Governance

Privacy Policy & Information Security Statement

This policy describes how Fjornsen processes information and how our Information Security Management System (ISMS) is aligned to ISO/IEC 27001:2022. It applies to the Fjornsen platform, its monitoring consoles and supporting infrastructure.

Version 2.0 · Effective 18 August 2026 · Owner: Information Security Officer

ISMS scope

The design, operation and support of the Fjornsen cyber defense platform, including threat detection, counter-intelligence operations and site monitoring services, delivered from hardened cloud infrastructure. Statement of Applicability and risk treatment plan are maintained internally and available to customers under NDA.

1. Data we process

Operational telemetry: domain names you choose to monitor, TLS handshake metadata, HTTP response headers, availability and latency measurements.

Security telemetry: source IP addresses, user-agent strings and request patterns observed while defending protected endpoints.

We do not collect payload contents, form submissions or end-user personal data from the sites you monitor.

2. Lawful basis and purpose

Processing is carried out on the basis of legitimate interests (network and information security) under GDPR Art. 6(1)(f), and on contract where you are a subscribing customer.

Data is used solely to detect, investigate and neutralise threats, and to produce security reporting for the account owner.

3. Your rights

You may request access, rectification, erasure, restriction, portability or object to processing at any time.

Requests are acknowledged within 5 working days and resolved within 30 days. Contact privacy@fjornsen.com.

Site lists added in Site Monitor are stored in your browser's local storage and can be deleted by you at any time without contacting us.

4. Retention and deletion

Security event logs: 12 months, then irreversibly deleted or aggregated.

Forensic evidence packages tied to an open investigation: retained until case closure plus 90 days.

Account and billing records: retained for the statutory period required by applicable law.

5. Sub-processors and transfers

A current list of sub-processors is available on request. All sub-processors are contractually bound to equivalent security obligations.

Any transfer outside the EEA/UK relies on Standard Contractual Clauses with a documented transfer impact assessment.

6. ISO/IEC 27001:2022 Annex A control alignment

ControlImplementation
A.5.1

Policies for information security

This policy is reviewed at least annually and after any material change.
A.5.12

Classification of information

Monitoring telemetry classified as Internal; credentials as Restricted.
A.5.34

Privacy and protection of PII

Data minimisation by default — site lists stay in the operator's browser.
A.8.5

Secure authentication

MFA enforced for all console operators; no shared accounts.
A.8.12

Data leakage prevention

Egress filtering and dark-web credential monitoring.
A.8.16

Monitoring activities

Continuous 30-second check cycle with tamper-evident logging.
A.8.24

Use of cryptography

TLS 1.3 in transit, AES-256-GCM at rest, keys rotated on schedule.
A.5.24

Incident management planning

Documented response plan; 72-hour breach notification commitment.

Alignment statements describe controls we operate. Where a formal certification status is required for procurement, request the current certificate and Statement of Applicability from compliance@fjornsen.com.

7. Contact

Data protection enquiries: privacy@fjornsen.com · Security vulnerabilities: security@fjornsen.com · Postal enquiries available on request.