LynxRiseGet lifetime access
11· Platform

Security and access

Client portals hold contracts, files, and payment records. Here's exactly how that data is protected — and the controls you own on your side.

6 min readUpdated 24 Jul 2026For agencies and their clients

Two things keep a portal safe: strong platform defaults you don't have to configure, and clear controls for the decisions only you can make — who gets in, and what they see.

01

Encryption in transit and at rest

All traffic runs over TLS 1.2 or higher with HTTPS enforced, including on custom domains. Stored data and uploaded files are encrypted at rest.

TransportEnforced
TLS1.3 preferred
HTTP requestsRedirected to HTTPS
Database at restAES-256
File storage at restAES-256
Certificate renewalAutomatic
  • Certificates are issued and renewed without any action from you
  • Payment card data is handled by the payment provider, never stored by LynxRise
  • Backups are encrypted with the same standard as live data
02

Access control

Access is never implicit. A client contact can only reach the portal they were invited to, and only the items marked client-visible inside it.

Access boundaries
Portal isolationPer client
Internal notesNever client-visible
Draft invoicesHidden until sent
Contractor scopeAssigned projects only
Two separate systemsTeam accounts and client portal accounts are distinct. A client contact can never gain access to your workspace, regardless of role.
03

Sessions and sign-in

Clients sign in with a secure link or a password they set on first use. You control how long sessions last and can end any session immediately.

Secure sign-in links

Single-use, expiring links sent to a verified email address.

Two-factor authentication

Available for team accounts and can be required workspace-wide.

Session length

Configurable; shorter sessions for portals handling financial data.

Immediate revocation

Revoking a contact or removing a teammate ends open sessions on the spot.

Require 2FA for adminsAdmins can change branding, domains, and invoices. Enforcing two-factor on admin accounts is the single highest-value control you can switch on.
04

Audit log

Sensitive actions are recorded with the actor, timestamp, and IP. Use it to answer "who changed this" without guesswork.

Audit logLast 24 hours
Invoice #0142 sentyou · 09:14
Contact revoked · Jo Langadmin · 10:02
Share link createdalex · 11:37
Domain verifiedsystem · 12:05
Failed sign-in ×3unknown · 12:41
  • Filter by actor, client, or action type
  • Export a date range for a client security review
  • Retention depends on plan; export before it rolls off
05

Backups, residency, and deletion

Data is backed up continuously with point-in-time recovery. You stay the owner of your content and can export or delete it on request.

Data handling
BackupsContinuous · PITR
ResidencyEU or US region
ExportSelf-serve
Deletion requestCompleted within 30 days
  • Choose your region when the workspace is created
  • Sub-processors are listed in our public documentation
  • Deleting a workspace removes files from backups on the stated schedule
Client security questionnaire?Ask us for the current security overview — most procurement checklists are covered by it.

Ready to launch your client portal?

Spin up a branded workspace, invite your first client, and keep every project, file, and invoice in one place.

Create workspace ↗