Legal

Terms of Service

Last updated: 28 July 2026

1. About this service

Fortify is an AI-assisted security and compliance platform provided by Blue Cipher Ltd(“we”, “us”, “our”). The platform comprises:

  • Free assessments — AI-guided conversations covering digital resilience and GDPR compliance, resulting in a personalised report
  • Fortify Portal — a subscription-based management platform for tracking findings, managing risks, logging incidents, building roadmaps, and maintaining a policy library
  • Compliance audit modules — AI-guided structured audits against recognised frameworks including Cyber Essentials Plus, ISO 27001, DORA, and the NHS Data Security and Protection Toolkit (DSPT)
  • Supporting tools — vendor management, agreement tracking, quarterly reporting, and team collaboration features within the portal

By using any part of Fortify you agree to these terms. If you do not agree, please do not use the service.

2. Informational purpose — not professional advice

All content produced by Fortify — including assessment reports, portal findings, audit section outcomes, control status readings, policy drafts, and AI-generated guidance — is informational only. It does not constitute professional security consultancy, legal advice, information governance consultancy, compliance certification, or any other regulated professional service.

All content is based solely on the information you provide. Fortify does not independently verify your answers or inspect your systems, processes, or infrastructure.

You should not rely on Fortify output as the sole basis for significant business, security, or compliance decisions. We recommend engaging a qualified professional — such as an accredited assessor, IG consultant, or solicitor — for formal assessments, regulatory submissions, or certifications.

3. AI-generated compliance guidance

Important — please read carefully

Fortify's compliance audit modules use AI to guide you through recognised frameworks and help you assess your current position. The following limitations apply to all AI-generated compliance content:

  • Audit outcomes are not certification. Completing a Fortify audit for Cyber Essentials Plus, ISO 27001, DORA, NHS DSPT, or any other framework does not constitute certification, accreditation, or formal compliance confirmation. Certifications require assessment by an independent accredited body or regulatory authority.
  • DSPT guidance is not NHS IG consultancy. The NHS Data Security and Protection Toolkit audit module is designed to help organisations prepare for their annual DSPT self-assessment. It does not constitute information governance consultancy, and completing it does not guarantee that your organisation will achieve “Standards Met” or “Standards Exceeded” status. DSPT submissions are assessed by NHS England, not Fortify.
  • AI-generated policy documents require review. Policy drafts produced by the Fortify policy editor are AI-generated starting points. They must be reviewed, amended to reflect your actual practices, and approved by an appropriate person in your organisation before use. They do not constitute legally reviewed documents.
  • Control readings may be inaccurate. AI-generated assessments of whether a control is “compliant”, “partially compliant”, or “non-compliant” are based solely on your descriptions during the guided conversation. They are indicative, not definitive, and may not reflect findings from a technical assessment or formal audit.
  • Regulatory requirements change. Framework requirements, regulatory guidance, and legal obligations change over time. Fortify updates its content periodically but does not guarantee that all guidance reflects the current version of any framework or regulation.

4. Acceptable use

When using Fortify you agree that you will not:

  • Provide false or misleading information during an assessment or audit
  • Attempt to reverse-engineer, scrape, or copy the platform content, prompts, or reports for commercial use
  • Use the service to generate content for distribution or resale without our written permission
  • Attempt to circumvent bot protection, rate limiting, or access controls
  • Use automated tools to submit assessments or audit responses at scale
  • Share personal data about individuals — including patient data, staff data, or customer data — during any assessment, audit, or AI conversation
  • Submit a DSPT or other regulatory declaration based solely on Fortify output without independent verification of your compliance position

5. Free tier

The free assessment is provided at no charge. You complete one assessment conversation and receive an AI-generated report by email. Portal access at the free tier is included following any paid assessment. We reserve the right to modify, suspend, or discontinue the free tier at any time with reasonable notice.

6. Paid subscriptions

Portal subscriptions (Lite, Pro, Annual) and compliance audit add-ons are billed on a recurring basis via Stripe. Subscription terms, pricing, and included features are set out on the pricing page and confirmed at checkout.

Payments are processed securely via Stripe. We do not store your payment card details. Subscription cancellations take effect at the end of the current billing period. Refund requests should be directed to jason@bluecipher.co.uk — consumer customers have a 14-day statutory cancellation right for digital services not yet accessed; business customers are not entitled to a refund after access has been granted unless otherwise agreed in writing.

7. Intellectual property

The Fortify platform, assessment framework, audit content, scoring methodology, report templates, and all associated content are owned by Blue Cipher Ltd. Nothing in these terms transfers any intellectual property rights to you.

Your assessment responses and the reports generated from them are yours. You may use them for internal business purposes. We may use anonymised, aggregated data derived from platform use to improve the service, as described in our Privacy Policy.

8. Disclaimer of warranties

The Fortify service is provided “as is” and “as available” without warranty of any kind, express or implied. We do not warrant that the service will be uninterrupted, error-free, or secure. We do not warrant that any report, audit outcome, policy draft, control reading, or other AI-generated content will be accurate, complete, current, or fit for a particular purpose. Compliance frameworks and regulatory requirements change, and Fortify does not guarantee that its content reflects the current version of any standard at all times.

9. Limitation of liability

To the fullest extent permitted by law, Blue Cipher Ltd shall not be liable for any indirect, incidental, consequential, special, or punitive damages arising from your use of Fortify or reliance on any output produced by it. This includes, without limitation, losses arising from: regulatory non-compliance or enforcement action; failure to achieve certification; a failed DSPT submission or NHS England assessment outcome; decisions made based on AI-generated audit readings or policy drafts; or data breaches occurring after use of the platform.

Our total aggregate liability to you for all claims arising out of or relating to your use of the service shall not exceed the total fees you paid us in the 12 months immediately preceding the event giving rise to the claim, or £500, whichever is greater.

Nothing in these terms limits our liability for death or personal injury caused by our negligence, fraudulent misrepresentation, or any other liability that cannot be excluded or limited by applicable law.

10. Third-party services

Fortify uses third-party services including Anthropic (AI), Supabase (database), Vercel (hosting), Resend (email), Cloudflare (bot protection), and Stripe (payments). Your use of these services is subject to their own terms and privacy policies. We are not responsible for the availability, accuracy, or conduct of these services.

11. Changes to these terms

We may update these terms from time to time. We will notify portal account holders of material changes by email at least 14 days before they take effect. The date at the top of the page reflects the most recent version. Continued use of the service after changes take effect constitutes acceptance of the updated terms.

12. Governing law

These terms are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

13. Contact

If you have any questions about these terms, please contact us at jason@bluecipher.co.uk.