What follows covers information that reaches Fortify 24x7 by this storefront, plus whatever the security lines throw off once running. Written to be read, meaning each kind of line gets named instead of waved at.
Issued 29 August 2026. It replaces anything published here before that date.This storefront is run by Fortify 24x7 under the CyberThreat Management name. Fortify 24x7 decides how information arriving here gets handled, and likewise whatever the lines you buy produce. Below, we always means Fortify 24x7.
Want any of this explained? Write to desk@cyberthreat.management. Somebody here opens it and writes back.
Deliberately dull, this site. No advertising trackers. Nothing built into a profile of your visit. Marketing scripts borrowed from elsewhere: none.
Stripe owns the card page. Number, expiry date, and whichever digits are printed on the reverse: all typed there. Those values are never handed to this site, never displayed to us, never written anywhere of ours.
Back comes the least an account will run on. A business name. An email address. Which lines, plus their quantities. Health of the subscription. Whichever references Stripe keeps against a customer or a subscription.
Running these services for you necessarily means handling whatever enrolled systems produce. The detail follows from whichever lines are owned.
All handling follows your instruction and delivers what was bought. Mining it for our own ends does not happen, nor is any of it for sale. That position stands; it is not something due for revisiting once the market turns.
Raising a bulletin hands us the subject, the description, whatever gets attached, and the address it came from. That lands in the ticketing system Fortify 24x7 works out of, so the history stays readable when the same thing happens again.
Passwords do not belong in a bulletin. Should a credential genuinely need to reach us, say so on the bulletin and a route gets arranged that is not plain text.
Doing this properly means other firms touch part of it. Here is the roll, and what each one handles.
Each of them is engaged on terms binding it to process on instruction. Where a line carries an onward transfer, ask; we say so rather than leave you hunting.
Records of account and of billing stay for the run of the subscription, then for whatever tax and accounting rules demand. Bulletin history stays too, so a recurring problem keeps a readable past.
Within the security platforms, retention is set line by line at configuration, since the right answer for a detection record differs from the right answer for a backup copy. Yours gets told to you. No single figure is printed here as though it covered the lot.
Where you happen to live decides what you may ask. A copy of the material we hold. A correction. A deletion. An objection to some handling. Write to desk@cyberthreat.management; we deal with it inside whatever period applicable law allows.
Two honest caveats. Anything held as processor for your employer is answered by your employer, and the request goes there. Records we are obliged to keep for tax purposes cannot be deleted by us, and we will name which ones those are.
Inside Fortify 24x7, access to customer data reaches only staff who need it for the work. It sits behind a second factor. It is logged. In transit and at rest it is encrypted, using the facilities of whichever platform is involved.
Change this notice and the issue date above changes with it. Anything materially affecting how your information gets handled arrives at the account address as a message. Never as a quiet edit.