Security and compliance

Your clients trust you with sensitive data

Tax documents, contracts, personal details, payment information. Portico encrypts it, logs every access, and gives you the compliance tools to handle it responsibly — GDPR-ready out of the box.

Security built into every layer

Not a checklist of promises — these are the controls running in production today.

Encryption at rest

Every file, form response, and signature is encrypted before it touches disk. Your clients' tax documents, contracts, and personal data are unreadable without the decryption key.

Encrypted in transit

All data moving between your clients' browsers and Portico is encrypted. Every form submission, file upload, and API call is protected in transit — no exceptions.

Tamper-proof audit trail

Every action — form submission, file upload, signature, approval, status change — is logged with a timestamp and cryptographically linked to the previous entry using SHA-256 hashing. If anyone modifies or deletes a record, the chain breaks and the tampering is immediately detectable. Exportable as CSV.

Role-based access control

Team owners control who can view, edit, or manage onboardings. Invite team members with scoped permissions — no one gets access they do not need.

Secure file uploads

Every uploaded file is checked for type and size before it's stored. Files are validated on our servers, not in the browser, so restrictions cannot be bypassed.

Magic-link authentication

Clients access onboardings via single-use magic links — no passwords to leak, no accounts to breach. Each link works once and expires after use.

GDPR compliance

Data rights, not data headaches

Your clients have the right to see, export, and delete their data. Portico makes that a one-click operation — not a support ticket.
  • Consent collection

    Configurable consent checkboxes before every onboarding. Every response is timestamped and auditable.

  • One-click data export

    Export all client data — onboardings, responses, files, signatures, and messages — as a single downloadable archive. GDPR Article 20 compliance built in.

  • Right to erasure

    Built-in deletion workflow removes files, strips personal data from records, and generates a compliance certificate. GDPR Article 17 compliance in one click.

  • Configurable data retention

    Set automatic retention periods per team. Data is purged on schedule — no manual cleanup, no forgotten client files sitting on servers indefinitely.

Infrastructure

What Portico runs on

AWS infrastructure — the same provider behind the largest SaaS platforms in the world.
HostingSupabase on AWS (Amazon Web Services)
DatabasePostgreSQL with access scoped to each team
File storageAWS S3 with server-side encryption
Encryption at restAES-256
Encryption in transitTLS 1.2+
AuthenticationMagic links for clients, secure password hashing for staff accounts
API securityHashed API keys, rate limiting, security headers
Webhook securitySigned payloads with event timestamps for verification

Why it matters

Security as infrastructure, not afterthought

Most client onboarding tools treat security as a checklist. Portico treats it as a foundation.

Clients will ask how their data is protected

When a client sends you tax documents or contracts, they're trusting you with sensitive data. Portico gives you a clear answer: encrypted storage, access logging, and a security page you can point them to.

Audit trails that hold up

Every action is logged and cryptographically chained to the previous entry — you can prove that records have not been modified. Verify chain integrity in one click, export the full log as CSV.

GDPR is not optional for global businesses

If you serve clients in Europe, GDPR applies. Portico handles consent, data export, and erasure so you do not need a separate compliance workflow.

No passwords for clients to leak

Magic-link authentication means your clients never set a password. No password reuse, no "forgot password" support tickets. One link, one session, one onboarding.

Compliance

What's live and what's next

Encryption at rest and in transit
Tamper-proof audit trail
GDPR consent collection
Right to erasure (Article 17)
Data export (Article 20)
Configurable data retention
Secure file uploads
Signed webhook payloads
SOC 2 Type IIPlanned
ISO 27001Planned

Frequently Asked Questions

Security your clients can trust

Start free. No credit card required. Your data is encrypted from day one.

Start Free