אבטחת מידע ב-FORTVISION

מסמך זה מיועד למנהלי IT, ממוני אבטחת מידע ויועצי פרטיות שמעריכים את הפלטפורמה. כל סעיף מתאר בקרה שקיימת בפועל בקוד ובתשתית — לא כוונות ולא הצהרות שיווקיות. עודכן: 3 בספטמבר 2026.
אין הסמכה פורמלית. FORTVISION אינה מחזיקה כיום בהסמכת SOC 2, ISO 27001 או הסמכה חיצונית אחרת, ולא בוצע מבדק חדירה על ידי צד שלישי. הבקרות המפורטות כאן מיושמות ונבדקות פנימית. אם ארגונכם דורש הסמכה — אנא ציינו זאת מראש.

1. ארכיטקטורה ואחסון

אפליקציה ו-API
Vercel — אפליקציית web חד-עמודית ופונקציות serverless (Node.js). כל התעבורה ב-HTTPS עם תעודות מנוהלות.
מסד נתונים ראשי
Upstash Redis — גישה דרך REST מעל TLS בלבד, עם טוקן שרת. כל נתוני סביבת העבודה (לידים, אנשי קשר, קמפיינים, הגדרות) נשמרים כאן.
AWS
SES לשליחת אימייל · S3 לקבצי מדיה וגיבויים (eu-west-1, אירלנד) · Aurora MySQL (נקודת קריאה בלבד) ו-API Gateway + Lambda לנתוני תוספי החנות (eu-west-1).
CDN לקריאייטיבים
Cloudflare Workers — הגשה ומטמון של קריאייטיבים עשירים למודעות (fortcdn.com). מגיש קבצי קריאייטיב בלבד.

מיקום הנתונים

2. אימות (Authentication)

3. הרשאות (Authorization) ובידוד לקוחות

4. הגנה על הנתונים

5. ניטור ותגובה לאירועים

6. פיתוח ופריסה מאובטחים

7. תתי-מעבדים (Sub-processors)

ספקים שמעבדים נתוני לקוחות בשם FORTVISION, כפי שמופיעים בקוד הפלטפורמה:

ספקתפקידנתוניםמיקום
Vercel Inc.אירוח האפליקציה וה-APIכל תעבורת האפליקציהארה"ב (iad1) + CDN גלובלי
Upstash Inc.מסד נתונים ראשי (Redis)נתוני סביבות העבודהלפי הגדרת המסד
Amazon Web ServicesSES (אימייל), S3 (מדיה, גיבויים), Aurora MySQL, Lambda/API Gatewayאימיילים, קבצים, גיבויים, נתוני תוספי חנותאירלנד (eu-west-1); SES לפי הגדרה
Cloudflare Inc.CDN לקריאייטיבים של מודעותקבצי קריאייטיב בלבדרשת גלובלית
Anthropic PBCעוזר AI (צ'אט), יצירת תוכןתוכן והקשר שהמשתמש מבקש לנתחארה"ב
OpenAIיצירת תוכן אימייל ו-AIתוכן שהמשתמש מזיןארה"ב
Google LLCGemini (יצירת דפי נחיתה), Google Sign-In, Google APIsתוכן שהמשתמש מזין; פרטי כניסהארה"ב / גלובלי
Twilio Inc.SMS, שיחות, מעקב שיחותמספרי טלפון, תוכן הודעותארה"ב / גלובלי
MicroPay (מיקרופיי)שליחת SMS בישראלמספרי טלפון, תוכן הודעותישראל
Unipileאינטגרציית הודעות LinkedInשיחות LinkedIn של חשבונות מחובריםEU

פלטפורמות מחוברות (בשליטת הלקוח)

הלקוח בוחר לחבר את החשבונות שלו; הפלטפורמות הבאות פועלות כבעלות שליטה עצמאיות על פי תנאיהן: Meta (פייסבוק, אינסטגרם, מודעות, לידים, WhatsApp Business), Google Ads / Analytics / Business Profile, TikTok for Business, LinkedIn, Shopify, Wix ו-WooCommerce.

8. דיווח על פגיעויות ויצירת קשר

מצאתם פגיעות אבטחה? אנא כתבו ל-info@fortvision.com עם הנושא "Security report". נאשר קבלה תוך 2 ימי עסקים, נעדכן על התקדמות, ולא ננקוט צעדים משפטיים נגד מחקר בתום לב שמכבד את פרטיות המשתמשים ואינו פוגע בזמינות השירות.

בקשות פרטיות (עיון, תיקון, מחיקה, ניוד), שאלות על תתי-מעבדים או בקשה ל-DPA חתום: אותה כתובת. מדיניות פרטיות: fortvision.com/privacy-policy.

Security at FORTVISION

Written for IT managers, security officers and privacy advisors evaluating the platform. Every section describes a control that actually exists in the code and infrastructure — not intentions, not marketing. Last updated: 3 September 2026.
No formal certification. FORTVISION does not currently hold SOC 2, ISO 27001 or any other external certification, and no third-party penetration test has been performed. The controls below are implemented and reviewed internally. If your organisation requires a certification, please say so up front.

1. Architecture & hosting

App & API
Vercel — single-page web app and serverless functions (Node.js). All traffic over HTTPS with managed certificates.
Primary database
Upstash Redis — accessed over REST/TLS only, with a server-side token. All workspace data (leads, contacts, campaigns, settings) lives here.
AWS
SES for email delivery · S3 for media files and backups (eu-west-1, Ireland) · Aurora MySQL (read-only reader endpoint) and API Gateway + Lambda for store-plugin data (eu-west-1).
Creative CDN
Cloudflare Workers — edge caching for rich-media ad creatives (fortcdn.com). Serves creative files only.

Data location

2. Authentication

3. Authorisation & tenant isolation

4. Data protection

5. Monitoring & incident response

6. Secure development & deployment

7. Sub-processors

Providers that process customer data on FORTVISION's behalf, as they appear in the platform code:

ProviderRoleDataLocation
Vercel Inc.Hosting of app and APIAll application trafficUSA (iad1) + global CDN
Upstash Inc.Primary database (Redis)Workspace dataPer database configuration
Amazon Web ServicesSES (email), S3 (media, backups), Aurora MySQL, Lambda/API GatewayEmails, files, backups, store-plugin dataIreland (eu-west-1); SES per configuration
Cloudflare Inc.CDN for ad creativesCreative files onlyGlobal network
Anthropic PBCAI assistant (chat), content generationContent and context the user asks to analyseUSA
OpenAIEmail and content generationContent the user submitsUSA
Google LLCGemini (landing-page generation), Google Sign-In, Google APIsContent the user submits; sign-in identityUSA / global
Twilio Inc.SMS, voice calls, call trackingPhone numbers, message contentUSA / global
MicroPaySMS delivery in IsraelPhone numbers, message contentIsrael
UnipileLinkedIn messaging integrationLinkedIn conversations of connected accountsEU

Connected platforms (customer-controlled)

The customer chooses to connect their own accounts; these platforms act as independent controllers under their own terms: Meta (Facebook, Instagram, Ads, Lead Ads, WhatsApp Business), Google Ads / Analytics / Business Profile, TikTok for Business, LinkedIn, Shopify, Wix and WooCommerce.

8. Responsible disclosure & contact

Found a security vulnerability? Please write to info@fortvision.com with the subject "Security report". We acknowledge within 2 business days, keep you updated on progress, and will not pursue legal action against good-faith research that respects user privacy and does not degrade the service.

Privacy requests (access, rectification, erasure, portability), sub-processor questions or a countersigned DPA: same address. Privacy policy: fortvision.com/privacy-policy.