Compliance & Security

Security controls, data protection, and responsible scanning for teams that need confidence before they connect assets

Built for security-conscious buyers

PortWarden runs on authorized scanning, limited data retention, and controlled access.

PortWarden helps customers monitor internet-facing exposure and run on-demand testing against assets they own or are explicitly authorized to test. The work touches sensitive findings, so the platform uses strict access controls, encrypted data handling, and a documented operating model.

Below is the current security and compliance posture for customers, MSPs, and procurement teams. Formal security docs and independent assessment materials are available under NDA for qualified customers.

Compliance posture at a glance

  • US-only infrastructure
  • Private network architecture with restricted administrative access
  • Customer scan data encrypted at rest and in transit
  • Customer scan artifacts retained for 30 days
  • Mandatory MFA and role-based least-privilege access
  • Opt-in scanning with mandatory client KYC
  • Independent security engineering oversight and documentation
Framework alignment

Controls aligned with common compliance expectations

PortWarden does not publicly claim SOC 2 attestation, ISO 27001 certification, PCI DSS certification, or HIPAA compliance unless those formal assessments are completed. We operate controls that align with common framework expectations and can support customer security reviews.

SOC 2 aligned

Controls cover security, confidentiality, access control, monitoring, and change visibility principles commonly reviewed in SOC 2 programs.

ISO 27001 aligned

The operating model maps to practical ISO 27001 areas such as access management, asset protection, supplier risk, incident handling, and information security governance.

NIST CSF aligned

Work follows identify, protect, detect, respond, and recover: restricted infrastructure, logging, monitoring, incident response, and customer communication.

CIS Controls aligned

Practices emphasize least privilege, controlled access, encrypted data handling, secure configuration, vulnerability visibility, audit logging, and accountable operations.

Platform security controls

Reduce exposure, limit access, and protect customer scan data

Posture starts with architecture: cloud-hosted, privately networked, access-restricted, with limited retention of security-sensitive artifacts.

Cloud infrastructure icon

US-only cloud infrastructure

Infrastructure is hosted in the United States with controls for physical security, network segmentation, and resilient hosting practices.

Encryption icon

Encrypted customer data

Customer scan data is encrypted in transit and at rest. Scan artifacts sit in encrypted object storage and are retained for 30 days unless a shorter period is required by agreement.

Private network architecture

Private network architecture

Core infrastructure is segmented from public access where appropriate. Admin access is limited to authorized personnel on controlled private paths, reducing unnecessary exposure of internal services.

Access control icon

Least-privilege access

Internal access is role-based and limited to the minimum needed. MFA is required for admin access. Access decisions track operational need.

Audit logging icon

Permanent access and audit logs

Access and audit logs are retained permanently for accountability, security review, incident investigation, and customer assurance when a qualified review needs evidence.

Security review

Independent security oversight

PortWarden maintains penetration testing and security documentation from a private security engineering firm that reviews platform posture.

Responsible scanning model

Authorization is not optional. Customers must verify who they are and what they control.

PortWarden is not an anonymous scanning platform. KYC is required before scanning is enabled, and scanning is opt-in only. Customers must own the targets they add or have explicit authorization to test them.

This model protects customers, reduces abuse risk, and helps procurement teams confirm the platform is for legitimate security operations, not unsupervised internet scanning.

Authorization controls

  • Mandatory client KYC before scanning access
  • Opt-in scanning for authorized assets only
  • Ownership and authorization expectations built into onboarding
  • Customer-controlled asset scope
  • No anonymous public scanning workflow
  • Security documentation available to qualified customers under NDA
Data handling

We collect only what we need for attack surface management and scan reporting.

PortWarden stores customer scan data and operational records needed for monitoring, reporting, retesting, auditability, and support. Customer scan data is not used to build unrelated products. Scanning stays customer-authorized and scope-bound.

Customer scan artifacts are retained for 30 days in encrypted storage. Access is role-based and limited to people with a legitimate operational need.

Data protection summary

  • Customer scan data encrypted at rest and in transit
  • 30-day retention for customer scan artifacts
  • Role-based internal access
  • Minimum necessary access model
  • US-only infrastructure footprint
  • Permanent access and audit log retention
  • No external subprocessors for core platform operations beyond infrastructure hosting
Incident response

Notification standards for confirmed material security incidents

Incident response focuses on rapid triage, containment, remediation, evidence preservation, and customer notification when a confirmed material incident affects customer data or service security.

1. Triage within 24 hours

Potential incidents are reviewed, classified, and escalated by impact, data sensitivity, and risk to customers or platform operations.

2. Containment and remediation

Confirmed issues are contained, investigated, remediated, and documented. Evidence is preserved in access logs, audit logs, and operational records.

3. Customer notification

For confirmed material incidents affecting customer data or service security, PortWarden aims to notify affected customers within 72 hours and update until closure.

Documentation available on request

Need security evidence for vendor review or procurement?

Qualified customers can request security documentation, independent assessment materials, architecture summaries, data handling details, and control explanations under NDA. Public claims stay conservative so the compliance language stays accurate.