Transparency

AI in Fortify

Full transparency on how we use AI: which features use it, exactly what data is sent, what is never shared, and how we comply with UK and EU AI regulations.

EU AI Act

Deployer · Limited / Minimal Risk

UK GDPR

ICO-aligned · Lawful basis documented

Anthropic DPA

Article 28 · SCCs · UK IDTA

The short version

Always

  • ✓ AI outputs are recommendations only
  • ✓ You make all final decisions
  • ✓ Org-level data only (no individual PII) in standard use
  • ✓ You can set an AI pseudonym for your org name

Never

  • ✕ Your name or email address
  • ✕ Employee names, emails, or roles
  • ✕ Customer personal data
  • ✕ Private initials-to-name reference notes
  • ✕ Documents without your explicit consent

With consent only

  • ⚑ Legal document text (you tick a consent checkbox before each upload)

Your privacy controls

These tools are built into the portal. You control them from your Account page.

AI pseudonym

Set a pseudonym for your organisation name. All AI features will use this name instead of your real one — so your organisation identity stays private.

Incident initials

When logging an incident, the form prompts you to use initials (e.g. J.S.) for any named individuals. A private "initials → full names" reference box is stored separately and is never sent to AI.

Document upload consent

Before uploading any legal document for AI analysis, you must tick a consent checkbox confirming you understand it will be processed by AI. You can use the full agreements module without ever uploading a document.

Feature-by-feature breakdown

Every Fortify feature that uses AI, and exactly what data is involved.

Ask Alex

AI chat assistant for cyber security and compliance guidance

When you send a message in Ask Alex

Sent to AI

  • →Organisation name (or pseudonym)
  • →Sector
  • →Employee count
  • →Compliance goal
  • →Conversation messages you type

Never sent

  • ✕Your name or email
  • ✕Employee personal data
  • ✕Customer data

Ask Scout

AI-powered vendor intelligence and supply chain risk scanning

When you run a Scout scan on a vendor

Sent to AI

  • →Organisation name (or pseudonym)
  • →Vendor / supplier name
  • →Publicly available web search results

Never sent

  • ✕Your employees' details
  • ✕Contract values
  • ✕Internal vendor assessments

Incident AI assist

Generates immediate action plan, notification checklist, and guidance for a logged incident

Automatically after you log a new incident

Sent to AI

  • →Organisation name (or pseudonym)
  • →Sector
  • →Incident description (as you wrote it)

Never sent

  • ✕Your name or email
  • ✕Private name reference (initials → names mapping)
  • ✕Personal data of affected individuals unless you include it in the description
We recommend using initials (e.g. J.S.) for any named individuals in incident descriptions.

Policy generation

Drafts cyber security and compliance policies tailored to your organisation

When you create or regenerate a policy

Sent to AI

  • →Organisation name (or pseudonym)
  • →Sector
  • →Employee count
  • →Compliance goal

Never sent

  • ✕Employee names or roles
  • ✕Customer data
  • ✕Financial data

Risk register AI assist

Suggests risks and mitigations relevant to your organisation

When you request AI suggestions in the Risk Register

Sent to AI

  • →Organisation name (or pseudonym)
  • →Sector
  • →Employee count
  • →Compliance goal

Never sent

  • ✕Individual employee data
  • ✕Financial data

Security objectives

Suggests security goals aligned to your sector and compliance goals

When you request AI-suggested objectives

Sent to AI

  • →Organisation name (or pseudonym)
  • →Sector
  • →Compliance goal

Never sent

  • ✕Employee or customer data

Leadership review agenda

Generates a suggested agenda for your leadership review meeting

When you generate an agenda for a leadership review

Sent to AI

  • →Organisation name (or pseudonym)
  • →Assessment summary data
  • →Sector

Never sent

  • ✕Individual attendee names or emails
  • ✕Financial data

Benchmarks

AI commentary comparing your scores to sector peers

When you view the benchmarks section

Sent to AI

  • →Organisation name (or pseudonym)
  • →Sector
  • →Employee count
  • →Assessment score data

