Legal

FedRAMP Rules of Behavior

Last updated: November 24, 2025

Fortreum operates a FedRAMP Moderate authorized compliance automation platform, powered by Kovr.ai, on AWS infrastructure. These Rules of Behavior establish security requirements for customer administrators, end users, contractors, and other authorized third parties accessing the platform.

On this page

1. System Access Standards

Authorized Use Only
Access systems exclusively for legitimate business purposes within the scope of your assigned role.

Least Privilege Principle
Permissions are limited to the duties necessary for your position. Contact security@kovr.ai if your access appears excessive for your role.

Information Classification
Systems handle FedRAMP Moderate impact data only. Do not process national security information or materials requiring a higher classification.

Credential Protection
Keep passwords, API keys, and multi-factor authentication codes confidential. Fortreum staff will never request your credentials.

Session Management

  • Authenticate manually only;
  • Avoid saving credentials in browsers;
  • Terminate sessions when finished; and
  • Lock workstations when away.
Incident Reporting
Report security events immediately to security@kovr.ai, including compromised credentials, suspicious activity, data spillage, and phishing attempts.

System Integrity
Unauthorized connections or integrations with external platforms require written approval.

Legal Compliance
Access constitutes consent to monitoring under federal Privacy Act regulations (5 U.S.C. § 552a).

Resource Stewardship
Use compute, storage, and network resources responsibly.

Information Boundaries
Access only the data required for your assigned responsibilities.

2. Technical Requirements

Browser Security Configuration

  • Use TLS 1.2+ with a minimum of 256-bit encryption;
  • Enable certificate validation and warnings;
  • Configure secure/non-secure connection alerts;
  • Close sessions before navigating elsewhere;
  • Enable certificate revocation checking; and
  • Clear cache, cookies, and temporary files on exit.

Acceptable Use Compliance
Circumventing your employer’s computer policies may violate the Computer Fraud and Abuse Act.

Questions
Contact your Customer Success Manager for clarifications on any of these technical requirements.

3. External Communications Standards

Confidentiality Obligations
Never disclose non-public information about Fortreum’s operations, implementations, or capabilities without explicit authorization.

Intellectual Property Respect
Honor trademarks, copyrights, trade secrets, and other proprietary information.

Personal Accountability
You are responsible for the accuracy and professionalism of content you publish.

Attribution and Disclosure
When discussing Fortreum publicly: include appropriate disclaimers, clearly identify your relationship to Fortreum, and base claims on verifiable sources.

Professional Conduct
Avoid harassment, defamation, discriminatory language, or other unprofessional behavior.

Customer and Partner Privacy
Never reference customers, partners, or employees publicly without their consent.

Proper Escalation Channels
Use official support channels to raise concerns rather than public platforms.

Common Sense Standard
Exercise sound judgment, protect privacy, maintain professionalism, and operate with integrity.

4. Acknowledgment

By accessing Fortreum systems, users acknowledge reading and agreeing to these Rules of Behavior.

Violations may result in access revocation, legal action, or other consequences.

Contact: security@kovr.ai