security and architecture / version 1.0

Security for production memory

A direct account of how Portals approaches valuable production assets: what is current, what depends on deployment or agreement, and what remains planned.

status
public brief
version
version 1.0
published
july 31, 2026
certifications
none

your production context is sensitive operational data.

Source media, prompts, client decisions, model settings, and lineage can carry commercial and intellectual-property value. Our security architecture is designed to protect it.

  • logical organization isolation
  • explicit access boundaries
  • recoverable production history
  • no training without written permission

our current security posture

Architecture, policy, operating position, and commitments.
Deployment-specific details and contractual controls are confirmed during pilot review.

Portals is a production repository for AI-native creative organizations. This brief describes the current product architecture, operating positions, customer-data policies, limitations, and planned security work as of July 31, 2026.

Portals is not represented as SOC 2 certified, ISO 27001 certified, HIPAA compliant, PCI compliant, or certified under another formal framework. Formal controls apply only when confirmed by a current certification document or signed agreement.

  • Customer production assets should remain logically isolated by organization.
  • Access should be governed by explicit user, team, and repository permissions.
  • Creative history should be recoverable, auditable, and exportable.
  • Customer production data is not training material without explicit written permission.

current status

No formal third-party security certification is claimed in this brief.

As of July 31, 2026, Portals does not claim SOC 2 Type I, SOC 2 Type II, ISO 27001, ISO 27701, HIPAA, PCI DSS, FedRAMP, GDPR certification, or CSA STAR certification.

planned certifications and security roadmap

The following work is planned or under evaluation. It is not complete, certified, scheduled, or contractually committed.

  • SOC 2 readiness assessment, followed by Type I and Type II evaluation as operational maturity allows.
  • Formal vendor-risk management and a published subprocessor list.
  • Expanded audit-log export, retention controls, and administrative export controls.
  • Enterprise SSO/SAML/OIDC support where not already available.
  • A security questionnaire package, data-processing addendum, and published incident-response summary.
  • Annual penetration-testing evaluation and a vulnerability-disclosure policy.
  • Formal business-continuity and disaster-recovery documentation.
  • Dedicated infrastructure and customer-managed encryption-key evaluation.

Frequently asked questions

no. the brief states the current security posture without claiming formal soc 2, iso, or other certifications that portals has not earned.

Download the security brief

the pdf contains the control inventory, current certification statement, planned roadmap, legal note, and internal navigation.

By submitting, you agree that we may contact you about this request. see our privacy policy.

Scope a paid pilot