AI-powered supply chain security for critical infrastructure
Fortress defends critical infrastructure and government agencies against supply chain cyber threats using an AI-powered platform. The tech stack reveals a modern, containerized architecture (Kubernetes, AWS Lambda, CloudFormation) paired with security-first infrastructure (Vault, RDS, VPC). Active infrastructure work—migrating secrets to Vault, transitioning legacy apps to containers, and hardening CI/CD pipelines—shows the company is consolidating deployment tooling and moving away from Ansible toward Kubernetes-native automation. Hiring is concentrated in security and product roles, with a senior-weighted mix suggesting focus on deepening threat intelligence and vendor risk assessment capabilities.
Fortress provides AI-powered cybersecurity solutions for critical infrastructure operators, government agencies, and their supply chains. Founded in 2015 and headquartered in Orlando, the company specializes in supply chain security, third-party risk management, vulnerability management, and SBOM-based threat detection. The product surfaces around defending against both direct cyber threats and supply chain attack vectors. Active work includes vulnerability management program optimization, GRC roadmap evolution, and CI/CD modernization—indicating both customer-facing capability maturation and internal infrastructure investment to support mission-critical deployments.
Fortress runs on AWS (Lambda, RDS, ECR, CloudWatch, VPC, API Gateway), Kubernetes, Jenkins, Terraform, and HashiCorp Vault. Data layers include MongoDB and PostgreSQL. The stack also includes Python, JavaScript, and Bash for automation.
Current projects include migrating legacy applications to Kubernetes, implementing advanced CI/CD strategies (blue/green, canary), optimizing vulnerability management programs, transitioning secrets to HashiCorp Vault, and defining a GRC roadmap for compliance and risk governance.
Other companies in the same industry, closest in size