Security

Protecting PORTIQA and its users.

Security controls are designed around a narrow API surface, delegated identity and payment providers, revocable bearer credentials, and minimal payload logging.

Current controls

Your part

Treat an API key like a password. Keep it in a secret manager or server-side environment variable; never embed it in browser code, mobile binaries, public repositories, screenshots, or support messages. Regenerate it immediately if exposure is suspected.

Report a vulnerability

Email security@portiqa.com with the affected URL, reproducible steps, impact, and any safe proof of concept. Do not access other users’ data, degrade availability, use social engineering, or retain data encountered during testing.

We ask for reasonable time to investigate and remediate before public disclosure. We do not claim a certification, external audit, or bug-bounty reward that has not been formally established.

Operational transparency

Current service information is published on the status page. Privacy and sub-processor details are in the Privacy Policy.