Security Architecture
How Fortress protects institutional keys: layered architecture, client-side key generation, AES-256 at rest, TLS 1.3 in transit and documented security practices.
Physical Security
Layer 1 Air-gapped signing devices. Client-side key generation — keys never touch our servers. Secure key generation ceremonies. Runs on your own hardened hardware.
Application Security
Layer 2 End-to-end encryption (AES-256). Multi-factor authentication. Role-based access control. Session management & timeout.
Network Security
Layer 3 TLS 1.3 everywhere. DDoS protection. Web Application Firewall. IP whitelisting (optional).
Data protection
Data at Rest: AES-256 Encrypted. Data in Transit: TLS 1.3. Key Storage: Client-Side Only. Backup Encryption: Client-side. Data Residency: Switzerland (CH).
Static Security Analysis
RC v3 (March 2026) assessed with Bandit, Semgrep, and pip-audit — zero high or medium severity findings. Independent third-party audit planned.
Responsible Disclosure
RFC 9116 security.txt published across all our domains, with a dedicated channel for security researcher reports
Incident Response
Documented incident response and escalation procedures with defined severity levels
SOC 2 Roadmap
Controls aligned to the SOC 2 Trust Services Criteria; formal certification on our roadmap
GDPR-Ready
Architecture and processes built around EU data protection requirements
ISO 27001-Aligned
Security management practices modeled on ISO 27001; certification planned
Audit Trails
Complete immutable logs for all actions