FortifAI · Data Resilience

Backups Are Easy. Getting Your Data Back Is Not.

A backup, restore and disaster recovery platform with AI applied to the part that decides how long an outage lasts: finding a clean recovery point quickly and proving the recovery will work. Encrypted end to end, immutable by design, and hosted wherever your policy requires.

AES-256Encrypted at rest and in transit
ImmutableRetention-locked recovery points
NIST CSFAligned control architecture
Zero TrustLeast privilege by default
Why FortifAI Exists

Most Organisations Are Confident They Can Recover. Far Fewer Have Proven It.

Backup software is a solved problem. Recovery is not. The gap surfaces at the worst possible moment: a ransomware event, a bad deployment, or an integration that quietly overwrote thousands of records weeks ago and went unnoticed until now.

  • A backup that has never been restored from is a belief, not a control
  • Knowing when the damage began matters more than holding a hundred restore points
  • Restoring records without the configuration around them leaves an environment half recovered
  • Storage costs that scale with data volume turn a safety net into a budget conversation
  • A backup held inside the platform it protects is of limited use when that platform is unavailable

The question few can answer

How long would recovery actually take, and what is that based on?

The one that costs the most time

Which recovery point is the last clean one?

The one most often missed

The records came back. Did the configuration around them?

The one finance raises

Why has the storage line doubled this year?

The Platform

Six Capability Areas

Each one maps to a recurring business domain requirement rather than a competitor feature checklist.

01

Automated Backup

Scheduled protection of data and the configuration around it, with higher frequency on the objects an operation depends on. Incremental, so performance holds as volumes grow.

02

Granular Restore

Recover a single record, one object, a configuration change or an entire environment. Scope is decided at the moment of recovery, not fixed at backup time.

03

Disaster Recovery

Defined recovery point and recovery time objectives, rehearsed procedures and a documented path back to service.

04

Immutable Copies

Recovery points that cannot be altered or deleted within their retention window, including by a privileged account that has been compromised.

05

Anomaly Detection

Mass deletions, bulk field changes and encryption-shaped activity are flagged as they occur, before they propagate into every retained copy.

06

Evidence and Retention

Defensible retention schedules and a complete record of what was protected, what was recovered and by whom, in a form suitable for audit.

Security Architecture

Built to the Controls Your Reviewer Will Ask About

Backup infrastructure holds a complete copy of everything worth protecting, which makes it one of the highest value targets in an estate. It is designed accordingly.

Encryption at Rest

AES-256 on every recovery point. Keys are managed through a key management service with scheduled rotation, so a key set once does not stay in force indefinitely.

Encryption in Transit

TLS 1.2 or above on every transfer, including between components on the same private network. Backup traffic is segmented from general network traffic.

Immutability and WORM

Write once, read many retention on recovery points, enforced at the storage layer rather than by application logic that a compromised administrator could bypass.

Identity and Least Privilege

Role separation between who can configure protection, who can approve a restore and who can delete. Multi-factor authentication and no standing administrative access.

Threat Detection

Behavioural baselining per object, so mass deletion, bulk overwrite and encryption patterns raise an alert and trigger an automatic hold on the last known-good copy.

Audit and Evidence

Every configuration change, access event and recovery action is logged immutably and exportable for an assessor without needing a support ticket.

Security & Compliance

Aligned to Recognised Control Standards

The architecture is designed and documented against NIST CSF and SP 800-53, HIPAA technical safeguards, SOC 2 Trust Services Criteria and the FedRAMP Moderate baseline, with control mapping and supporting documentation available on request.

Data residency is contractually specified rather than inferred from a subprocessor list, and a Business Associate Agreement is available where protected health information is in scope.

Security documentation

Architecture diagram, control mapping and data flow, provided for review under NDA.

Questionnaire support

We complete your standard assessment rather than returning a generic datasheet.

In-house security practice

Reviewed by our own cybersecurity team rather than outsourced at the end.

