Your privacy is fundamental to Bastion Forge. As a compliance security platform, we are held to the highest standards of data protection. This policy explains exactly what data we collect, why we collect it, and how we protect it.
01 Overview and Scope
This Privacy Policy applies to Bastion Forge Cloud Solutions, LLC, a veteran-owned limited liability company organized under the laws of the State of Georgia. It covers all information collected through bastionforge.tech and our cloud compliance platform.
Bastion Forge operates as both a Data Controller (for account and business information) and a Business Associate under HIPAA (for client-uploaded Protected Health Information where a Business Associate Agreement is in place).
This policy does not apply to third-party websites or services linked from our platform.
02 Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information from third-party services.
| Category | Data Collected | Purpose |
|---|---|---|
| Account Information | Full name, company name, email address, phone number, job title | Account creation and management |
| Payment Information | Billing address, payment method token (processed by Stripe — we do not store card numbers) | Subscription billing |
| Company Data | Industry type, company size, compliance frameworks applicable | Service configuration and compliance monitoring |
| Uploaded Documents | Compliance documents, audit records, and other files you upload to your vault | Secure immutable storage per your subscription |
| Usage Data | Login timestamps, feature usage, API call logs, dashboard activity | Security monitoring, audit trail, service improvement |
| Technical Data | IP address, browser type, operating system, device identifiers | Security monitoring and fraud prevention |
03 How We Use Your Information
Bastion Forge uses collected information for the following purposes:
- Service Delivery — Provision, maintenance, and improvement of your compliance storage platform
- Security Monitoring — Detecting and responding to security threats, unauthorized access attempts, and anomalous activity through our Chiron agent
- Compliance Monitoring — Tracking regulatory changes relevant to your industry through our Vallonia agent
- Financial Reporting — Generating compliance and billing reports through our Plutus agent
- Communication — Sending account notifications, security alerts, monthly compliance briefings, and service updates
- Legal Compliance — Meeting our obligations under HIPAA, applicable state laws, and other regulations
- Audit Trail — Maintaining tamper-proof logs of all platform activity as required for compliance purposes
We do not sell your personal information to third parties. We do not use your data for advertising purposes.
05 HIPAA and Protected Health Information
For healthcare clients who have executed a Business Associate Agreement (BAA) with Bastion Forge, we handle Protected Health Information (PHI) in accordance with HIPAA requirements:
- PHI is stored exclusively in AWS us-east-1 with HIPAA-eligible services
- PHI is encrypted at rest using AES-256 via AWS KMS
- PHI is encrypted in transit using TLS 1.2 or higher
- Access to PHI is logged in an immutable CloudTrail audit record
- PHI is subject to S3 Object Lock ensuring it cannot be altered or deleted
- Breach notification procedures follow HIPAA requirements (notification within 60 days of discovery)
Healthcare clients: A signed BAA is required before any PHI is uploaded to the platform. Contact Xavier@bastionforge.tech to execute your BAA.
06 Data Security
Bastion Forge implements enterprise-grade security controls to protect your data:
- Encryption at Rest — AES-256 encryption for all stored data via AWS KMS
- Encryption in Transit — TLS 1.2+ for all data transmission
- Immutable Storage — S3 Object Lock in COMPLIANCE mode prevents unauthorized modification or deletion
- Multi-Factor Authentication — Required for all platform access
- Continuous Monitoring — AWS GuardDuty and Security Hub provide 24/7 threat detection
- Tamper-Proof Audit Trail — AWS CloudTrail logs all API activity immutably
- Penetration Testing — Regular security assessments of platform infrastructure
- Access Controls — Principle of least privilege applied to all system access
While we implement industry-leading security measures, no system is 100% secure. In the event of a security incident affecting your data, we will notify you in accordance with applicable law and our BAA obligations.
07 Data Retention
Bastion Forge retains data according to the following schedule:
| Data Type | Retention Period | Basis |
|---|---|---|
| Compliance documents in vault | 7 years minimum (or per regulatory requirement) | HIPAA, FINRA, SEC requirements |
| Audit trail logs (CloudTrail) | 7 years | HIPAA Security Rule |
| Account information | Duration of subscription + 30 days | Service delivery |
| Payment records | 7 years | Tax and financial compliance |
| Security logs | 1 year | Security monitoring |
After account cancellation, your data will be retained for 30 days to allow for data export before deletion. Compliance documents may be retained longer as required by applicable law.
08 Your Rights and Choices
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- Access — Request a copy of the personal information we hold about you
- Correction — Request correction of inaccurate information
- Deletion — Request deletion of your personal information (subject to legal retention requirements)
- Portability — Request your data in a portable format
- Objection — Object to certain processing of your information
- Withdrawal of Consent — Where processing is based on consent, withdraw that consent
To exercise any of these rights, contact us at Xavier@bastionforge.tech. We will respond within 30 days. Note that some requests may be limited by our legal obligations, particularly for compliance data subject to mandatory retention periods.
09 Cookies and Tracking
Bastion Forge uses minimal cookies necessary for platform functionality:
- Authentication Cookies — Session tokens required to keep you logged in. These are essential and cannot be disabled.
- Security Cookies — CSRF tokens and other security mechanisms required to protect your account.
We do not use advertising cookies, tracking pixels, or third-party analytics that share your data with advertisers. We do not use Google Analytics or similar tracking services.
10 Children's Privacy
Bastion Forge services are intended for business use only and are not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will delete it promptly.
11 Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. When we make material changes, we will:
- Update the effective date at the top of this page
- Send an email notification to all registered clients
- Display a prominent notice on our platform
We encourage you to review this policy periodically. Your continued use of our Services after any update constitutes acceptance of the revised policy.
12 Contact Us
For privacy-related questions, data requests, or to report a privacy concern, please contact our Privacy Officer:
Privacy Officer — Bastion Forge Cloud Solutions, LLC
Moultrie, Georgia, United States
Email: Xavier@bastionforge.tech
Website: bastionforge.tech
Response time: Within 30 days of receipt