Security
How we protect your data
You’re trusting PortalShip with access to your HubSpot account. Here’s exactly what that means and how we handle it.
Your data stays isolated
Every request to your portal or admin dashboard is checked, on that request, against your own account — not just at login. One business can never see another business’s customers, tickets, or HubSpot data, by construction, not by convention.
Encrypted at rest
Your HubSpot connection (and any custom email server credentials you configure) are encrypted at rest with AES-256-GCM before they ever touch our database.
Encrypted in transit
Every connection to PortalShip, and every call we make to HubSpot on your behalf, happens over HTTPS.
We don’t duplicate your CRM
PortalShip doesn’t copy your HubSpot data into a second permanent database. Your portal reads live from HubSpot each time, cached only briefly to keep pages fast. Disconnect us and your HubSpot data is exactly as it was.
Passwords, hashed — magic links, short-lived
Admin passwords are hashed with scrypt, never stored in plain text. Customers sign in with a one-time magic link instead of a password — it expires in 5 minutes and can only be used once.
Webhooks are verified, not trusted
Inbound webhooks from HubSpot and Stripe are cryptographically signature-verified before we act on them — a request claiming to be from HubSpot has to prove it.
No trackers
We don’t run third-party analytics or advertising trackers on PortalShip. See our Privacy Policy for the full picture.
Found a security issue?
If you believe you’ve found a vulnerability in PortalShip, please email us at info@portalship.io with details. We take reports seriously and will respond as quickly as we can. Please give us a reasonable chance to fix an issue before disclosing it publicly.
Questions?
Read our Privacy Policy for what data we collect and why, or email info@portalship.io.
