Status labels are deliberate and are the only claims we make:
- SOC 2 — readiness in progress / planned. No SOC 2 report or certification exists. We are working through a readiness roadmap (policies, risk assessment, logging, access reviews, evidence collection). Completing readiness work does not confer certification.
- Independent penetration test — planned. No third-party penetration test has been performed. Results will be summarized here only when a report exists and its scope and dates are approved for sharing.
- HIPAA — architecture supports isolation; BAA where applicable after legal review. There is no HIPAA certification (no such certification exists). Healthcare deployments require a qualifying contract, BAA review, PHI-authorized destination approvals, and enforcement controls. Where Fortaify never receives PHI, responsibilities differ materially.
Compliance artifacts (for example SOC 2 reports or penetration test attestations) are published with status, scope, issue/expiry dates, and reviewer only after the artifact exists and its wording is approved. No badge on this page implies a certification that has not completed that process.