security and architecture / version 1.0
Security for production memory
A direct account of how Portals approaches valuable production assets: what is current, what depends on deployment or agreement, and what remains planned.
- status
- public brief
- version
- version 1.0
- published
- july 31, 2026
- certifications
- none
your production context is sensitive operational data.
Source media, prompts, client decisions, model settings, and lineage can carry commercial and intellectual-property value. Our security architecture is designed to protect it.
- logical organization isolation
- explicit access boundaries
- recoverable production history
- no training without written permission
our current security posture
Architecture, policy, operating position, and commitments.
Deployment-specific details and contractual controls are confirmed during pilot review.
Portals is a production repository for AI-native creative organizations. This brief describes the current product architecture, operating positions, customer-data policies, limitations, and planned security work as of July 31, 2026.
Portals is not represented as SOC 2 certified, ISO 27001 certified, HIPAA compliant, PCI compliant, or certified under another formal framework. Formal controls apply only when confirmed by a current certification document or signed agreement.
- Customer production assets should remain logically isolated by organization.
- Access should be governed by explicit user, team, and repository permissions.
- Creative history should be recoverable, auditable, and exportable.
- Customer production data is not training material without explicit written permission.
current status
No formal third-party security certification is claimed in this brief.
As of July 31, 2026, Portals does not claim SOC 2 Type I, SOC 2 Type II, ISO 27001, ISO 27701, HIPAA, PCI DSS, FedRAMP, GDPR certification, or CSA STAR certification.
planned certifications and security roadmap
The following work is planned or under evaluation. It is not complete, certified, scheduled, or contractually committed.
- SOC 2 readiness assessment, followed by Type I and Type II evaluation as operational maturity allows.
- Formal vendor-risk management and a published subprocessor list.
- Expanded audit-log export, retention controls, and administrative export controls.
- Enterprise SSO/SAML/OIDC support where not already available.
- A security questionnaire package, data-processing addendum, and published incident-response summary.
- Annual penetration-testing evaluation and a vulnerability-disclosure policy.
- Formal business-continuity and disaster-recovery documentation.
- Dedicated infrastructure and customer-managed encryption-key evaluation.