Fortinetics LLC ("Fortinetics," "we," "us") respects your privacy. This policy describes what information we collect, store, and process when you (a) visit fortinetics.com, (b) contact us, or (c) use a compliance reference app published by Fortinetics LLC on the Apple App Store, and how we handle it.
We publish this policy as a single document covering both the website and Fortinetics-published apps because most readers will encounter both surfaces. App-specific behaviors are called out in the "Apps published by Fortinetics LLC" section below; everything else applies to both surfaces.
What we collect
Information you give us. When you email us, request a scoping call, or otherwise contact us, we collect the information you provide — typically name, email address, company, and the content of your message. We use this information to respond to your inquiry.
Analytics. This site uses Cloudflare Web Analytics, which is privacy-first and does not use cookies or fingerprint visitors. It records anonymized, aggregate page-view statistics — roughly: which pages were visited, from which country, on what browser. It does not identify individuals.
Cookies. This site does not set tracking cookies. We may use strictly necessary functional cookies only if and when required to operate site features.
How we use information
We use the information you provide solely to respond to your inquiry, deliver contracted services, fulfill legal and contractual obligations, and maintain operational records.
We do not sell your information. We do not share your information with third parties for their marketing purposes. We do not use your information to train machine-learning models.
Who processes information for us
We use a small number of service providers to operate the firm. Relevant to this site:
- Cloudflare — hosts this website, terminates TLS, and provides analytics. Cloudflare's privacy policy applies to their processing.
- Microsoft 365 (via GoDaddy) — operates @fortinetics.com email. Microsoft's privacy policy applies to their processing.
- GitHub — hosts our private source code repositories. GitHub's privacy policy applies to their processing.
Apps published by Fortinetics LLC
Fortinetics LLC publishes a small portfolio of compliance reference apps on the Apple App Store — utilities for CMMC, NIST 800-171, FedRAMP, DoD Cloud Computing SRG, SCIF/SAPF accreditation, and related federal-aligned compliance frameworks. The categorical scope is intentional: only compliance and federal-cybersecurity reference apps appear under "Fortinetics LLC" as the developer. Any other app you find published under "Fortinetics LLC" is not ours.
Per-app disclosures govern. Each app's specific data practices are disclosed in that app's App Store listing under "App Privacy" (sometimes called "privacy nutrition labels"). Where this policy and an individual app's App Store disclosure differ, the App Store disclosure governs that specific app. The defaults below describe Fortinetics's standard data-handling posture for compliance reference apps; individual apps may collect less than the defaults but will not collect more without explicit disclosure.
Standard data posture. Compliance reference apps from Fortinetics are built to operate on-device wherever possible. As a default:
- No account required. Most apps work without sign-in. When sign-in is offered, it's optional and only enables features that need it (e.g., cross-device sync of saved checklists).
- Local storage by default. User-entered content (notes, scores, configurations) is stored on-device in app-private storage, not transmitted to Fortinetics servers, unless an explicit cloud-sync feature is offered and enabled by the user.
- No advertising or third-party trackers. Apps do not contain advertising SDKs, analytics SDKs that build cross-app profiles, or third-party trackers. Some apps may use Apple's first-party crash-reporting and on-device analytics (which are governed by Apple's privacy controls — you can opt in or out in iOS Settings).
- No tracking across apps or websites. Apps do not implement Apple's App Tracking Transparency tracker requests because we do not engage in tracking as Apple defines it.
- No selling or sharing for marketing. Information collected through apps is never sold, shared with data brokers, or used for third-party marketing purposes.
- No machine-learning training on customer data. Information collected through apps is never used to train, fine-tune, or evaluate machine-learning models — Fortinetics's own or third-party.
- No targeting users under 13. Fortinetics's compliance reference apps are designed for working professionals and are not directed at children. We do not knowingly collect information from users under 13.
What apps may collect. Specific apps may collect:
- Crash diagnostics — anonymized crash logs to improve app stability. Apple's standard mechanism; user-controlled in iOS Settings → Privacy & Security → Analytics & Improvements.
- Support inquiries — when you email an app's support address, we receive your message content, your email address, and any attachments you send.
- Optional cloud sync — for apps offering cross-device sync, the app may upload user content to iCloud (Apple-managed; covered by Apple's privacy policy) or to Fortinetics-operated infrastructure (disclosed per-app, encrypted in transit and at rest, deleted on user request).
- In-app purchase records — for paid apps or apps with paid features, Apple processes the purchase. Fortinetics receives only the anonymized purchase confirmation Apple provides; we do not receive your payment card information.
Push notifications. Apps may request permission to send push notifications. Notifications are limited to: (a) compliance-deadline reminders the user has explicitly configured, (b) app-update notices, and (c) responses to user-initiated actions. We do not use push notifications for marketing or promotional content.
App-specific privacy questions or data requests. See /support/ for app support contacts. Privacy and data-subject-access requests for any Fortinetics-published app should go to contact@fortinetics.com.
How we protect information
We apply the same controls to our own firm that we help clients implement for theirs: multi-factor authentication on all accounts, endpoint protection on all devices, full-disk encryption, centralized logging, and least-privilege access.
No transmission of information over the internet or storage in electronic form can be guaranteed one-hundred-percent secure. If you are sharing sensitive or classified information, we will execute a Mutual Non-Disclosure Agreement first.
Retention
We retain inquiry and contract correspondence for the life of the engagement and for twelve (12) months after the final invoice. Longer retention may apply where legally required.
Your rights
You may request a copy of the information we hold about you, ask us to correct inaccuracies, or request deletion, subject to any legal or contractual record-retention obligations. Send requests to contact@fortinetics.com.
Changes
We may update this policy. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced on this page.
Contact
Questions about this policy: contact@fortinetics.com.