Two things keep a portal safe: strong platform defaults you don't have to configure, and clear controls for the decisions only you can make — who gets in, and what they see.
Encryption in transit and at rest
All traffic runs over TLS 1.2 or higher with HTTPS enforced, including on custom domains. Stored data and uploaded files are encrypted at rest.
- Certificates are issued and renewed without any action from you
- Payment card data is handled by the payment provider, never stored by LynxRise
- Backups are encrypted with the same standard as live data
Access control
Access is never implicit. A client contact can only reach the portal they were invited to, and only the items marked client-visible inside it.
Sessions and sign-in
Clients sign in with a secure link or a password they set on first use. You control how long sessions last and can end any session immediately.
Single-use, expiring links sent to a verified email address.
Available for team accounts and can be required workspace-wide.
Configurable; shorter sessions for portals handling financial data.
Revoking a contact or removing a teammate ends open sessions on the spot.
Audit log
Sensitive actions are recorded with the actor, timestamp, and IP. Use it to answer "who changed this" without guesswork.
- Filter by actor, client, or action type
- Export a date range for a client security review
- Retention depends on plan; export before it rolls off
Backups, residency, and deletion
Data is backed up continuously with point-in-time recovery. You stay the owner of your content and can export or delete it on request.
- Choose your region when the workspace is created
- Sub-processors are listed in our public documentation
- Deleting a workspace removes files from backups on the stated schedule