1Fort · Trust Center

1Fort Trust Center

Trust center

1Fort maintains a public trust center documenting SOC 2 Type II, HIPAA, and CCPA compliance.

insuranceinsurtechcommercial-insurancecyber-insuranceinsurance-brokerquotingpolicy-managementpremium-financepaymentsworkflow-automationartificial-intelligenceagentic-ai
Trust center: https://security.1fort.com/

Certifications & Compliance

SOC 2 Type IIHIPAACCPA

Source

Trust Center

Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://security.1fort.com/
url: https://security.1fort.com/
platform: SafeBase (Drata)
public_security_page: https://1fort.ai/security

certifications:
- SOC 2 Type II
- HIPAA
- CCPA

certification_detail:
- name: SOC 2 Type II
  status: attested
  report: request-gated on the trust center
- name: HIPAA
  status: claimed
- name: CCPA
  status: claimed

documents:
- name: SOC 2 Report
  access: request
- name: Pentest Report
  access: request
- name: Network Diagram
  access: request
- name: Cyber Insurance documentation
  access: request
access_gate: >-
  Documents require an access request through the SafeBase portal ("We can provide completed
  questionnaires upon request"). No NDA terms or subprocessor list are published anonymously.

control_families:
  product_security: [Audit logging, Data security, Multi-factor authentication]
  data_security: [Access monitoring, Data backups, Encryption at rest]
  application_security: [Credential management, Secure development training, SDLC]
  access_control: [Data access, Logging, Password security]
  infrastructure: [Status monitoring, Amazon Web Services, BC/DR]
  network_security: [Data loss prevention, DNSSEC, Firewall]
  endpoint_security: [Disk encryption]
  corporate_security: [Asset management, Email protection, Employee training]

stated_practices:
  encryption: at rest and in transit using "known strong protocols and ciphers"
  mfa: phishing-resistant hardware via WebAuthn
  architecture: Zero Trust, remote-first, cloud-native on AWS
  ddos: mitigation at application and network layers
  testing: internal and third-party red team testing
third_party_rating: SecurityScorecard grade A (displayed on the trust center)

discrepancy:
  claim: The trust center lists DNSSEC under network security controls.
  observed: >-
    Live DNS probe (security/1fort-domain-security.yml) found no DNSKEY on either 1fort.ai or
    1fort.com — DNSSEC is not enabled on the public domains — and neither domain publishes a CAA
    record. The DNSSEC control may apply to internal corporate DNS rather than the public zones.

evidence:
- source: https://security.1fort.com/
  status: 200
  keywords: [soc 2, hipaa, ccpa, pentest report, trust center]
- source: https://1fort.ai/security
  status: 200
  keywords: [soc 2 type ii, ccpa, hipaa, webauthn, aws]