Full transparency on how we use AI: which features use it, exactly what data is sent, what is never shared, and how we comply with UK and EU AI regulations.
EU AI Act
Deployer · Limited / Minimal Risk
UK GDPR
ICO-aligned · Lawful basis documented
Anthropic DPA
Article 28 · SCCs · UK IDTA
Always
Never
With consent only
These tools are built into the portal. You control them from your Account page.
Set a pseudonym for your organisation name. All AI features will use this name instead of your real one — so your organisation identity stays private.
When logging an incident, the form prompts you to use initials (e.g. J.S.) for any named individuals. A private "initials → full names" reference box is stored separately and is never sent to AI.
Before uploading any legal document for AI analysis, you must tick a consent checkbox confirming you understand it will be processed by AI. You can use the full agreements module without ever uploading a document.
Every Fortify feature that uses AI, and exactly what data is involved.
AI chat assistant for cyber security and compliance guidance
Sent to AI
Never sent
AI-powered vendor intelligence and supply chain risk scanning
Sent to AI
Never sent
Generates immediate action plan, notification checklist, and guidance for a logged incident
Sent to AI
Never sent
Drafts cyber security and compliance policies tailored to your organisation
Sent to AI
Never sent
Suggests risks and mitigations relevant to your organisation
Sent to AI
Never sent
Suggests security goals aligned to your sector and compliance goals
Sent to AI
Never sent
Generates a suggested agenda for your leadership review meeting
Sent to AI
Never sent
AI commentary comparing your scores to sector peers
Sent to AI
Never sent
Generates AI-authored staff training content on cyber security topics
Sent to AI
Never sent
Drafts NDAs, DPAs, and service agreements from the details you enter
Sent to AI
Never sent
Extracts key terms from an uploaded contract or legal document
Sent to AI
Never sent
Automatically assigns incident type and severity using AI
Sent to AI
Never sent
Human oversight
Every AI-generated output in Fortify — recommendations, policy drafts, risk suggestions, incident guidance — is presented as a starting point for review. No AI feature in Fortify makes a final decision on your behalf. You review, edit, accept, or reject everything. This is by design.
Policy documents
AI drafts a starting point. You edit and approve before it is used.
Incident action plans
AI generates a suggested list. You implement the steps you judge appropriate.
Risk register
AI suggests risks and mitigations. You add, edit, or remove each entry.
Benchmarks
AI provides commentary on your sector position. You interpret and act on it.
All AI features in Fortify are powered by Claude, made by Anthropic.
Under Article 28 of the UK GDPR and EU GDPR, Anthropic acts as a data processor on Fortify's behalf. They process data only as instructed by Fortify and only for the purpose of generating AI responses. Anthropic does not use your data to train their models (API customers are excluded from training data by default).
Anthropic operates from the United States. Transfers are protected by EU Standard Contractual Clauses (Module 2, Controller-to-Processor), the UK International Data Transfer Addendum (IDTA), and Anthropic's participation in the EU–US Data Privacy Framework.
Anthropic does not retain API inputs or outputs beyond the immediate request–response cycle for non-enterprise API customers. Prompt content is not written to disk as training data. Fortify stores only what it needs to provide the service (e.g. Ask Alex conversation history within your account).
By default, data submitted to Anthropic's API is not used to improve or train their models. This applies to all data Fortify sends. Your incident descriptions, policy content, and any uploaded document text are not used for AI training.
Every AI call has a real compute and energy cost. We built Fortify to avoid unnecessary ones, not just to disclose the ones we make.
Vulnerability analysis, prioritised action lists, remediation guidance, audit pre-population, and sector benchmarks are all generated once and cached — not recreated every time you open the page. Most only regenerate when you explicitly ask for a refresh.
Short, structured tasks — classification, extraction, suggestions — run on Anthropic's smaller, faster Haiku model. The larger Sonnet model is reserved for genuine long-form reasoning, such as writing a full assessment report.