Never sent

  • ✕Named employees
  • ✕Customer lists

Training course generation

Generates AI-authored staff training content on cyber security topics

When you generate a new training course

Sent to AI

  • →Organisation name (or pseudonym)
  • →Sector
  • →Course topic

Never sent

  • ✕Learner names or emails
  • ✕Training completion records

Agreement generation

Drafts NDAs, DPAs, and service agreements from the details you enter

When you use the AI draft feature for an agreement

Sent to AI

  • →Organisation name (or pseudonym)
  • →Counterparty name
  • →Agreement type and terms you specify

Never sent

  • ✕Existing signed contracts
  • ✕Financial terms unless you type them

Agreement document analysis

Extracts key terms from an uploaded contract or legal document

When you upload a document and provide consent

Sent to AI

  • →Full text of the uploaded document (which may include personal data, financial terms, and legally sensitive content)

Never sent

  • ✕Documents you have not explicitly uploaded for analysis
This is the only feature that may send personal data to AI. You must tick a consent checkbox before upload. You can use Fortify without this feature.

Incident classification

Automatically assigns incident type and severity using AI

Automatically when a new incident is logged

Sent to AI

  • →Incident description
  • →Sector

Never sent

  • ✕Private name reference
  • ✕Individual personal data

Human oversight

AI advises. You decide.

Every AI-generated output in Fortify — recommendations, policy drafts, risk suggestions, incident guidance — is presented as a starting point for review. No AI feature in Fortify makes a final decision on your behalf. You review, edit, accept, or reject everything. This is by design.

Policy documents

AI drafts a starting point. You edit and approve before it is used.

Incident action plans

AI generates a suggested list. You implement the steps you judge appropriate.

Risk register

AI suggests risks and mitigations. You add, edit, or remove each entry.

Benchmarks

AI provides commentary on your sector position. You interpret and act on it.

Our AI provider — Anthropic

All AI features in Fortify are powered by Claude, made by Anthropic.

Role: data processor

Under Article 28 of the UK GDPR and EU GDPR, Anthropic acts as a data processor on Fortify's behalf. They process data only as instructed by Fortify and only for the purpose of generating AI responses. Anthropic does not use your data to train their models (API customers are excluded from training data by default).

Data transfer safeguards

Anthropic operates from the United States. Transfers are protected by EU Standard Contractual Clauses (Module 2, Controller-to-Processor), the UK International Data Transfer Addendum (IDTA), and Anthropic's participation in the EU–US Data Privacy Framework.

Data retention

Anthropic does not retain API inputs or outputs beyond the immediate request–response cycle for non-enterprise API customers. Prompt content is not written to disk as training data. Fortify stores only what it needs to provide the service (e.g. Ask Alex conversation history within your account).

No AI training on your data

By default, data submitted to Anthropic's API is not used to improve or train their models. This applies to all data Fortify sends. Your incident descriptions, policy content, and any uploaded document text are not used for AI training.

Efficient AI use

Every AI call has a real compute and energy cost. We built Fortify to avoid unnecessary ones, not just to disclose the ones we make.

Generated once, reused after that

Vulnerability analysis, prioritised action lists, remediation guidance, audit pre-population, and sector benchmarks are all generated once and cached — not recreated every time you open the page. Most only regenerate when you explicitly ask for a refresh.

The smallest model for the job

Short, structured tasks — classification, extraction, suggestions — run on Anthropic's smaller, faster Haiku model. The larger Sonnet model is reserved for genuine long-form reasoning, such as writing a full assessment report.

Nothing runs just because a page loaded

Beyond the core assessment and audit conversations, AI features across the portal only run when you trigger them — generating a brief, requesting suggestions, refreshing a priority list. Nothing calls AI in the background on a page you're simply viewing.

