Skip to content
Remote Fort logo

Remote Fort B.V.

Trust Center

How we secure the platform we ask customers to trust.

Program reviewed · 19 Aug 2026

Report a vulnerability

ISMS

Every listed control is currently passing.

IDs follow our internal catalog. Framework tags show where the same control is reused—exactly the model we sell to customers.

57 / 57 passing10 groups
  1. AC-01

    MFA on every workforce account

    SSO with phishing-resistant or TOTP MFA. Shared passwords for production systems are prohibited.

    ISO 27001SOC 2TISAX

    Passing

  2. AC-02

    MFA and SSO for cloud consoles

    AWS and other admin consoles require SSO plus MFA. Root credentials are vaulted and used only for break-glass.

    ISO 27001SOC 2AWS

    Passing

  3. AC-03

    Role-based access, least privilege

    Production roles are scoped by job function. Standing admin access is not granted by default.

    ISO 27001SOC 2TISAX

    Passing

  4. AC-04

    Quarterly access reviews

    Owners attest that each production and SaaS role is still required. Orphaned accounts are revoked.

    ISO 27001SOC 2

    Passing

  5. AC-05

    Joiner–mover–leaver within 24 hours

    New hires get the minimum role. Movers are recertified. Leavers lose production and email access the same business day.

    ISO 27001SOC 2GDPR

    Passing

  6. AC-06

    Privileged activity is logged

    Assume-role events, production deploys, and datastore access are written to the audit trail.

    ISO 27001SOC 2

    Passing

  7. AC-07

    Admin session timeouts

    Idle and absolute timeouts on administrative surfaces. Re-authentication required for sensitive actions.

    ISO 27001SOC 2

    Passing

  8. AC-08

    Unique IDs — no shared prod logins

    Every human and service account is uniquely attributable. Generic admin users are not used in production.

    ISO 27001SOC 2TISAX

    Passing

  9. CR-01

    TLS 1.2+ in transit

    Public and private service traffic uses modern TLS. Weak ciphers and plain HTTP on product surfaces are disabled.

    ISO 27001SOC 2GDPR

    Passing

  10. CR-02

    Encryption at rest (AES-256)

    Datastores and object storage use provider-managed AES-256. Snapshots inherit encryption.

    ISO 27001SOC 2GDPRTISAX

    Passing

  11. CR-03

    Secrets never live in git

    API keys, tokens, and certificates are stored in a managed vault. Secret scanning runs on every push.

    ISO 27001SOC 2

    Passing

  12. CR-04

    Keys in cloud KMS

    Application encryption keys are generated and stored in AWS KMS. Rotation follows the key policy.

    ISO 27001SOC 2AWS

    Passing

  13. CR-05

    Full-disk encryption on endpoints

    Company laptops require FileVault/BitLocker (or equivalent) before they can reach corporate systems.

    ISO 27001SOC 2TISAX

    Passing

  14. LG-01

    Centralized audit logging

    Authentication, authorization, and data-access events from the product and cloud accounts land in a central store.

    ISO 27001SOC 2

    Passing

  15. LG-02

    Log retention of at least 12 months

    Security-relevant logs are retained for a minimum of twelve months to support investigations and Type II evidence windows.

    ISO 27001SOC 2

    Passing

  16. LG-03

    Alerts on anomalous authentication

    Impossible travel, repeated failures, and privilege escalation generate paging alerts for on-call.

    ISO 27001SOC 2

    Passing

  17. LG-04

    Trusted time on systems

    Production systems synchronize clocks so audit events can be correlated across services.

    ISO 27001SOC 2

    Passing

  18. LG-05

    Log integrity protections

    Log destinations restrict delete/modify to a break-glass role. Application roles are write-only.

    ISO 27001SOC 2

    Passing

  19. VM-01

    Dependency scanning on every build

    CI fails closed on known-critical issues in application dependencies, with a documented exception path.

    ISO 27001SOC 2

    Passing

  20. VM-02

    Image and infrastructure scanning

    Container images and infrastructure definitions are scanned before they are promoted to production.

    ISO 27001SOC 2AWS

    Passing

  21. VM-03

    Independent pentest at least annually

    An external firm tests the product and selected infrastructure. Findings are tracked to closure. Summary under NDA.

    ISO 27001SOC 2VAPT

    Passing

  22. VM-04

    Patch SLAs for critical issues

    Critical remotely exploitable issues are targeted for mitigation within 72 hours of a stable fix, sooner when feasible.

    ISO 27001SOC 2TISAX

    Passing

  23. VM-05

    Change management for production

    Production changes go through reviewed pull requests and CI. Emergency changes are retrospectively documented.

    ISO 27001SOC 2

    Passing

  24. VM-06

    Separated production and staging

    Non-production environments do not share credentials or customer data with production.

    ISO 27001SOC 2GDPR

    Passing

  25. HR-01

    Background verification where lawful

    Roles with production access are screened in line with Dutch and EU employment law.

    ISO 27001SOC 2TISAX

    Passing

  26. HR-02

    Security awareness on hire and annually

    Training covers phishing, data handling, and incident reporting. Completion is tracked.

    ISO 27001SOC 2GDPR

    Passing

  27. HR-03

    Confidentiality and acceptable use

    Workforce agreements cover confidentiality, acceptable use, and return of assets at offboarding.