Beyond the core assessment and audit conversations, AI features across the portal only run when you trigger them — generating a brief, requesting suggestions, refreshing a priority list. Nothing calls AI in the background on a page you're simply viewing.
Every AI request sends a bounded amount of data — no open-ended prompts. Usage is also rate-limited per organisation and, on lower tiers, capped to a monthly message allowance, so usage can't run away unchecked.
On the provider side: Anthropic has not published an audited environmental report, so we won't cite a specific carbon or energy figure for Claude — we'd rather say nothing than overstate what we can't verify. What we can point to is that Anthropic was the first standalone AI company to join Frontier, a coalition pre-committing to buy carbon removal ahead of the technology reaching commercial scale.
Regulation
Regulation (EU) 2024/1689 entered into force on 1 August 2024 with phased application. Here is how it applies to Fortify.
The AI Act distinguishes between providers (who build and place AI systems on the market) and deployers (who use AI systems in a professional context). Fortify is a deployer — we use Anthropic's Claude API to power our features. Anthropic is the provider and bears the obligations that fall on providers, including GPAI model documentation obligations that came into force on 2 August 2025. Fortify's obligations as a deployer are more limited and depend on the risk classification of our AI use cases.
Ask Alex — AI assistant
Direct human-to-AI interactions fall under 'limited risk' under Article 50. We are required to disclose that you are interacting with an AI system. We do this through clear product labelling and are preparing for the formal Article 50 transparency requirements that take effect 2 August 2026.
All other AI features
Policy generation, risk register assistance, benchmarks, document analysis, training content, and all other AI features are classified as minimal risk. They do not fall within any Annex III high-risk category — they are analytical and recommendation tools in a B2B professional context, with human review of all outputs.
High-risk categories (Annex III) include biometrics, employment decisions, credit scoring, law enforcement, and administration of justice. None of Fortify's features fall within these categories. Our AI features support organisational cyber security and compliance management, which is not listed in Annex III.
AI literacy (Article 4) — In force
Compliant2 February 2025
We provide training and awareness to staff operating AI features. Prohibited AI practices (Article 5) are not used by Fortify.
GPAI model obligations — In force (Anthropic)
Compliant2 August 2025
These obligations fall on Anthropic as the GPAI model provider. Fortify, as a deployer, is not subject to provider-level obligations.
Full transparency obligations (Article 50) — Preparing
Preparing2 August 2026
We are designing compliant AI disclosure labelling ahead of this date. All AI-interactive features will display clear disclosure at the point of interaction.
Regulation
The UK currently has no equivalent to the EU AI Act. UK AI oversight is sector-based and principles-led, with existing data protection law as the primary framework.
All AI processing of data within Fortify is conducted in accordance with UK GDPR. Where organisational data is sent to AI (such as sector, employee count, or incident descriptions), the lawful basis is legitimate interests (Article 6(1)(f) UK GDPR) — supported by a documented Legitimate Interests Assessment. Our Privacy Notice details all AI processing activities, sub-processors (including Anthropic), and international transfer mechanisms.
The Data (Use and Access) Act 2025 (Royal Assent: 19 June 2025) introduced new automated decision-making provisions that come into force December 2025. The Act explicitly requires that human review of AI outputs must be genuine — not a token gesture. Fortify's design, which requires users to actively review, approve, and edit all AI-generated content before it takes effect, satisfies this requirement. No AI feature in Fortify makes decisions automatically on your behalf.
We follow the ICO's published guidance on AI and data protection, including its requirements on transparency, accuracy caveating, and data minimisation. AI-generated outputs in Fortify are presented as recommendations rather than definitive statements, in line with ICO accuracy guidance for generative AI. The ICO's AI and Automated Decision-Making Code of Practice is expected in 2027; we will align with it when published.
If you have questions about how AI is used, what data is processed, or our regulatory compliance, contact us.