Capped, rate-limited, and quota'd

Every AI request sends a bounded amount of data — no open-ended prompts. Usage is also rate-limited per organisation and, on lower tiers, capped to a monthly message allowance, so usage can't run away unchecked.

On the provider side: Anthropic has not published an audited environmental report, so we won't cite a specific carbon or energy figure for Claude — we'd rather say nothing than overstate what we can't verify. What we can point to is that Anthropic was the first standalone AI company to join Frontier, a coalition pre-committing to buy carbon removal ahead of the technology reaching commercial scale.

Regulation

EU Artificial Intelligence Act

Regulation (EU) 2024/1689 entered into force on 1 August 2024 with phased application. Here is how it applies to Fortify.

Our role: deployer, not provider

The AI Act distinguishes between providers (who build and place AI systems on the market) and deployers (who use AI systems in a professional context). Fortify is a deployer — we use Anthropic's Claude API to power our features. Anthropic is the provider and bears the obligations that fall on providers, including GPAI model documentation obligations that came into force on 2 August 2025. Fortify's obligations as a deployer are more limited and depend on the risk classification of our AI use cases.

Risk classification

Limited risk

Ask Alex — AI assistant

Direct human-to-AI interactions fall under 'limited risk' under Article 50. We are required to disclose that you are interacting with an AI system. We do this through clear product labelling and are preparing for the formal Article 50 transparency requirements that take effect 2 August 2026.

Minimal risk

All other AI features

Policy generation, risk register assistance, benchmarks, document analysis, training content, and all other AI features are classified as minimal risk. They do not fall within any Annex III high-risk category — they are analytical and recommendation tools in a B2B professional context, with human review of all outputs.

High-risk categories (Annex III) include biometrics, employment decisions, credit scoring, law enforcement, and administration of justice. None of Fortify's features fall within these categories. Our AI features support organisational cyber security and compliance management, which is not listed in Annex III.

Compliance timeline

AI literacy (Article 4) — In force

Compliant

2 February 2025

We provide training and awareness to staff operating AI features. Prohibited AI practices (Article 5) are not used by Fortify.

GPAI model obligations — In force (Anthropic)

Compliant

2 August 2025

These obligations fall on Anthropic as the GPAI model provider. Fortify, as a deployer, is not subject to provider-level obligations.

Full transparency obligations (Article 50) — Preparing

Preparing

2 August 2026

We are designing compliant AI disclosure labelling ahead of this date. All AI-interactive features will display clear disclosure at the point of interaction.

Regulation

UK Regulation

The UK currently has no equivalent to the EU AI Act. UK AI oversight is sector-based and principles-led, with existing data protection law as the primary framework.

UK GDPR and the Data Protection Act 2018

All AI processing of data within Fortify is conducted in accordance with UK GDPR. Where organisational data is sent to AI (such as sector, employee count, or incident descriptions), the lawful basis is legitimate interests (Article 6(1)(f) UK GDPR) — supported by a documented Legitimate Interests Assessment. Our Privacy Notice details all AI processing activities, sub-processors (including Anthropic), and international transfer mechanisms.

Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 (Royal Assent: 19 June 2025) introduced new automated decision-making provisions that come into force December 2025. The Act explicitly requires that human review of AI outputs must be genuine — not a token gesture. Fortify's design, which requires users to actively review, approve, and edit all AI-generated content before it takes effect, satisfies this requirement. No AI feature in Fortify makes decisions automatically on your behalf.

ICO guidance on AI and data protection

We follow the ICO's published guidance on AI and data protection, including its requirements on transparency, accuracy caveating, and data minimisation. AI-generated outputs in Fortify are presented as recommendations rather than definitive statements, in line with ICO accuracy guidance for generative AI. The ICO's AI and Automated Decision-Making Code of Practice is expected in 2027; we will align with it when published.

Questions about AI in Fortify?

If you have questions about how AI is used, what data is processed, or our regulatory compliance, contact us.

Contact us →