Iron Fort replaces manual compliance spreadsheets, expensive consultants, and annual checkbox reviews with a continuous, automated platform built for Canadian government, healthcare, and SaaS teams.
Free · No Obligation
Tell us about your compliance needs and we'll match you with the right solution in 30 minutes.
Trusted Procurement Channels
AWS MARKETPLACE
GOV. OF CANADA · RFSA
TBIPS · CSPV · PROSERVICES
SLSA · SOFTWARE LICENSING
Whether you're a healthcare organization, a government agency, or a growth-stage SaaS startup, Iron Fort has a purpose-built compliance path for you.
Real-time monitoring of all HIPAA safeguards — encryption, MFA, access logs, and BAA tracking — purpose-built for healthcare organizations and their business associates.

Purpose-built for federal, provincial, and municipal government. Automates SA&A processes, control selection, evidence collection, and Protected A/B profile compliance.
Fast-track your SaaS platform to SOC-2 certification in weeks, not months. Pre-built controls, guided evidence collection, and startup-friendly pricing through AWS Marketplace.
Give your consulting practice a live, portfolio-wide compliance monitoring tool that converts one-time assessments into trackable programs. Impress clients. Close more engagements.
Learn More →Iron Fort connects to your cloud infrastructure, identity providers, and DevOps tooling — running 24/7 compliance checks and surfacing drift before it becomes an audit finding.
S3 bucket policies, IAM roles, CloudTrail logging, VPC security groups, and encryption-at-rest checks.
GCS bucket ACLs, IAM bindings, Cloud Audit Logs, Compute firewall rules, and KMS key rotation.
Entra ID MFA enforcement, Storage Account public access, NSG rules, Key Vault access policies, and Defender alerts.
Conditional access policies, external sharing settings, DLP rules, audit log retention, and Teams data residency.
Branch protection rules, secret scanning, dependency alerts, org SSO enforcement, and repo visibility controls.
Pipeline security policies, artifact feed permissions, board access controls, and audit stream configuration.
All integrations use read-only API access — no agents to install, no firewall changes required. Ask about custom connectors →
No 6-month consultant engagements. No spreadsheet fire drills. Iron Fort gets you compliant fast — and keeps you there continuously.
30 minutes with a compliance expert. We map your current state, identify your highest-risk gaps, and recommend the fastest path to compliance.
Connect Iron Fort to your AWS, Azure, GCP, or on-premises infrastructure. Pre-built integrations get you live in hours, not weeks.
Iron Fort runs 24/7, monitoring every safeguard, collecting evidence, and alerting you to gaps before they become violations or audit findings.
Generate complete audit packages with one click. All evidence, all policies, all documentation — organized, timestamped, and audit-ready.
Step 1 Starts Here
Get a personalized gap report and compliance roadmap — free, no strings attached.
A 47-point checklist used by compliance teams across 200+ healthcare organizations.
Download Free →Iron Fort is purpose-built for compliance — not a generic GRC tool bolted onto a spreadsheet.
Real-time checks on encryption, MFA, access controls, and backup policies across all environments.
Centralized, timestamped evidence collection that feeds directly into your audit package.
Continuously scores your controls by severity, surfaces critical gaps, and generates a prioritized remediation roadmap.
NewUpload existing policies and get a line-by-line analysis against HIPAA, ITSG-33, or SOC-2 — gaps flagged before your auditor finds them.
NewManage all Business Associate Agreements in one place with expiry alerts and completeness scoring.
Track workforce compliance training and attestations — searchable, exportable, audit-ready.
Built-in HIPAA-compliant incident response workflows with notification timelines and documentation.
Custom analytics dashboards for compliance leaders who need executive-level reporting.
Transparent, public pricing for health tech and SaaS companies. No sales call required to get started.
30-day free trial · No credit card
30-day free trial · No credit card
14-day free trial · No credit card
Demo + 14-day trial included
All plans available on AWS Marketplace with consolidated billing — use your existing AWS credits toward your compliance program.
Purpose-built for federal, provincial, and municipal programs. Scoped to the complexity of your SA&A engagement — not priced per seat.
Available through
ITSG-33 Annex 3 control selection, gap analysis, and evidence collection — automated across your full system scope.
Pre-configured control baselines for Unclassified, Protected A, and Protected B classification levels.

All SA&A documentation, reports, and policy templates delivered in both English and French.
Aligned to Treasury Board's 12 GC Cloud Guardrails for departments migrating workloads to public cloud.
Power BI-integrated compliance dashboards for CIO and CISO reporting to departmental leadership.
Tailored SA&A audit reports formatted to departmental requirements with full evidence traceability.
Engagement Pricing
Every SA&A engagement is different. Pricing is based on number of systems in scope, classification level, and program complexity — not per-user seat counts.
Every engagement includes
RFSA · SLSA · TBIPS · CSPV eligible
Use your existing AWS account to subscribe, bill, and manage Iron Fort — no new vendor relationship, no separate invoice.
Eligible procurement vehicles
Iron Fort charges appear on your existing AWS invoice. One bill, one vendor relationship — no new accounts to set up.
Apply existing AWS Marketplace credits or committed spend directly toward your Iron Fort subscription — dollar for dollar.
Iron Fort is AWS Foundational Technical Review certified — the fastest compliance path for organizations pursuing AWS ISV partnership.
Canadian federal departments and agencies can procure Iron Fort via AWS Marketplace under existing RFSA and SLSA procurement vehicles.
Subscribe on AWS Marketplace and Iron Fort activates immediately — no procurement delays, no lengthy onboarding paperwork.
Start with a free trial through AWS Marketplace — no credit card required, cancel anytime. Full platform access from day one.
AWS Marketplace Plans
Annual billing · Free trial on all plans
Try Free on AWS Marketplace Buy with AWSNo credit card · Cancel anytime
Book a free 30-minute strategy call. Walk away with a personalized compliance roadmap — no obligation, no sales pressure.
Available on AWS Marketplace · RFSA Eligible · No credit card required for trial