Security

Your content. Your rules.

The whole product is built around one idea: we work inside your walls, on your terms, and every action is accountable.

Security posture
Deployment
Runs in our cloud or yours: your AWS account or on-prem hosts, hybrid supported. In production deployments, content stays in your environment. Pilot runway A runs single-tenant in Fortify's cloud on archival data you choose, deleted and verified at wrap.
Posture
SOC 2 Type II aligned engineering posture. Designed for MPA content-security best practices. These describe engineering discipline, not third-party certification.
Encryption
AES-256 at rest. TLS 1.3+ in transit.
Identity
Single sign-on (OIDC and SAML 2.0 via the identity broker). Authenticator-app MFA. API keys for machines, with a managed lifecycle. Role-based access control with per-production scoping.
Secrets
A central credential vault for integration keys: envelope-encrypted, versioned, rotatable, grants with expiry, instant revoke, per-action audit.
Audit
Severity-tagged audit logging across operator actions, with batch export to an external sink.
Content protection
Visible watermarking on video, image and document outputs. C2PA Content Credentials signing on image outputs, including an AI-source assertion.
AI posture
Embeddings are computed inside the deployment environment; no calls to external AI APIs for retrieval. Generation can be pinned to local models or to providers you approve. AI-suggested tags and mappings wait for human approval.
Data handling
Read-only by default against your sources; write paths are explicit, opt-in, and land only where you point them. At the end of a pilot: keep everything, or we delete it and verify the deletion.

Found a vulnerability? Email steve@fortifymedia.io with "Security report" in the subject. We read every report and respond fast.