About

Evidence, for businesses that suddenly need some.

Fortoxa is built for the accountancies, clinics, agencies and small SaaS companies across the UK and EU that run their own servers, hold data that matters, and have just been sent a security questionnaire by a customer who will not sign without it.

What it does

It turns server logs into a register an assessor can read.

An agent you install on a server reads system and authentication logs. Fortoxa turns those events into records — blocked connections, account and role history, host configuration and patch state — and places each one against the requirements of the framework you picked, keeping the system it came from and the time it was collected.

Requirements with nothing behind them stay visible and marked as not measured. A register showing every requirement satisfied is the outcome this product exists to prevent, so it is the one thing Fortoxa will not render.

Why UK and EU

The frameworks here are specific.

Cyber Essentials, NCSC CAF, GDPR Article 32 and NIS2 each ask for different things, and generic tooling built elsewhere maps cleanly to none of them. Fortoxa is built around these four, which also means it says plainly when one of them does not apply to you — most small businesses are outside NIS2 and outside the CAF entirely.

See which framework is actually yours

Who it is not for

Two cases where Fortoxa is the wrong purchase.

  • You have no servers

    If your estate is laptops and SaaS accounts, the agent has nothing to install onto and the register will be almost entirely not measured. That is an honest result, but it is not worth paying for.

  • You need a certificate today

    Fortoxa produces evidence you hand to an assessor. It does not certify you, and no output from it is a certificate. If a customer needs to see a certificate this month, you need a certification body, not a monitoring tool.

Contact

Questions, partnerships or press.

One route, and a person reads it.