    ISO 27001SOC 2

    Passing

  28. HR-04

    MDM on company devices

    Company laptops are enrolled, patchable, and remotely wipeable. Unmanaged devices cannot reach production.

    ISO 27001SOC 2TISAX

    Passing

  29. HR-05

    Screen lock and clean desk

    Automatic lock on idle. Sensitive paper and displays are handled as confidential in offices and coworking spaces.

    ISO 27001TISAX

    Passing

  30. HR-06

    Same-day offboarding

    Identity, email, vault, and cloud access are revoked as part of a single offboarding checklist.

    ISO 27001SOC 2GDPR

    Passing

  31. VR-01

    Living subprocessor inventory

    Processors that may see personal data are listed on this Trust Center and in customer DPAs.

    GDPRISO 27001SOC 2

    Passing

  32. VR-02

    DPA with each processor

    No personal data is sent to a processor without a data processing agreement and an assessed transfer mechanism.

    GDPRISO 27001

    Passing

  33. VR-03

    Security review before onboard

    Critical vendors are reviewed for encryption, access control, incident process, and subprocessors of their own.

    ISO 27001SOC 2TISAX

    Passing

  34. VR-04

    Annual re-assessment of critical vendors

    High-risk processors are recertified at least annually or when their scope materially changes.

    ISO 27001SOC 2

    Passing

  35. VR-05

    30-day notice for material subprocessor changes

    Customers are notified of material additions as required by the DPA, with an objection window where contracted.

    GDPR

    Passing

  36. PR-01

    Records of processing

    We maintain Article 30 records for controller activities and processor activities on behalf of customers.

    GDPR

    Passing

  37. PR-02

    Customer DPA available

    A GDPR data processing addendum is part of the customer contract pack and can be requested from this Trust Center.

    GDPRSOC 2

    Passing

  38. PR-03

    DSAR handling procedure

    Privacy requests are logged, verified, and completed within statutory timelines. Tenant DSARs are routed to the customer when we are processor.

    GDPR

    Passing

  39. PR-04

    Retention and deletion schedule

    Each personal-data category has a retention rule. Tenant deletion follows the contract and backup TTL.

    GDPRISO 27001SOC 2

    Passing

  40. PR-05

    EU residency for tenant data

    Primary customer tenant data is stored in AWS eu-central-1. Exceptions are only listed subprocessors with a transfer tool.

    GDPRTISAX

    Passing

  41. PR-06

    Privacy by design in the SDLC

    Features that collect or expose personal data get a lightweight DPIA-style review before launch.

    GDPRISO 27001

    Passing

  42. SD-01

    Mandatory peer review

    Production code cannot merge without at least one review from someone other than the author.

    ISO 27001SOC 2

    Passing

  43. SD-02

    CI security gates

    Tests, lint, and security scans must pass before deploy. Protected branches block force-push.

    ISO 27001SOC 2

    Passing

  44. SD-03

    SAST and secret scanning

    Static analysis and secret detection run in CI. High findings are tracked like any other defect.

    ISO 27001SOC 2

    Passing

  45. SD-04

    Logical tenant isolation

    Authorization checks are tenant-scoped. Automated tests cover cross-tenant access attempts.

    ISO 27001SOC 2GDPR

    Passing

  46. SD-05

    Responsible disclosure inbox

    security@remotefort.com accepts vulnerability reports. We ask researchers not to access customer data or disrupt service.

    ISO 27001SOC 2

    Passing

  47. SD-06

    Production access only via SSO

    Engineers do not SSH with standing keys. Access is identity-aware, MFA-gated, and time-bound.

    ISO 27001SOC 2AWS

    Passing

  48. RS-01

    Automated encrypted backups

    Datastores are backed up on a defined schedule, encrypted, and stored in-region.

    ISO 27001SOC 2

    Passing

  49. RS-02

    Restore tests

    Restore procedures are exercised on a defined cadence so backups are known to be usable.

    ISO 27001SOC 2

    Passing

  50. RS-03

    Status and customer incident comms

    Severity definitions include when and how customers are notified of availability or security incidents.

    ISO 27001SOC 2

    Passing

  51. RS-04

    Capacity and health monitoring

    Error rates, latency, and saturation page on-call before customers feel a full outage.

    ISO 27001SOC 2

    Passing

  52. RS-05

    Documented RTO / RPO

    Recovery time and recovery point objectives for the production platform are written and reviewed with the ISMS.

    ISO 27001SOC 2TISAX

    Passing

  53. IR-01

    Incident response plan

    Roles, severity, evidence handling, and legal notification paths are documented and accessible to on-call.

    ISO 27001SOC 2GDPRTISAX

    Passing

  54. IR-02

    24/7 severity matrix

    P1 security and availability events page immediately. Lower severities follow business-hours SLAs.

    ISO 27001SOC 2

    Passing

  55. IR-03

    Customer notification commitments

    Personal-data breaches affecting a tenant are notified in line with GDPR and the DPA—without waiting for a marketing review.

    GDPRSOC 2

    Passing

  56. IR-04

    Post-incident reviews

    Blameless reviews capture timeline, impact, and corrective actions. Actions are tracked to done.

    ISO 27001SOC 2

    Passing

  57. IR-05

    Annual tabletop exercise

    At least once a year we rehearse a security incident with engineering, operations, and a privacy owner.

    ISO 27001SOC 2TISAX

    Passing