Remote Fort B.V.
Trust Center
How we secure the platform we ask customers to trust.
Program reviewed · 19 Aug 2026
Report a vulnerabilityVendors
Subprocessors that may see personal data on our behalf.
This inventory covers processors used to operate remotefort.com and the Remote Fort platform. Your signed DPA is authoritative if it lists a narrower set. We notify customers of material additions with at least 30 days’ notice where the contract requires it.
| Vendor | Purpose | Data | Location | Transfer | DPA |
|---|---|---|---|---|---|
Amazon Web Services Amazon Web Services EMEA SARL Infrastructure aws.amazon.com | Primary hosting for the Remote Fort platform: compute, datastores, object storage, backups, and KMS in eu-central-1. | Customer tenant content, account data, logs, backups | EU — Frankfurt (eu-central-1) | EU processing · AWS DPA | DPA |
Cloudflare Cloudflare, Inc. Edge & network cloudflare.com | DNS, CDN, TLS, and WAF in front of public web surfaces. Caching of static marketing assets only. | IP addresses, request metadata, static site assets | Global edge · EU routing preferred | SCCs + Cloudflare DPA | DPA |
Google Analytics Google Ireland Limited Analytics analytics.google.com | Measurement of visits to remotefort.com so we can improve the marketing site. Not used inside customer tenants. | Online identifiers, device/browser data, page views | EEA (Google Ireland) with possible US support access | SCCs · Google Ads Data Processing Terms | DPA |
Google Workspace Google Ireland Limited Productivity workspace.google.com | Corporate email, calendar, and documents for Remote Fort staff, including support correspondence. | Business contact data, email content, support attachments | EU data regions for Workspace (as configured) | Google Cloud DPA · SCCs as needed | DPA |
GitHub GitHub, Inc. (Microsoft) Software delivery github.com | Source control, code review, and CI for the Remote Fort product. Customer tenant data is not stored in git. | Source code, issue metadata, workforce identities | United States / Microsoft cloud | SCCs + GitHub DPA | DPA |
Slack Slack Technologies Limited (Salesforce) Communications slack.com | Internal operations chat. Customer names or ticket snippets may appear when staff discuss support issues. | Workforce messages; incidental customer identifiers | Salesforce / Slack cloud (region per workspace) | SCCs + Slack DPA | DPA |
Linear Linear Orbit, Inc. Operations linear.app | Engineering issue tracking. May contain sanitized reproductions or customer-reported defects without bulk tenant exports. | Ticket text, workforce identities, occasional customer names | United States | SCCs + Linear DPA | DPA |
Notion Notion Labs, Inc. Operations notion.so | Internal ISMS documentation, runbooks, and company wiki. Not a store of customer evidence files. | Internal docs; limited personal data of staff and contacts | United States / AWS | SCCs + Notion DPA | DPA |
Stripe Stripe Payments Europe, Limited Payments stripe.com | Subscription billing when a customer pays Remote Fort by card. Card numbers are captured by Stripe, not stored by us. | Billing contact, company name, truncated payment metadata | EEA (Stripe Payments Europe) with US support entities | SCCs + Stripe DPA | DPA |
Material change notice: 30 days, unless a shorter window is required to address a security incident.