A Fortify 24x7 brand. Managed security programs for multi-site organizations across North America.Rate scheduleClient sign in
Enterprise Secure Systems
Paperwork

Privacy Policy

What gets collected the moment you buy a managed security program, the reason it is held, which platforms handle it for us, and what you may require us to do about it.

Revised24 August 2026
Coversenterprisesecuresystems.com
CounterpartyFortify 24x7
DescriptorFORTIFY 24X7
Section 01

Who this policy belongs to

Enterprise Secure Systems is a brand operated by Fortify 24x7. The contract with you is entered by Fortify 24x7, which retains what is described below and answers for the way all of it gets treated. Where this document says we or us, it means Fortify 24x7 acting under this brand.

This policy covers the website at enterprisesecuresystems.com, the client portal, and the managed security programs sold through them. It does not govern the separate privacy practices of any organization that links to us.

Section 02

What we collect

We keep the collection narrow on purpose, because data nobody holds is data nobody can lose. In practice there are four categories.

  • Account and contact details. The business email address used to purchase, the organization name, and the names and addresses of the people you nominate as technical or billing contacts.
  • Subscription records. Which controls you bought, in what quantities, when the subscription started, and its billing state. These reach us from the payment processor and from our own provisioning records.
  • Operational telemetry. Security and management data produced by the platforms running your programs: detections, device inventory and health, patch state, mail threat verdicts, discovery findings, and backup job outcomes.
  • Support correspondence. Cases you raise, the messages in them, and the notes our team adds while working them.
Section 03

Payment information

We never see, handle, or store your card number. Stripe runs the checkout and the card details go to Stripe alone. What returns to us amounts to a token, four trailing digits, the brand of card, and a yes or no on the charge.

Stripe processes payment data as an independent controller under its own terms and privacy policy. Refunds, chargebacks, and disputes run through the same channel. Your statement will carry the descriptor FORTIFY 24X7 rather than this brand name.

Section 04

Why we hold it

Each category exists for a stated reason, and we do not repurpose data collected for one into another use without telling you.

  • To provision, operate, and support the controls you purchased.
  • To detect, investigate, and respond to security events in your environment.
  • To bill the subscription and to keep the financial records the law requires of us.
  • To reach the people you nominated about incidents, service changes, and case updates.

Personal information is never sold here. None of it goes to advertising networks. Nothing in the operational telemetry is turned into a marketing profile.

Section 05

The platforms that process data for us

These programs run on established security platforms rather than tooling we wrote ourselves, and operating them means your data is processed by their vendors under contract with us. Which ones apply depends entirely on which controls you bought.

  • SentinelOne together with Fluency, covering endpoint detection and the correlation of logs.
  • ThreatLocker for application allowlisting and elevation.
  • Ironscales for mailbox-level mail defense and user training.
  • N-able N-sight, Addigy, and Zimperium for endpoint, Apple, and mobile management.
  • Actifile, covering discovery of sensitive data and its enforcement.
  • N-able Cove and Dropsuite for backup and tenant protection.
  • Stripe for payment processing, and our ticketing and email systems for support correspondence.

Each is engaged to deliver the service you bought and is not permitted to use your data for its own purposes. We will name the specific processors touching your account on request.

Section 06

When we disclose

Outside the processors above, we disclose data in only three circumstances: when you direct us to, when a valid legal process compels us and we are permitted to comply, and when disclosure is necessary to protect the safety or rights of a person. Where a lawful demand for your data turns up, and nothing bars us from saying as much, you will hear about it.

If the business is ever sold or reorganized, records may transfer with it. The protections in this policy travel with them.

Section 07

How long we keep it

Operational telemetry is retained for the window the relevant platform is configured for, which varies by control and is stated during onboarding. Support correspondence is kept while your account is active and for a period afterwards so that a returning client does not have to re-explain their own history. Billing records are held for the term applicable financial and tax rules require.

When a subscription ends, agents and connectors are retired and the associated tenant data is removed on the schedule the platform provides for it. You can ask us in writing to accelerate deletion of anything not subject to a retention obligation.

Section 08

Security of what we hold

Access to client data is restricted to the members of our team whose work requires it. Administrative access to the platforms is protected by multi-factor authentication, and credentials are held in a managed secret store rather than in documents, chat history, or anybody's browser.

We will not claim that any system is impossible to breach. What we will commit to is that if an incident affects your data, the people you nominated hear it from us directly and promptly, with what we know at the time rather than a delayed summary.

Section 09

Your choices

Ask and we will give you a copy of whatever personal information sits against your name. Ask and we will correct it, or erase anything no rule obliges us to retain, or take a nominated contact back off operational notifications. Send it to support@enterprisesecuresystems.com using an address the account already knows, and it gets verified before anybody acts.

Depending where you are located you may have additional statutory rights. We apply the handling described here to everyone regardless of jurisdiction, and we will honour a valid statutory request wherever it comes from.

Section 10

Cookies and site analytics

This site stores your selected controls in your own browser using local storage so that a schedule survives a page reload. None of it leaves your own device before checkout. The client portal stores a session token the same way, which is removed when you sign out.

No advertising tracker and no cross-site profiling runs on this domain.

Section 11

Children

These are commercial services sold to organizations. They are not directed at children, and we do not knowingly collect personal information from anyone under sixteen. If you believe we have, tell us and it will be deleted.

Section 12

Changes and how to reach us

A material change here revises the date printed above, and where it alters the handling of your data we tell the contacts on your account instead of trusting you to spot it.

Questions, requests, and complaints go to support@enterprisesecuresystems.com and reach a person on the Fortify 24x7 operations desk.