Skip to content
Remote Fort logo

Remote Fort B.V.

Trust Center

How we secure the platform we ask customers to trust.

Program reviewed · 19 Aug 2026

Report a vulnerability

Buyers ask

Short answers for the questionnaire you were about to send.

If something is not listed, email security@remotefort.com. Do not run unauthenticated scans against customer tenants or shared infrastructure.

Where is customer data stored?+

Primary tenant data is stored in AWS eu-central-1 (Frankfurt). Backups stay in-region. Listed subprocessors may process limited personal data outside that region only with a DPA and a transfer mechanism (usually SCCs).

How is data encrypted?+

In transit: TLS 1.2 or higher. At rest: AES-256 via AWS-managed encryption and KMS for application keys. Company endpoints use full-disk encryption and MDM.

Who at Remote Fort can see my tenant?+

Support and engineering access is least-privilege, SSO + MFA, and logged. We do not browse customer evidence as a matter of course. Production access is time-bound and reviewed.

Are you SOC 2 and ISO 27001 certified?+

We operate an ISMS mapped to ISO/IEC 27001:2022 and the SOC 2 Trust Services Criteria, and we monitor the controls on this page. TISAX, Allianz für Cyber-Sicherheit, and PROKS are company marks we hold. Formal SOC 2 Type II and ISO attestation packages are released to customers and qualified prospects under NDA—request them from Documents. We do not treat this public ledger as a substitute for those reports.

Do you pentest?+

Yes. An independent firm tests at least annually. The executive summary is in the NDA pack. Please do not run your own unauthenticated scans against shared infrastructure or other customers’ tenants.

How do you notify subprocessor changes?+

Material additions are posted here and emailed to the security contact on file with at least 30 days’ notice, unless a shorter window is required to contain an incident. Your DPA governs objection rights.

Do you train models on our data?+

Customer tenant content is not used to train general-purpose foundation models. AI features that draft control answers or questionnaire text run against your workspace under the DPA. We do not sell customer data.

How fast will you tell us about a breach?+

If a personal-data breach affects your tenant, we notify you in line with GDPR Article 33/34 duties as processor and the timelines in your DPA—without waiting on a marketing review. Availability incidents follow the severity matrix in the incident plan.

What happens when we offboard?+

Export is available during the contract. After termination we delete tenant data from production on the schedule in the DPA; backups then age out on their rolling window. Confirm the date with support@remotefort.com.

How do I report a vulnerability?+

Email security@remotefort.com with a clear description and reproduction notes. Do not access data that is not yours, and do not publicly disclose until we have had a reasonable chance to investigate. We do not offer a cash bounty by default.