Security & sovereignty
Portico is built for the OFFICIAL tier: UK data residency, multi-factor sign-in, a record of every access and edit, and an Information Governance pack that makes your DPO's job a sign-off.
The promise in one line
Each office's data is kept apart from every other's by the database itself, all of it stays in the UK, and every view and change of a constituent's record is logged with who did it and when.
How access works
Multi-factor sign-in
Staff sign in with a password and an authenticator app. Your office can require it of everyone; Portico staff always use it.
Mailboxes only when you choose
Connecting a mailbox is optional and separate. Portico reads only the mailbox a user connects.
Roles, not blanket access
Caseworkers, managers and administrators see what their role needs. Sensitive actions are for administrators only.
Sessions that end
Idle sessions sign out after fifteen minutes, and every session ends overnight.
Mapped to the NCSC 14 Cloud Security Principles
Public-sector IT teams evaluate suppliers against this matrix. Here is where Portico sits.
| # | Principle | Portico |
|---|---|---|
| 1 | Data in transit protection | HTTPS only, with HSTS. |
| 2 | Asset protection & resilience | Hosted in the UK (AWS eu-west-2). Encrypted at rest; encrypted backups. |
| 3 | Separation between customers | Row-level security in the database keeps each office's records apart. |
| 4 | Governance framework | Named security owner; documented risk register. |
| 5 | Operational security | Vulnerability scanning on every change; patching; central logging. Cyber Essentials Plus targeted. |
| 6 | Personnel security | Least-privilege access for Portico staff. |
| 7 | Secure development | Code review, automated tests and dependency scanning before anything ships. |
| 8 | Supply chain security | Sub-processor register; DPAs in place. |
| 9 | Secure user management | Office administrators add and remove their own users; removal is immediate. |
| 10 | Identity & authentication | Passwords plus authenticator-app MFA. |
| 11 | External interface protection | Minimal surface; rate limiting; HTTPS only. |
| 12 | Secure service administration | MFA and least privilege for administrators; privileged actions logged. |
| 13 | Audit information for users | Each record shows who viewed and changed it; full history for administrators. |
| 14 | Secure use of the service | IG pack, integration notes and an IT runbook make secure setup straightforward. |
Information Governance pack
For your DPO and IT team: DPIA support with the processor-side sections completed, a security and sovereignty paper with the full NCSC mapping, and a one-page brief for IT. Ask and we'll send it.
Special-category data. Constituent casework reveals political opinions (Article 9, UK GDPR) and often health and ethnicity. A DPIA is mandatory, and Portico is designed accordingly.