Cyber Essentials · NCSC CAF · GDPR Article 32 · NIS2

Every security claim you make, with the evidence attached.

Fortoxa monitors your servers and turns what it sees into a control register your assessor can read: each requirement, the artifact that satisfies it, the system it came from, and when it was collected. Including the requirements you have not covered yet.

The register above is a Business feature, £349/month. Monitoring and the live activity feed start at £29. Starter and Business include a 14-day trial on a new subscription.

Cyber Essentials

4 of 5 evidenced

  • Firewalls

    Boundary and host firewall configuration

    Blocked inbound connections, per host, with timestamps

    log_events · 4 min ago

    Live
  • Secure config

    Devices configured to reduce vulnerability

    Host configuration baseline and drift since last check

    fortoxa-agent · 1 day ago

    Stale
  • Updates

    Security update management

    Installed patch level per monitored host

    fortoxa-agent · 11 min ago

    Live
  • Access control

    User access control

    Active accounts and roles, with the date each was granted

    workspace_members · 2 min ago

    Live
  • Malware

    Malware protection

    Endpoint protection status per host

    fortoxa-agent · never collected

    Not configured

Five technical controls, as assessed by an IASME-licensed certification body.

Example workspace, sample data. Your own register is built from your servers once an agent is installed.

What lands in the register

Four artifacts, not a score out of a hundred.

A number tells your assessor nothing they can check. These are the records Fortoxa produces from your own telemetry, and what each one satisfies.

  • Blocked connection log

    Every inbound connection your firewall dropped, with source address, target host and timestamp. Exports as CSV.

    Cyber Essentials: Firewalls · NCSC CAF C1

  • Access register

    Who has an account, what role they hold, when it was granted, and which API keys exist against your workspace.

    Cyber Essentials: User access control · NIS2 21(2)(g)

  • Host configuration baseline

    Patch level and configuration state per monitored server, with the drift since the previous collection.

    Cyber Essentials: Secure configuration, Security update management · NCSC CAF B4

  • Incident timeline

    What was detected, when, what action followed, and who took it — in chronological order, not as a summary.

    NIS2 21(2)(b) · GDPR Article 32(1)(b)

Getting started

One command, then it builds itself.

  1. 01

    Install the agent on one server

    A single command. The agent reads system and auth logs and ships events to your workspace. Nothing else changes on the host.

  2. 02

    Fortoxa builds the register

    Events become artifacts, artifacts map to the requirements of the framework you picked, and every entry keeps the system it came from and the time it was collected.

  3. 03

    Export what your assessor asked for

    Take the register as a PDF or the underlying records as CSV. Each line traces back to a timestamped source, so you can answer "how do you know" without going back to the logs yourself.

What it does not do

The gaps are part of the product.

A register that shows every requirement as satisfied is the failure this exists to prevent. Fortoxa marks what it has not measured, and says why.

  • It does not certify you

    Certification is awarded by an assessor or a certification body. Fortoxa produces the evidence you hand them; it does not replace them, and no output from it is a certificate.

  • It only knows what it can see

    Fortoxa evidences the servers you install the agent on. Anything outside that — laptops, SaaS accounts, physical controls — shows as not measured rather than as a pass.

  • Some requirements are yours to hold

    Backup restoration, staff training records and supplier contracts are not technical telemetry. The register references them and tracks whether they exist; it does not invent them.

Plans

The register starts at £349 a month.

Business is the plan that produces the control register and the evidence export, at £349 for twenty seats. Below that, Micro at £29 and Starter at £99 cover monitoring, alerts and the live activity feed, but not the register. Every limit is published, not negotiated.