Security & Vulnerability Disclosure

Effective date: [Effective Date] · Last updated: [Last Updated Date]

Portanus ("the Service"), operated by Twin Raven Studios, Inc. ("we," "us"), handles sensitive operational, medical, and financial data on behalf of service-dog and assistance-animal organizations. This page summarizes how we protect that data and explains how security researchers can report potential vulnerabilities to us in good faith.

1. Encryption

Data in transit is protected with industry-standard TLS, and data at rest is encrypted using strong, industry-standard algorithms. For especially sensitive fields, we apply additional application-layer field encryption so that the data is protected independently of the underlying storage.

2. Access control and authentication

Access to the Service is governed by role-based access control, with least-privilege roles assigned to Users by each Customer. Multi-factor authentication is enforced for privileged and administrative accounts. Internal access to production systems is limited, logged, and reviewed.

3. Tenant isolation

The Service is multi-tenant with schema-per-tenant isolation. Each Customer organization's data lives in its own database schema, and requests are scoped to a single tenant so that one Customer cannot access another Customer's data.

4. Audit logging and monitoring

We maintain comprehensive audit logging across the Service to record significant actions, including authentication events, permission changes, and access to sensitive records. Logs support investigation, monitoring, and accountability.

5. Secure development lifecycle

We follow a secure software development lifecycle that includes peer code review, automated testing, and dependency vulnerability scanning. Security considerations are part of design and review, and we work to remediate identified issues on a risk-prioritized basis.

6. Vendor diligence and HIPAA

We perform diligence on the sub-processors and vendors that support the Service, and we enter into Business Associate Agreements (BAAs) with vendors where HIPAA applies. Our data-handling commitments are described further in our Privacy Policy and Data Protection Policy.

7. Compliance framing

The Service is designed and operated to meet the requirements of SOC 2, the HITRUST CSF, and HIPAA. Formal third-party attestation and certification are in progress; we do not represent that any such attestation or certification is complete except where we provide the corresponding report or certificate. We are happy to share the current status of our compliance program with Customers on request.

8. Vulnerability Disclosure Policy

We welcome good-faith security research and value the work of researchers who help us keep the Service safe. This policy describes how to report a vulnerability and what you can expect from us in return.

9. Scope

This policy applies to the Portanus application and its public-facing production endpoints operated by us. The following are out of scope: findings that require physical access to a User's device, social engineering of our staff or Customers, denial-of-service or volumetric testing, automated scanning that degrades the Service, and vulnerabilities in third-party services we do not control. When in doubt, ask us before testing.

10. How to report

Please send reports to [security contact email]. We also publish a /.well-known/security.txt file with our current contact and disclosure details. Include enough information for us to reproduce and validate the issue, such as the affected endpoint, a description of the vulnerability, and step-by-step reproduction notes. Please do not include real Customer data in your report.

11. Safe harbor

We will not pursue or support legal action against researchers who report vulnerabilities in good faith and in compliance with this policy. We consider activity conducted consistent with this policy to be authorized, and we will work with you to understand and resolve the issue quickly. This safe harbor does not apply to activity that violates this policy or applicable law.

12. What we ask of researchers

  • Do not access, modify, or destroy data that does not belong to you, and avoid privacy violations.
  • Do not degrade, disrupt, or deny service to our systems or our Customers.
  • Stop testing and notify us immediately if you encounter Customer or personal data.
  • Give us a reasonable time to investigate and remediate before any public disclosure.
  • Act in good faith and comply with all applicable laws.

13. Our commitment

  • We will acknowledge receipt of your report within a target window of [acknowledgement window].
  • We will validate the report and keep you reasonably updated on our progress.
  • We will work to remediate confirmed vulnerabilities on a risk-prioritized basis.
  • We are glad to credit researchers who wish to be recognized, where appropriate.

14. Reporting a security concern

Found something, or have a security question about the Service? Contact us at security@twinravenstudios.com or consult our published /.well-known/security.txt. We take every report seriously and appreciate your help.


This document is a draft provided for transparency and is not legal advice. It should be reviewed and tailored by qualified counsel and security leadership, and aligned with your master agreement, before use.