Now Recruiting Beta Testers

Security & sovereignty

Portico is built for the OFFICIAL tier: UK data residency, multi-factor sign-in, a record of every access and edit, and an Information Governance pack that makes your DPO's job a sign-off.

The promise in one line

Each office's data is kept apart from every other's by the database itself, all of it stays in the UK, and every view and change of a constituent's record is logged with who did it and when.

How access works

Multi-factor sign-in

Staff sign in with a password and an authenticator app. Your office can require it of everyone; Portico staff always use it.

Mailboxes only when you choose

Connecting a mailbox is optional and separate. Portico reads only the mailbox a user connects.

Roles, not blanket access

Caseworkers, managers and administrators see what their role needs. Sensitive actions are for administrators only.

Sessions that end

Idle sessions sign out after fifteen minutes, and every session ends overnight.

Mapped to the NCSC 14 Cloud Security Principles

Public-sector IT teams evaluate suppliers against this matrix. Here is where Portico sits.

#PrinciplePortico
1Data in transit protectionHTTPS only, with HSTS.
2Asset protection & resilienceHosted in the UK (AWS eu-west-2). Encrypted at rest; encrypted backups.
3Separation between customersRow-level security in the database keeps each office's records apart.
4Governance frameworkNamed security owner; documented risk register.
5Operational securityVulnerability scanning on every change; patching; central logging. Cyber Essentials Plus targeted.
6Personnel securityLeast-privilege access for Portico staff.
7Secure developmentCode review, automated tests and dependency scanning before anything ships.
8Supply chain securitySub-processor register; DPAs in place.
9Secure user managementOffice administrators add and remove their own users; removal is immediate.
10Identity & authenticationPasswords plus authenticator-app MFA.
11External interface protectionMinimal surface; rate limiting; HTTPS only.
12Secure service administrationMFA and least privilege for administrators; privileged actions logged.
13Audit information for usersEach record shows who viewed and changed it; full history for administrators.
14Secure use of the serviceIG pack, integration notes and an IT runbook make secure setup straightforward.

Information Governance pack

For your DPO and IT team: DPIA support with the processor-side sections completed, a security and sovereignty paper with the full NCSC mapping, and a one-page brief for IT. Ask and we'll send it.

Special-category data. Constituent casework reveals political opinions (Article 9, UK GDPR) and often health and ethnicity. A DPIA is mandatory, and Portico is designed accordingly.