Governance
Privacy Policy & Information Security Statement
This policy describes how Fjornsen processes information and how our Information Security Management System (ISMS) is aligned to ISO/IEC 27001:2022. It applies to the Fjornsen platform, its monitoring consoles and supporting infrastructure.
Version 2.0 · Effective 18 August 2026 · Owner: Information Security Officer
ISMS scope
The design, operation and support of the Fjornsen cyber defense platform, including threat detection, counter-intelligence operations and site monitoring services, delivered from hardened cloud infrastructure. Statement of Applicability and risk treatment plan are maintained internally and available to customers under NDA.
1. Data we process
Operational telemetry: domain names you choose to monitor, TLS handshake metadata, HTTP response headers, availability and latency measurements.
Security telemetry: source IP addresses, user-agent strings and request patterns observed while defending protected endpoints.
We do not collect payload contents, form submissions or end-user personal data from the sites you monitor.
2. Lawful basis and purpose
Processing is carried out on the basis of legitimate interests (network and information security) under GDPR Art. 6(1)(f), and on contract where you are a subscribing customer.
Data is used solely to detect, investigate and neutralise threats, and to produce security reporting for the account owner.
3. Your rights
You may request access, rectification, erasure, restriction, portability or object to processing at any time.
Requests are acknowledged within 5 working days and resolved within 30 days. Contact privacy@fjornsen.com.
Site lists added in Site Monitor are stored in your browser's local storage and can be deleted by you at any time without contacting us.
4. Retention and deletion
Security event logs: 12 months, then irreversibly deleted or aggregated.
Forensic evidence packages tied to an open investigation: retained until case closure plus 90 days.
Account and billing records: retained for the statutory period required by applicable law.
5. Sub-processors and transfers
A current list of sub-processors is available on request. All sub-processors are contractually bound to equivalent security obligations.
Any transfer outside the EEA/UK relies on Standard Contractual Clauses with a documented transfer impact assessment.
6. ISO/IEC 27001:2022 Annex A control alignment
| Control | Implementation |
|---|---|
| A.5.1 Policies for information security | This policy is reviewed at least annually and after any material change. |
| A.5.12 Classification of information | Monitoring telemetry classified as Internal; credentials as Restricted. |
| A.5.34 Privacy and protection of PII | Data minimisation by default — site lists stay in the operator's browser. |
| A.8.5 Secure authentication | MFA enforced for all console operators; no shared accounts. |
| A.8.12 Data leakage prevention | Egress filtering and dark-web credential monitoring. |
| A.8.16 Monitoring activities | Continuous 30-second check cycle with tamper-evident logging. |
| A.8.24 Use of cryptography | TLS 1.3 in transit, AES-256-GCM at rest, keys rotated on schedule. |
| A.5.24 Incident management planning | Documented response plan; 72-hour breach notification commitment. |
Alignment statements describe controls we operate. Where a formal certification status is required for procurement, request the current certificate and Statement of Applicability from compliance@fjornsen.com.
7. Contact
Data protection enquiries: privacy@fjornsen.com · Security vulnerabilities: security@fjornsen.com · Postal enquiries available on request.