Remote Fort B.V.
Trust Center
How we secure the platform we ask customers to trust.
Program reviewed · 19 Aug 2026
Report a vulnerabilityArchitecture
EU-hosted product. Least-privilege operations. No shadow IT in the data path.
Production workloads run in AWS eu-central-1. The public site is statically exported and served at the edge. Customer tenant data does not leave the EU region we contract for, except where a listed subprocessor is required to complete a specific function and a transfer mechanism is in place.
01 · Edge
TLS termination and abuse protection
HTTPS only, modern cipher suites, DNS and WAF in front of public surfaces. No customer evidence files at this layer.
02 · EU region
AWS eu-central-1 application and data plane
Encrypted disks, IAM-scoped roles, private networking for data stores, backups in-region. Tenant isolation enforced in application and storage layers.
03 · Operations
Amsterdam operator, SSO + MFA to production
Remote Fort B.V. staff reach production through SSO, MFA, and time-bound roles. Secrets live in a managed vault. Laptops are MDM-enrolled with disk encryption.