P
Porter

Trust & Security

Last updated: March 2026

Porter is built for organisations that take security seriously. This page describes our security practices, data handling procedures, and compliance posture. If you have questions not covered here, contact our security team directly.

1. Security Overview

Porter is a cloud-hosted visitor management platform. We process visitor check-in data, host notifications, contractor compliance documents, and organisational configuration on behalf of our customers. Security is a core requirement, not an afterthought.

  • All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control (RBAC) with seven built-in roles
  • Immutable audit logging of all administrative and security events
  • Automated data retention and GDPR deletion workflows
  • Rate limiting on all authentication and public endpoints
  • CSRF protection via origin validation on state-changing requests

2. Infrastructure & Hosting

Porter runs on Railway, a cloud platform built on top of Google Cloud infrastructure. Our production environment is deployed in European data centres to support UK and EU data residency requirements.

  • Application hosting: Railway (Google Cloud Platform underlying infrastructure)
  • Database: PostgreSQL on Railway with encrypted backups and a documented restore procedure. Files uploaded to Porter (contractor documents, visitor photographs and signatures) are held in this database alongside the records they belong to.
  • Region: European Union. Both the application and the database run in Google Cloud's europe-west4 region, in the Netherlands. Section 6 of the Data Processing Agreement states the same, and the current region detail is confirmed on request.
  • Monitoring: Automated health checks

3. Encryption

All communication between clients and Porter servers is encrypted using TLS 1.2 or higher. We enforce HTTPS on all endpoints with no fallback to unencrypted connections.

  • In transit: TLS 1.2+ with modern cipher suites
  • At rest: AES-256 encryption on all database volumes
  • Passwords: Hashed with bcrypt (cost factor 12), never stored in plain text
  • API keys: Stored as SHA-256 hashes; the raw key is only shown once at creation
  • Session tokens: Signed with HS256 JWTs, short-lived (15 min) with secure refresh rotation

4. Access Controls

Porter implements role-based access control with strict tenant isolation. Every API request is authenticated and authorised against the user's role and organisation membership.

RolePermissions
OwnerFull access including billing, team management, and security settings
AdminAll operational access; cannot transfer ownership
Location AdminManage assigned locations, kiosks, and local team members
ReceptionistCheck in/out visitors, manage deliveries, view visitor log
HostView own visitors, approve visits, receive notifications
SecurityView on-site visitors, evacuation controls, blocklist management
Read-OnlyView-only access to visitor logs and analytics

Administrators can further restrict team invitations to specific email domains (e.g. only @company.com addresses), and configure session timeout policies.

5. Data Handling

Porter acts as a Data Processor on behalf of our customers (Data Controllers). We only process personal data as instructed by the customer through their use of the platform.

  • Storage location: EU-based PostgreSQL database
  • Data retention: Configurable per organisation (30 days to indefinite). Automated deletion of expired records.
  • Data export: Full GDPR data export available via the dashboard (JSON format)
  • Data deletion: Organisations can submit deletion requests through the dashboard. Individual visitor records can also be deleted on request.
  • Backups: Automated daily database backups with 7-day retention. Backups are encrypted at rest.

6. GDPR Compliance

Porter is designed from the ground up for GDPR compliance.

  • Lawful basis: The controller's legitimate interest in workplace security and safety, disclosed to visitors via a privacy notice shown at the point of check-in
  • Affirmative-action logging: Genuine affirmative actions such as NDA signing are recorded with timestamp, IP address, and user agent
  • Data minimisation: We only collect data necessary for visitor management
  • Right to erasure: Supported via dashboard GDPR request workflow
  • Right to portability: JSON data export available for organisations via the dashboard
  • Data Processing Agreement: Available at /dpa
  • Privacy Policy: Available at /privacy

7. Sub-processors

Porter uses the following third-party services to deliver the platform. Each sub-processor has been evaluated for security and GDPR compliance.

Sub-processorPurposeData Location
RailwayApplication hosting and PostgreSQL databaseEuropean Union
StripePayment processing and subscription billingUS (PCI DSS Level 1)
ResendTransactional email delivery (notifications, invites)US
TwilioSMS notifications for host alertsUS
PostHogProduct analytics, only after cookie consent is givenEuropean Union
SentryError monitoring. Diagnostic data, which may incidentally contain personal dataUS
PexelsStock imagery for marketing pages (no personal data processed)US

We will notify customers of any changes to our sub-processor list with at least 30 days advance notice. Section 6 of the Data Processing Agreement carries the same list with the data each one receives, and section 8 there sets out the safeguard relied on for each transfer outside the UK and the EEA.

Where you configure a webhook or an outbound integration yourself, the destination you choose is not a Porter sub-processor. We have no contract with it and did not select it, and that disclosure is yours to make.

8. Buildings with several resident businesses

Porter can run an office building where many independent businesses share one reception desk. In that arrangement the building operator sees the whole building, and each resident company sees only its own visitors, deliveries and people. How that is enforced matters more than the claim, so:

  • Isolation sits in the data layer. Every read made under a company's scope is filtered before it reaches the database, and every write is stamped with that company, by a single mechanism underneath the application rather than by a condition written out on each screen. A request for another company's record by its exact identifier is answered as not found.
  • Widening scope is deliberate and recorded. The operations that legitimately cross companies (the fire roll-call, retention, an operator's export) go through one named function that writes an audit event when it is used.
  • The building-wide roll-call is by design. The evacuation register lists everybody inside the building regardless of which company they came to see. That is a life-safety requirement and it is disclosed to visitors at the kiosk rather than buried here.
  • Each company can see who opened its records. A connected company has its own log of building-wide access to its data, which names the individual and states what it does not cover.
  • It is tested before every release. Every route is walked with one company's credentials against another company's identifiers, in each role a company can hold, and the responses are checked for the second company's data. Isolation has not been independently penetration tested. See section 10.

The operator and each resident company are ordinarily joint controllers of the check-in, because one sign-in at one kiosk reaches both. Porter is the operator's processor under the DPA. A resident company's relationship is with the operator rather than with Porter, so Porter does not enter a separate agreement with each resident company.

9. Incident Response

In the event of a security incident or data breach:

  • Affected customers will be notified within 72 hours of discovery, as required by GDPR Article 33
  • A detailed incident report will be provided including scope, root cause, and remediation steps
  • Our team will work directly with affected organisations to minimise impact
  • Post-incident reviews are conducted and findings are applied to prevent recurrence

10. Compliance & Certifications

Porter holds no security certification today. That is stated plainly rather than implied, because a procurement questionnaire will ask and an ambiguous answer wastes everybody's time.

  • UK GDPR: the product is built for it, and the Data Processing Agreement is available on request and at /dpa. Compliance with the UK GDPR is a legal obligation rather than a certification, and no certificate exists to hold.
  • Cyber Essentials: on our roadmap. Not held, and no assessment has been undertaken.
  • SOC 2: on our roadmap. Not held, and no audit has been undertaken.
  • ISO 27001: on our roadmap. Not held, and no audit has been undertaken.
  • Independent penetration test: scoped and costed, not yet commissioned. When one is carried out, the date and the scope will be stated here.

11. Security Contact

If you have security concerns, need to report a vulnerability, or require additional documentation for your procurement process, contact us directly:

  • Email: security@portervisitors.com
  • Response time: We aim to acknowledge all security inquiries within 1 business day
  • Responsible disclosure: We welcome responsible disclosure of security vulnerabilities. Please email the address above with details and we will respond promptly.

This trust page is reviewed and updated regularly. For the most current information, contact security@portervisitors.com.