Trust Center

Data Privacy

Regulated content stays in the customer data plane. In the documented control-plane architecture the service receives decision metadata — classifications, actions, destinations, policy versions — not prompts, secrets, PHI, or privileged text. Audit events carry keyed fingerprints for correlation, never raw matched values.

What Fortaify can access depends on the deployment model. In managed SaaS, Fortaify operators can access account, entitlement, and control-plane metadata; production access is limited and administrative changes to enterprise settings are recorded in an append-only audit log. In self-hosted and air-gapped deployments, Fortaify has no access to customer data unless a documented integration is enabled by the customer.

See the Privacy Policy for consumer data handling, and Enterprise Regulated for contractual data handling.