- Own hostname and sessions. The portal runs as a separate application, and portal and console sessions are fully independent.
- Least-privilege data access. The portal reads only customer-facing data: standing, published reports, case summaries and tickets. Organization scope applies on top to every query.
- Sign-in required for every page.
- Invite-only accounts locked to one organization, with a twelve-character minimum password and a mandatory authenticator app.
- Rate limiting per address and per account on sign-in.
- Short sessions in encrypted cookies with strict same-site protection.
- Audit of every sign-in, activation and ticket action.
- Published copies of reports are separate from working drafts, and the portal serves published copies only.
The portal is in scope for the vulnerability disclosure policy.