Security Architecture

How Fortress protects institutional keys: layered architecture, client-side key generation, AES-256 at rest, TLS 1.3 in transit and documented security practices.

Physical Security

Layer 1 Air-gapped signing devices. Client-side key generation — keys never touch our servers. Secure key generation ceremonies. Runs on your own hardened hardware.

Application Security

Layer 2 End-to-end encryption (AES-256). Multi-factor authentication. Role-based access control. Session management & timeout.

Network Security

Layer 3 TLS 1.3 everywhere. DDoS protection. Web Application Firewall. IP whitelisting (optional).

Data protection

Data at Rest: AES-256 Encrypted. Data in Transit: TLS 1.3. Key Storage: Client-Side Only. Backup Encryption: Client-side. Data Residency: Switzerland (CH).

Static Security Analysis

RC v3 (March 2026) assessed with Bandit, Semgrep, and pip-audit — zero high or medium severity findings. Independent third-party audit planned.

Responsible Disclosure

RFC 9116 security.txt published across all our domains, with a dedicated channel for security researcher reports

Incident Response

Documented incident response and escalation procedures with defined severity levels

SOC 2 Roadmap

Controls aligned to the SOC 2 Trust Services Criteria; formal certification on our roadmap

GDPR-Ready

Architecture and processes built around EU data protection requirements

ISO 27001-Aligned

Security management practices modeled on ISO 27001; certification planned

Audit Trails

Complete immutable logs for all actions