Penetration testing

Independent testing with remediation evidence, shared on request.

Data Residency

Deployment on Your Terms, Not the Licence’s.

Most platforms offer a single answer on where data is held: their cloud, their region, their terms. Where residency, sovereignty or regulatory obligations apply, that single answer is often the reason a capable product does not clear review. FortifAI treats storage location as a deployment decision rather than a consequence of the licence.

  • Deploy entirely within infrastructure you already own, operate and audit
  • Or use managed storage, with the facility and jurisdiction specified in the agreement
  • Or run both: a local copy for recovery speed, an offsite copy for site-level events, one console
  • Relocate later without repurchasing the platform, because portability is part of the design

Self-hosted

Your hardware, your facility, your physical access controls. Data does not leave the estate.

Managed

Named facility and jurisdiction, with location and retention terms in writing.

Hybrid

Local copy for rapid recovery, offsite copy for resilience against site-level events.

Yours in every model

Encrypted under keys you control, exportable in a documented format at any time.

Applied AI

Focused Where It Shortens an Outage

Not a conversational layer on a backup console. Four places where a model outperforms an engineer reading logs under pressure.

Clean point selection

Establishing when the damage began is the slowest phase of most recoveries.

Capability
  • Traces anomalies to first occurrence
  • Ranks recovery points by likely integrity
  • Shows what changed between candidates
  • Flags points that should not be trusted

Restore sequencing

Order matters. Restoring in the wrong sequence can extend an incident.

Capability
  • Maps dependencies before execution
  • Sequences the recovery steps
  • Predicts residual impact after restore
  • Surfaces manual prerequisites up front

Early detection

Detection only helps if it happens before the bad state reaches every retained copy.

Capability
  • Baselines normal change volume per object
  • Alerts on mass delete or bulk overwrite
  • Recognises encryption-shaped activity
  • Holds a known-good copy automatically

Incident reporting

The person briefing leadership is rarely the person running the restore.

Capability
  • Summarises scope and impact in plain language
  • Drafts the incident timeline
  • Produces the evidence pack
  • Translates technical state into operational terms

Every AI action is logged and reversible. Nothing destructive executes without a named human approval.

Records and relationships

Restoring rows is straightforward. Restoring them with relationships intact is the difficult part.

Configuration alongside data

Flows, layouts, permissions and validation rules, not only the records inside them.

Frequency where it matters

Daily across the environment, more frequently on the objects operations depend on.

Held off-platform

Stored outside Salesforce, so a platform incident does not remove the recovery option.

Specialist Capability

Salesforce Data and Metadata as One Recovery.

As a 5-Star Salesforce partner, this is the area we have least excuse to get wrong. Salesforce does not protect itself the way many assume, and native tooling is a blunt instrument when a single record from three weeks ago is what is needed.

The common failure is restoring data and finding the configuration around it has moved on: a validation rule that rejects the records being replaced, a flow firing on every insert, a field that no longer exists. FortifAI treats data and metadata as a single recovery operation, because operationally that is what it is.

Getting Started

A Recovery Review First, Not a Licence

We would rather establish what your actual exposure is before discussing a platform.

1

Discovery

What you operate, what the loss of it would mean, and what recovery has to look like. Ninety minutes.

2

Recovery review

An assessment of what is protected today and where the real gaps are. You keep the findings regardless.

3

Scoped pilot

One workload, one environment, a genuine restore test with a written result.

4

Rollout

Phased deployment against agreed recovery objectives, with rehearsal built into the schedule.

Pricing is scoped against what you are protecting and how fast it has to come back, agreed in writing before commitment, rather than a per gigabyte rate that grows with retention. Organisations engaging now receive preferential terms that carry forward.

Next Step

Tell Us What You Cannot Afford To Lose.

A ninety minute conversation about your recovery position, with a written assessment at the end. No obligation, and the findings are yours either way.