
- HR-03
Confidentiality and acceptable use
Workforce agreements cover confidentiality, acceptable use, and return of assets at offboarding.
ISO 27001SOC 2Passing
- HR-04
MDM on company devices
Company laptops are enrolled, patchable, and remotely wipeable. Unmanaged devices cannot reach production.
ISO 27001SOC 2TISAXPassing
- HR-05
Screen lock and clean desk
Automatic lock on idle. Sensitive paper and displays are handled as confidential in offices and coworking spaces.
ISO 27001TISAXPassing
- HR-06
Same-day offboarding
Identity, email, vault, and cloud access are revoked as part of a single offboarding checklist.
ISO 27001SOC 2GDPRPassing
- VR-01
Living subprocessor inventory
Processors that may see personal data are listed on this Trust Center and in customer DPAs.
GDPRISO 27001SOC 2Passing
- VR-02
DPA with each processor
No personal data is sent to a processor without a data processing agreement and an assessed transfer mechanism.
GDPRISO 27001Passing
- VR-03
Security review before onboard
Critical vendors are reviewed for encryption, access control, incident process, and subprocessors of their own.
ISO 27001SOC 2TISAXPassing
- VR-04
Annual re-assessment of critical vendors
High-risk processors are recertified at least annually or when their scope materially changes.
ISO 27001SOC 2Passing
- VR-05
30-day notice for material subprocessor changes
Customers are notified of material additions as required by the DPA, with an objection window where contracted.
GDPRPassing
- PR-01
Records of processing
We maintain Article 30 records for controller activities and processor activities on behalf of customers.
GDPRPassing
- PR-02
Customer DPA available
A GDPR data processing addendum is part of the customer contract pack and can be requested from this Trust Center.
GDPRSOC 2Passing
- PR-03
DSAR handling procedure
Privacy requests are logged, verified, and completed within statutory timelines. Tenant DSARs are routed to the customer when we are processor.
GDPRPassing
- PR-04
Retention and deletion schedule
Each personal-data category has a retention rule. Tenant deletion follows the contract and backup TTL.
GDPRISO 27001SOC 2Passing
- PR-05
EU residency for tenant data
Primary customer tenant data is stored in AWS eu-central-1. Exceptions are only listed subprocessors with a transfer tool.
GDPRTISAXPassing
- PR-06
Privacy by design in the SDLC
Features that collect or expose personal data get a lightweight DPIA-style review before launch.
GDPRISO 27001Passing
- SD-01
Mandatory peer review
Production code cannot merge without at least one review from someone other than the author.
ISO 27001SOC 2Passing
- SD-02
CI security gates
Tests, lint, and security scans must pass before deploy. Protected branches block force-push.
ISO 27001SOC 2Passing
- SD-03
SAST and secret scanning
Static analysis and secret detection run in CI. High findings are tracked like any other defect.
ISO 27001SOC 2Passing
- SD-04
Logical tenant isolation
Authorization checks are tenant-scoped. Automated tests cover cross-tenant access attempts.
ISO 27001SOC 2GDPRPassing
- SD-05
Responsible disclosure inbox
security@remotefort.com accepts vulnerability reports. We ask researchers not to access customer data or disrupt service.
ISO 27001SOC 2Passing
- SD-06
Production access only via SSO
Engineers do not SSH with standing keys. Access is identity-aware, MFA-gated, and time-bound.
ISO 27001SOC 2AWSPassing
- RS-01
Automated encrypted backups
Datastores are backed up on a defined schedule, encrypted, and stored in-region.
ISO 27001SOC 2Passing
- RS-02
Restore tests
Restore procedures are exercised on a defined cadence so backups are known to be usable.
ISO 27001SOC 2Passing
- RS-03
Status and customer incident comms
Severity definitions include when and how customers are notified of availability or security incidents.
ISO 27001SOC 2Passing
- RS-04
Capacity and health monitoring
Error rates, latency, and saturation page on-call before customers feel a full outage.
ISO 27001SOC 2Passing
- RS-05
Documented RTO / RPO
Recovery time and recovery point objectives for the production platform are written and reviewed with the ISMS.
ISO 27001SOC 2TISAXPassing
- IR-01
Incident response plan
Roles, severity, evidence handling, and legal notification paths are documented and accessible to on-call.
ISO 27001SOC 2GDPRTISAXPassing
- IR-02
24/7 severity matrix
P1 security and availability events page immediately. Lower severities follow business-hours SLAs.
ISO 27001SOC 2Passing
- IR-03
Customer notification commitments
Personal-data breaches affecting a tenant are notified in line with GDPR and the DPA—without waiting for a marketing review.
GDPRSOC 2Passing
- IR-04
Post-incident reviews
Blameless reviews capture timeline, impact, and corrective actions. Actions are tracked to done.
ISO 27001SOC 2Passing
- IR-05
Annual tabletop exercise
At least once a year we rehearse a security incident with engineering, operations, and a privacy owner.
ISO 27001SOC 2TISAXPassing