1. Our commitment
Security is considered throughout the platform lifecycle, from design to operation. We apply technical and organizational measures proportionate to the risks and adapt them as the service evolves. This page intentionally provides a general overview: sensitive configurations, internal procedures and architecture details are not made public.
2. Data protection
Access to the platform uses HTTPS. Information exchanged is protected by encryption mechanisms appropriate to its sensitivity, and passwords are hashed rather than stored in plain text. To avoid weakening these protections, we do not publish algorithms, keys, configurations or technical diagrams.
3. Account protection
Authentication mechanisms and safeguards for sensitive actions are designed to reduce unauthorized access. You support this protection by using a long, unique and hard-to-guess password, enabling available security options and regularly reviewing your account activity.
4. Sessions and security cookies
Sessions use secure cookies designed to keep you signed in without exposing credentials. Appropriate protections limit interception, tampering, session hijacking and fraudulent requests. Their technical settings, lifetime and internal validation mechanisms are intentionally not disclosed.
5. Access control
Access to systems and data is limited to the people and services that need it to perform their duties. Permissions follow the principle of least privilege, sensitive operations are controlled, and important events are logged to support the detection and analysis of unusual activity.
6. Resilience and continuity
Backup, recovery and continuity mechanisms help preserve service availability and data integrity. They are designed to limit the impact of a failure or incident and enable controlled recovery, without publishing operational information that could reduce their effectiveness.
7. Monitoring and prevention
Relevant technical and security events are monitored to identify unusual behavior, attempted abuse and service degradation. Preventive controls, usage limits and alerts complement this monitoring. Collected signals are used only for security, reliability and service improvement.
8. Updates and vulnerabilities
Platform components are reviewed regularly. Identified updates and vulnerabilities are assessed and addressed according to their level of risk. Significant changes are reviewed and verified before release to reduce errors and security regressions.
9. Incident response
When a security incident is suspected, our approach is to assess it, contain its effects, correct its cause and restore the service safely. We then review the event to strengthen protections. Where required by law, the competent authorities and affected people are informed within the applicable time limits.
10. Good practices for users
Never share your credentials or a verification code. Use a unique password, be cautious with urgent or unexpected messages, check the website address before signing in, and sign out of shared devices. Portfoler will never ask for your full password by email, message or phone.
11. Report a security concern
If you believe you have found a weakness or notice suspicious activity, contact us through the contact form and describe the issue accurately, without sending passwords, secrets or unnecessary personal data. Do not exploit the weakness, disrupt the service or access other people's data. Your report will be reviewed carefully.