Early Access: 40% off on paid plans — limited spotsSee pricing →
PortalKitPortalKit
PlatformAboutBlogPricing
Log InGet Started

Security

Security you
can trust.

Last updated: 30 June 2026

Your data and your clients' data are protected by multiple independent security layers — from the database all the way to the browser.

How we protect your data

Defence in depth

We do not rely on a single security control. Every layer of the platform has independent protections so that a failure in one does not compromise the rest.

Encrypted everywhere

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. This applies to every file, message, and invoice stored on the platform — including database backups.

  • TLS 1.3 for all connections
  • AES-256 encryption at rest
  • Encrypted database backups

No-password client access

Clients access their portals via time-limited, cryptographically signed magic-link tokens — not passwords. There are no client accounts to create, compromise, or forget. Tokens are single-use and expire after 24 hours.

  • HMAC-signed access tokens
  • SHA-256 hashed — plain token never stored
  • 24-hour expiry, single-use
  • Instant link revocation by freelancer

Row-level security

Every query is enforced by row-level security (RLS) policies at the database layer — not just at the application layer. Freelancers can only ever read and write their own data.

  • RLS on every table
  • Granular per-client permissions
  • Principle of least privilege enforced

Ongoing security review

We conduct internal security reviews before every major release and maintain a responsible disclosure programme for external researchers.

  • Pre-release security reviews
  • Responsible disclosure programme
  • Automated dependency scanning

Standards & compliance

Built to meet global standards

Sri Lanka PDPA 2022

Compliant with the Personal Data Protection Act No. 9 of 2022. Data subject rights honoured for all users.

Compliant
Sri Lanka ETA 2006

E-signed contracts are legally valid under the Electronic Transactions Act No. 19 of 2006. Signature metadata and audit logs retained.

Compliant
GDPR / UK GDPR

Data processing agreements available for EU and UK customers. Standard Contractual Clauses used for cross-border transfers.

Compliant
CCPA / CPRA

California privacy rights honoured for all users. We do not sell or share personal data.

Compliant
AU Privacy Act

Compliant with the Privacy Act 1988 (Cth), Australian Privacy Principles, and 2024 reform obligations.

Compliant

Responsible disclosure

We welcome security researchers who responsibly disclose vulnerabilities. If you discover a security issue in PortalKit, email security@portalkit.app with a detailed description of the issue and steps to reproduce it. We follow a 90-day coordinated disclosure timeline.

We aim to acknowledge all reports within 48 hours and resolve confirmed vulnerabilities within 30 days. Please do not access user data beyond what is strictly necessary to prove the vulnerability, and allow us reasonable time to issue a fix before public disclosure.

Note: the Sri Lanka Computer Crimes Act No. 24 of 2007 applies to any unauthorised system access. Researchers acting in good faith and within the scope described above are not our target — but we strongly recommend obtaining written authorisation before conducting any active testing.

Data practices

We do not sell your data or your clients' data. Files, invoices, and messages you store on PortalKit are used solely to provide the Service. Our engineers access customer data only when necessary to diagnose a reported issue, and only with appropriate access controls in place.

For full details on how we handle personal information, see our Privacy Policy.

Questions about security?

Our team is happy to answer detailed security questions before you commit to any plan.

Contact usStart for free
TLS 1.3 encrypted
AES-256 at rest
GDPR compliant
PortalKitPortalKit

Built for freelancers.
Loved by clients.

Product

  • Platform
  • Pricing
  • Security

Company

  • About
  • Blog
  • Guides

Support

  • Contact
  • Leave a Feedback

© 2026 PortalKit. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyRefund Policy
TLS 1.3

All platform connections use TLS 1.3. Older TLS versions are rejected.

Enforced
AES-256

Industry-standard encryption for all data at rest via Supabase managed storage, including database backups.

Enforced
SOC 2 Type II

We are actively working towards SOC 2 Type II certification.

In progress