Fortitude.Media
  • Platform
    Fortitude SentinelTrack how four AI engines recommend you and your rivals Fortitude ForgeThe team that moves your score, content, PR and web The VaultYour category's history, recorded before you arrived The whole platformHow Sentinel, Forge and the Vault fit together→
  • Why AI
  • Pricing
  • Insights
    AAI & LLM OptimisationHow AI engines pick brands CContent StrategyTopic depth that earns citations POnline PR & AuthorityEarned signals AI engines trust WWebsite & PerformanceArchitecture for crawlers and humans FThe AI-First FutureVoice, agents, autonomous buying IIndustry GuidesVertical playbooks by sector MMetrics, ROI & Business CaseMeasurement and the board case VCompare: Fortitude vs the alternativesHead-to-head with every named tool View all insights92 guides plus live Vault reports→
  • About
Home / Trust centre
Trust centre

How we handle your data, and keep it safe.

This page summarises Fortitude Media's security and data protection posture for clients, prospects and their security and procurement teams. Full underlying documents are available on request.

Last updated
24 June 2026
On this page
    Security questions?

    Email security@fortitudemedia.ai and a human will reply.

    Fortitude Media takes data protection and security seriously. We handle client data under UK GDPR and apply controls proportionate to the marketing data we process. This page is maintained by Fortitude Media to answer the common security and privacy questions reviewers ask about Sentinel, Forge and the wider Fortitude service.

    Data protection and GDPR

    In most engagements Fortitude Media acts as a data processor on behalf of the client, who remains the controller of any personal data they share with us. We comply with the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

    • Our full Privacy Policy sets out what we collect, why, and your rights.
    • A Data Processing Addendum is available and is signed as part of every client engagement involving personal data.
    • Fortitude Media Limited is registered with the UK Information Commissioner's Office, registration reference ZC136854.

    Sub processors

    We use a small number of reputable providers to deliver the service. Clients receive prior notice of any material change.

    ProviderPurposeRegionSafeguard
    SupabaseApplication database, authentication and file storageEU / USUK IDTA and SCCs where applicable
    VercelHosting, web analytics and monitoring for the Sentinel applicationUS and global edgeUK IDTA and SCCs, EU US Data Privacy Framework
    CloudflareContent delivery and object storage (R2)GlobalUK IDTA and SCCs
    LovableHosting for the public marketing websiteEU / USUK IDTA and SCCs
    PaddlePayments and Merchant of RecordUK / EUUK GDPR, intra UK and EEA
    StripeCard payments, and Merchant of Record where selectedEU / USUK IDTA and SCCs
    GoCardlessDirect debit collectionUK / EUUK GDPR, intra UK and EEA
    ResendTransactional and report email deliveryUS / EUUK IDTA and SCCs
    Google WorkspaceBusiness email, document collaboration and file storageEU / USUK IDTA and SCCs, EU US Data Privacy Framework
    OpenAI, Anthropic, Google, Microsoft, PerplexityAI engines queried to generate reports, using brand and category prompts rather than personal dataUS and globalUK IDTA and SCCs, contractual no-training terms where available

    Not every sub-processor applies to every engagement. Payment providers, for example, apply only to paid Sentinel subscriptions.

    Security measures

    Proportionate, current and actually in place.

    • Least privilege access. Access to client data is restricted to the people who need it for the engagement.
    • Multi factor authentication. MFA is enforced on all accounts that touch client data.
    • Encryption in transit. All client data is exchanged over TLS.
    • Reputable vendor infrastructure. We build on established providers (Google, Cloudflare, our hosting partners) rather than self-hosting sensitive workloads.
    • Data minimisation. We collect and retain only what we need to deliver the service.

    Confidentiality

    Mutual non-disclosure agreements are in place with clients on request, and as standard for Forge engagements. All Fortitude personnel and contractors are under written confidentiality obligations that survive the end of their engagement with us.

    Data handling, retention and breach response

    • Minimum necessary. We only process the data we need to deliver the service the client asked for.
    • Return or deletion on exit. On request, or at the end of the engagement, we return or securely delete client personal data, subject to legal retention obligations such as accounting records.
    • Breach notification. If we become aware of a personal data breach affecting a client, we notify that client without undue delay and in any event within 72 hours of becoming aware, with the information they need to meet their own regulatory obligations.

    International transfers

    We prefer to keep data in the UK and EEA. Where personal data is transferred outside the UK or EEA, we rely on the safeguards required by UK GDPR, including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, and supplementary measures where appropriate.

    Insurance

    Fortitude Media Limited holds the following insurance cover. Certificates are available on request.

    • Professional Indemnity: £1,000,000.
    • Cyber: £500,000.
    • Public Liability: £1,000,000.

    Certifications and roadmap

    Fortitude Media is not currently certified to ISO 27001 or SOC 2. We are a specialist supplier processing low-risk marketing data, and we would rather give a straight answer here than imply otherwise.

    Our internal controls are aligned to the principles of ISO 27001 and the UK National Cyber Security Centre's Cyber Essentials scheme, covering access control, secure configuration, patching, malware protection and user awareness. We will pursue Cyber Essentials certification first, with ISO 27001 considered as our enterprise client base grows and the cost is proportionate.

    Contact and documents

    For any security, privacy or due diligence question, email security@fortitudemedia.ai and a member of the team will reply.

    The following documents are available on request: Privacy Policy (also published at /privacy), Data Processing Addendum template, GDPR Compliance Statement, and insurance certificates.

    Request documentation

    Fortitude.

    The AI visibility company. Sentinel sees it. Forge changes it.

    Fortitude Media Limited, company no. 17191927
    5 Missenden Road, Chesham, England, HP5 1JL
    Part of the Fortitude Group.

    Platform

    • The Platform
    • Fortitude Sentinel
    • Fortitude Forge
    • The Vault
    • Pricing
    • Free visibility check

    Insights

    • AI & LLM Optimisation
    • Content Strategy
    • PR & Authority
    • Website & Performance
    • Industry Guides
    • Compare tools
    • All insights

    Company

    • Why AI
    • About
    • Why Fortitude
    • Methodology
    • Careers
    • Contact

    Legal

    • Privacy policy
    • Terms of use
    • Subscription terms
    • Refund policy
    • Usage Promise
    • Acceptable use
    • Cookies
    • Data processing
    • Trust centre
    • Security
    • Cookie preferences
    © 2026 Fortitude Media Limited. Registered in England, no. 17191927. Privacy · Terms · Refund Sentinel sees it. Forge changes it.