©2026 Fortreum. All Rights Reserved. | Privacy Policy | Terms Of Use | Customer Agreement | FedRAMP Rules of Behavior
Legal
FedRAMP Rules of Behavior
Last updated: November 24, 2025
Fortreum operates a FedRAMP Moderate authorized compliance automation platform, powered by Kovr.ai, on AWS infrastructure. These Rules of Behavior establish security requirements for customer administrators, end users, contractors, and other authorized third parties accessing the platform.
On this page
1. System Access Standards
Authorized Use Only
Access systems exclusively for legitimate business purposes within the scope of your assigned role.
Least Privilege Principle
Permissions are limited to the duties necessary for your position. Contact security@kovr.ai if your access appears excessive for your role.
Information Classification
Systems handle FedRAMP Moderate impact data only. Do not process national security information or materials requiring a higher classification.
Systems handle FedRAMP Moderate impact data only. Do not process national security information or materials requiring a higher classification.
Credential Protection
Keep passwords, API keys, and multi-factor authentication codes confidential. Fortreum staff will never request your credentials.
Keep passwords, API keys, and multi-factor authentication codes confidential. Fortreum staff will never request your credentials.
Session Management
- Authenticate manually only;
- Avoid saving credentials in browsers;
- Terminate sessions when finished; and
- Lock workstations when away.
Incident Reporting
Report security events immediately to security@kovr.ai, including compromised credentials, suspicious activity, data spillage, and phishing attempts.
Report security events immediately to security@kovr.ai, including compromised credentials, suspicious activity, data spillage, and phishing attempts.
System Integrity
Unauthorized connections or integrations with external platforms require written approval.
Unauthorized connections or integrations with external platforms require written approval.
Legal Compliance
Access constitutes consent to monitoring under federal Privacy Act regulations (5 U.S.C. § 552a).
Access constitutes consent to monitoring under federal Privacy Act regulations (5 U.S.C. § 552a).
Resource Stewardship
Use compute, storage, and network resources responsibly.
Use compute, storage, and network resources responsibly.
Information Boundaries
Access only the data required for your assigned responsibilities.
Access only the data required for your assigned responsibilities.
2. Technical Requirements
Browser Security Configuration
- Use TLS 1.2+ with a minimum of 256-bit encryption;
- Enable certificate validation and warnings;
- Configure secure/non-secure connection alerts;
- Close sessions before navigating elsewhere;
- Enable certificate revocation checking; and
- Clear cache, cookies, and temporary files on exit.
Acceptable Use Compliance
Circumventing your employer’s computer policies may violate the Computer Fraud and Abuse Act.
Questions
Contact your Customer Success Manager for clarifications on any of these technical requirements.
3. External Communications Standards
Confidentiality Obligations
Never disclose non-public information about Fortreum’s operations, implementations, or capabilities without explicit authorization.
Never disclose non-public information about Fortreum’s operations, implementations, or capabilities without explicit authorization.
Intellectual Property Respect
Honor trademarks, copyrights, trade secrets, and other proprietary information.
Honor trademarks, copyrights, trade secrets, and other proprietary information.
Personal Accountability
You are responsible for the accuracy and professionalism of content you publish.
You are responsible for the accuracy and professionalism of content you publish.
Attribution and Disclosure
When discussing Fortreum publicly: include appropriate disclaimers, clearly identify your relationship to Fortreum, and base claims on verifiable sources.
When discussing Fortreum publicly: include appropriate disclaimers, clearly identify your relationship to Fortreum, and base claims on verifiable sources.
Professional Conduct
Avoid harassment, defamation, discriminatory language, or other unprofessional behavior.
Avoid harassment, defamation, discriminatory language, or other unprofessional behavior.
Customer and Partner Privacy
Never reference customers, partners, or employees publicly without their consent.
Never reference customers, partners, or employees publicly without their consent.
Proper Escalation Channels
Use official support channels to raise concerns rather than public platforms.
Use official support channels to raise concerns rather than public platforms.
Common Sense Standard
Exercise sound judgment, protect privacy, maintain professionalism, and operate with integrity.
Exercise sound judgment, protect privacy, maintain professionalism, and operate with integrity.
4. Acknowledgment
By accessing Fortreum systems, users acknowledge reading and agreeing to these Rules of Behavior.
Violations may result in access revocation, legal action, or other consequences.
Contact: security@kovr.ai
