What it collects, what it produces, and what it refuses to say.
Fortoxa reads your server logs and account state, and turns them into records an assessor will accept. The event types and sources below are the real ones — you will see the same strings in the product.
What it collects
Authentication attempts
Failed logins, invalid users and brute-force patterns from your SSH and system auth logs.
Blocked traffic
Connections your firewall or ban tooling dropped, with the source address and the rule that dropped it.
Host state
Patch level, configuration baseline and drift since the previous collection, per monitored server.
Workspace access
Accounts, roles, grant dates and API keys — who can reach your data and since when.
What it produces
A control register
Requirements from Cyber Essentials, NCSC CAF, GDPR Article 32 or NIS2, each mapped to the artifact that evidences it and the system it came from.
An incident timeline
Detection, action and actor in chronological order. Time is the axis, because that is how an incident is actually reviewed.
Exports your assessor can open
The register as a PDF, the underlying records as CSV. No screenshots, no copy-paste out of a dashboard.
A record of what is missing
Requirements with no evidence render as not measured, with the reason. They never render as a pass.
What it refuses to say
These are design decisions, not gaps. A monitoring tool that fills its own blanks is worse than no monitoring tool, because you stop checking.
No invented trend lines
If there is no previous snapshot to compare against, Fortoxa says so rather than drawing a flat line or a green arrow. The API returns the sentence; the interface prints it.
No score without a method
Every figure carries the system that produced it and the time it was collected. If you cannot trace it, it does not belong on the screen.
No silent gaps
An empty list means one of two things — nothing happened, or nothing is wired up. Fortoxa distinguishes them, because treating the second as the first is how people get caught out.
Which plan gets which
Collection runs on every plan. The control register, the evidence export and the audit-readiness view are gated to Business and above, and the pricing page cites the file that enforces each limit.
See the enforced limits