PricingResourcesBlog
Sign InGet Started
Security

Security at Portifer,
stated plainly.

How Portifer protects customer and recipient data today: who operates the platform, how access and credentials are secured, what GDPR tooling exists, and which certifications and features we do not have yet.

Get startedTalk to us

On this page

  • Who runs Portifer
  • Where data is hosted
  • Data in transit and stored credentials
  • Accounts, sign-in and access control
  • GDPR tooling
  • How long data is kept
  • What we do not have yet
  • Security questionnaires and vulnerability reports
  • FAQ

Last updated 2026-10-04

  1. Home
  2. /Security

Who runs Portifer

Portifer is built and operated by Getia AS (org. no. 926 610 198), Møllergata 6, 0179 Oslo, Norway. Getia AS is the data processor for the personal data you upload, and signs a data processing agreement (DPA) with customers.

The platform runs on third-party infrastructure. Every provider that processes personal data on our behalf, what it does and where it processes data is listed on the subprocessors page.

  • Subprocessors
  • Data processing agreement
  • Privacy policy

Where data is hosted

  • Application and database: Railway, listed on the subprocessors page as processing in the United States.
  • Uploaded photos, videos and files: Cloudflare R2 object storage, with the storage location chosen automatically by Cloudflare.
  • Email: GetMailer (EU). SMS: Twilio (US). AI analysis: OpenAI and Anthropic (US).
  • No hosting region is pinned in our application configuration, so regions follow each provider as listed on the subprocessors page. If you need EU-only hosting, ask us before you sign; we will tell you plainly whether we can offer it.
  • Subprocessors and locations

Data in transit and stored credentials

  • The site and app are served over HTTPS only, with HTTP Strict Transport Security (two-year max-age, preload).
  • Carrier API credentials (Bring, PostNord, DHL, UPS, FedEx) and HubSpot tokens are encrypted in the database with AES-256-GCM before they are stored.
  • API keys issued to customers are stored as hashes, not in readable form.
  • Outbound webhooks are signed with HMAC-SHA256 using a per-subscription secret, and webhook URLs that point at internal network addresses are rejected.
  • Browser responses carry a nonce-based Content Security Policy, X-Frame-Options DENY and X-Content-Type-Options nosniff.

Accounts, sign-in and access control

  • Passwords are hashed with bcrypt and must be at least 12 characters.
  • Two-factor authentication (TOTP authenticator app, with backup codes) is available to every user. When it is on, passwordless email sign-in is refused for that account.
  • Repeated failed logins are rate limited and can lock the account temporarily.
  • Sessions expire after 30 days by default and can be revoked centrally.
  • Each customer is a separate organisation. Brand admins, testers, fulfilment partners and sales reps each get their own portal and only see what their role allows.
  • When Portifer staff open a customer account to help with support, the session is logged.

GDPR tooling

  • Users can export their data and delete their account from their settings.
  • Recipients reach a branded page per shipment; you decide which fields a campaign collects.
  • We sign a DPA with every customer that asks, and commit in it to notify you of a personal data breach within 72 hours of becoming aware of it.

How long data is kept

  • Customer data is kept while your account is active.
  • Deleting an account from settings deletes the user's records from the database straight away. If that user is the only admin of the organisation, the organisation's data is deleted with it; if other users remain, deletion is refused until access is handed over.
  • Accounts whose email bounces and that never sign in are flagged after 7 days, deactivated 14 days later and deleted 30 days after flagging, about 37 days after signup.
  • Inactive mobile app sessions are removed after 30 days.
  • Database backups are kept on a rotation of 7 daily, 8 weekly and 12 monthly copies, so deleted records can remain in backups for up to about 12 months before they age out.
  • When a contract ends, we delete or return customer data as set out in the DPA.
  • Privacy policy
  • Data processing agreement

What we do not have yet

We would rather you hear this from us than find it in a questionnaire. As of the date on this page:

  • No SOC 2 or ISO 27001 certification.
  • No single sign-on via SAML or OpenID Connect.
  • No IP allow-listing for customer accounts.
  • No customer-facing audit log; audit and login history are available to Portifer staff only.
  • One admin role per brand team; there are no finer-grained viewer or editor roles yet.
  • No standard uptime SLA. Where service levels are offered, they are written into a Fully Managed agreement.

Security questionnaires and vulnerability reports

Send security questionnaires, DPA requests and vendor-assessment forms to [email protected]. We answer every question as it stands today, including the ones where the answer is no.

Found a vulnerability? Email [email protected] with steps to reproduce. Our security.txt is published at /.well-known/security.txt. Please give us reasonable time to fix an issue before you disclose it.

  • Contact us

Frequently asked questions

Is Portifer SOC 2 or ISO 27001 certified?

No. Portifer does not hold SOC 2 or ISO 27001 certification today. We answer security questionnaires directly at [email protected].

Does Portifer support single sign-on (SSO)?

Not yet. Portifer does not support SAML or OpenID Connect single sign-on today. Users sign in with email and password or a one-time email link, and can turn on two-factor authentication.

Where is my data stored?

Portifer is operated by Getia AS in Norway. The application and database run on Railway (listed as United States) and uploaded files on Cloudflare R2. No region is pinned in our configuration; each provider's location is on the subprocessors page.

Will you sign a DPA?

Yes. Getia AS signs a data processing agreement with customers. The standard terms are published on the DPA page.

How do I delete data?

Users can export their data and delete their account from their settings. Deleting the only admin account of an organisation deletes the organisation's data; contact us if you need a different arrangement.

Related pages

  • SubprocessorsEvery provider that processes personal data for us.
  • Data processing agreementOur standard DPA terms.
  • IntegrationsWhat connects to Portifer and how.
  • Help & API docsWebhooks, imports and setup guides.

Last updated 2026-10-04

See if Portifer fits your next campaign

Tell us what you want to send and to whom. We'll show you the platform and put the pricing in writing.

Talk to usSee pricing

Product seeding and testing platform for consumer brands.

Solutions

  • Product Seeding
  • Product Testing
  • ICP Outreach
  • Occasions
  • Gifting Platform
  • See all use cases

Product

  • Features
  • Pricing
  • Integrations
  • Security
  • Help & API docs

Compare

  • Compare
  • Alternatives
  • Switch to Portifer

Resources

  • Blog
  • Free Tools
  • Templates
  • ROI calculator
  • Sample size calculator
  • Glossary
  • Research Guide
  • Screening Checklist

Company

  • Contact Us
  • Feedback
  • Editorial policy
  • Privacy Policy
  • Terms of Service
  • DPA
  • Cookie Policy
  • Subprocessors

Get Consumer Insights

Subscribe for the latest product testing trends, research insights, and industry best practices.

No spam. Unsubscribe anytime.

© 2026 Portifer. All rights reserved.

Sign InGet Started