Security
Security you
can trust.
Your data and your clients' data are protected by multiple independent security layers — from the database all the way to the browser.
How we protect your data
Defence in depth
We do not rely on a single security control. Every layer of the platform has independent protections so that a failure in one does not compromise the rest.
Encrypted everywhere
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. This applies to every file, message, and invoice stored on the platform — including database backups.
- TLS 1.3 for all connections
- AES-256 encryption at rest
- Encrypted database backups
No-password client access
Clients access their portals via time-limited, cryptographically signed magic-link tokens — not passwords. There are no client accounts to create, compromise, or forget. Tokens are single-use and expire after 24 hours.
- HMAC-signed access tokens
- SHA-256 hashed — plain token never stored
- 24-hour expiry, single-use
- Instant link revocation by freelancer
Row-level security
Every query is enforced by row-level security (RLS) policies at the database layer — not just at the application layer. Freelancers can only ever read and write their own data.
- RLS on every table
- Granular per-client permissions
- Principle of least privilege enforced
Ongoing security review
We conduct internal security reviews before every major release and maintain a responsible disclosure programme for external researchers.
- Pre-release security reviews
- Responsible disclosure programme
- Automated dependency scanning
Standards & compliance
Built to meet global standards
Compliant with the Personal Data Protection Act No. 9 of 2022. Data subject rights honoured for all users.
CompliantE-signed contracts are legally valid under the Electronic Transactions Act No. 19 of 2006. Signature metadata and audit logs retained.
CompliantData processing agreements available for EU and UK customers. Standard Contractual Clauses used for cross-border transfers.
CompliantCalifornia privacy rights honoured for all users. We do not sell or share personal data.
CompliantCompliant with the Privacy Act 1988 (Cth), Australian Privacy Principles, and 2024 reform obligations.
CompliantResponsible disclosure
We welcome security researchers who responsibly disclose vulnerabilities. If you discover a security issue in PortalKit, email security@portalkit.app with a detailed description of the issue and steps to reproduce it. We follow a 90-day coordinated disclosure timeline.
We aim to acknowledge all reports within 48 hours and resolve confirmed vulnerabilities within 30 days. Please do not access user data beyond what is strictly necessary to prove the vulnerability, and allow us reasonable time to issue a fix before public disclosure.
Note: the Sri Lanka Computer Crimes Act No. 24 of 2007 applies to any unauthorised system access. Researchers acting in good faith and within the scope described above are not our target — but we strongly recommend obtaining written authorisation before conducting any active testing.
Data practices
We do not sell your data or your clients' data. Files, invoices, and messages you store on PortalKit are used solely to provide the Service. Our engineers access customer data only when necessary to diagnose a reported issue, and only with appropriate access controls in place.
For full details on how we handle personal information, see our Privacy Policy.
Questions about security?
Our team is happy to answer detailed security questions before you commit to any plan.