The documents your reviewer will ask for.
Everything Fortoxa can put in front of a procurement or security review is linked below, along with a direct statement of what it cannot. Fortoxa holds no third-party audit report — if your process requires one, that is a blocker today, and it is better read here than found later.
Six pages, all public.
None of these is gated behind a sales call or an NDA. A reviewer can read the whole position before speaking to anyone.
Security posture
Encryption in transit and at rest, credential handling, browser hardening, tenant separation, and where data is processed — each with the basis it rests on.
Subprocessors
Every third party that processes customer data, the role it plays, and where it operates.
Data Processing Agreement
The standard DPA, with UK GDPR and EU GDPR terms and Standard Contractual Clauses.
Compliance mappings
What Cyber Essentials, NCSC CAF, GDPR Article 32 and NIS2 each require, and what Fortoxa produces toward them from your servers.
Service status
When the platform services were last reviewed by hand, and why Fortoxa does not publish an automated status signal.
Responsible disclosure
The security mailbox, testing scope and rules, safe harbour, and the response commitment Fortoxa has not yet set.
Send the questions; you will get answers, not a packet.
Fortoxa does not maintain pre-completed CAIQ, SIG Lite or vendor-risk workbooks. An earlier version of this page said it did. Send the questionnaire or the specific questions and Fortoxa will answer them directly, referencing the pages above — and will say so where the answer is that a control is not in place.