Home/Reference Architecture/Pattern 1
Nothing to deploy and nothing to operate. Iron Fort runs the platform in North American regions, and you connect your cloud accounts with read-only credentials. You are running a compliance programme the same week you sign up.
The platform is shared and multi-tenant, with isolation enforced at the application and data layer rather than by separate infrastructure. That is what makes it affordable at this size, and it is the right trade for a team whose alternative is a spreadsheet.
Applies to Founder and Startup plans. Every pattern runs the same platform — the same frameworks, the same evidence model and the same reports. What changes is who holds the infrastructure and where evidence comes to rest.
You grant read-only access across the nineteen supported integrations — a CloudFormation stack creates the cross-account role for AWS, an app registration covers Azure and Microsoft 365, and the rest connect by OAuth or service account.
Shared scanner workers pick up queued work and call your APIs read-only. Credentials are fetched per run and never written to disk.
Findings go to the database, artefacts to Amazon S3 under a tenant-scoped prefix, each mapped to the control clause it answers.
Your team works in the app; auditors get scoped read-only access; customers get a public trust page.
Two plans, because they answer different questions and usually different people. Read them here, or take the PDF into your own planning.
Nothing is deployed and nothing is operated by you, so this plan is mostly about granting access carefully and deciding scope. Most of the work is in phases 2 and 3.
Done whenYour administrators can sign in and see an empty but correctly scoped tenant.
Done whenEvery in-scope system returns data on a test collection.
Done whenThe control set is installed and every control has a scope.
Done whenA coverage figure exists and the team agrees it is honest.
Done whenEvery required policy exists, has an owner and has a next review date.
Done whenYou can hand an assessor a link and a report pack on the same day they ask.
Sequence, not schedule. Phases are ordered by dependency. Elapsed time depends on your change process and scope, so we do not guess at it — ask us and we will estimate against your specifics.
The platform is running from day one, so adoption is entirely about people. The risk here is not technical failure — it is a tool that one person uses and nobody else opens.
Done whenEvery control set in scope has a named owner who knows they own it.
Done whenOne framework has a real coverage figure the owner recognises as true.
Done whenOwners are closing their own evidence requests without being chased.
Done whenA month passes with no manual chasing and nothing falls overdue.
Done whenA customer security questionnaire is answered with a link.
Done whenThe second framework reaches useful coverage in a fraction of the first one's effort.
Sequence, not schedule. Phases are ordered by dependency. Elapsed time depends on your change process and scope, so we do not guess at it — ask us and we will estimate against your specifics.
We would rather send you to another pattern than sell you the wrong one.
Residency, tenancy, egress, air gap — tell us the rule you have to satisfy and we will show you the deployment that satisfies it.