What each part of the portal does, where to find it, and how the key features work.
The portal has a dark sidebar on the left for navigation and a main content area on the right. Every feature in Fortify lives in the sidebar — start from the Compliance Hub and Action Hub near the top, or browse the other groups like Supply Chain and Incidents.
Sidebar
Navigation — always visible
Guidance banner
First-time section intro
? HelpTip
Hover or click for detail
Scout button
Ask questions, bottom-right
Four things you'll use on nearly every page.
Every section heading in the portal has a small grey circle with a ? in it. Click it — or hover over it — to see a plain-language explanation of what that section or metric measures, why it matters, and what to do about it.
Useful when you're in a section you haven't used before, or when you want to understand a specific number on the Compliance Health dashboard.
Click the ? next to any heading for a plain-language explanation.
The violet circle (always visible in the bottom-right of every portal page) opens Scout — an AI that knows your specific assessment results and can answer questions about your security position in plain language.
There's also a full Ask Alex page in the sidebar for longer conversations.
The first time you visit any section, a blue banner appears at the top explaining what the section is for, who should use it, and why it matters. Once you dismiss it, it won't appear again.
If you want to re-read a banner, clear your browser's localStorage for the Fortify domain — the banners will reappear.
What is this section for?
Track security issues and improvements as you find them.
Every issue gets a reference number and a status so you can show auditors you have a process for identifying and closing problems.
On the Roadmap and Findings pages, you can attach evidence to each item to prove a control is in place. Open any item and use the Evidence panel to upload a file or paste a URL.
Use “Export evidence pack” on the Roadmap to download everything as a ZIP for auditors.
Status: In progress
Evidence
Security Goals (under the ISO 27001 section in the sidebar) are measurable targets that show auditors your programme is actively improving — not just stable.
Set a goal like “reduce open critical findings to zero by Q3” or “achieve 80% policy coverage by year end”. Update the current value monthly. Goals that slip to “at risk” surface on the Compliance Health dashboard.
ISO 27001 requires measurable information security objectives with tracked progress — Security Goals is where you build that record.
Target: Q3 2026 · Owner: Jason
Follow these steps the first time you set up the portal.
Complete a free assessment
Go to the home page and take a Digital Resilience, GDPR, or Business Continuity assessment. It takes about 10 minutes. You'll get a PDF report and a session token to import your results.
Import your results into the portal
In the portal, go to Assessments and paste your session token. This populates your dashboard score, findings list, and roadmap automatically.
Complete Getting Started
The Getting Started checklist walks through your org profile, compliance goal (e.g. ISO 27001), and team setup. Completing it unlocks your full dashboard score.
Work through your 30-day roadmap actions
The Roadmap organises your findings into 30, 60, and 90-day actions. Start with the 30-day items. Mark each one in progress and attach evidence when done.
Publish your first policy
Go to Policies and generate an Information Security Policy. Edit the draft to match your organisation, then publish it. Drafted policies don't count towards your score.
Set at least one Security Goal
Under ISO 27001 → Security Goals, create a measurable target with a deadline. Auditors ask for evidence of planned improvement — this is where you build that record.
Run your first quarterly review
Once you've imported an assessment and closed some roadmap items, generate a Quarterly Review PDF. Download it and share with your board or keep it on file.
Sign in to the portal and use the sidebar to navigate between sections.
Top level
Compliance Hub
Action Hub
Compliance
Supply Chain
Incidents
Insights
Learning
Settings
Take a free assessment and import your results into the portal in under 15 minutes.