Security & data handling
Portals hold the data a business runs on — client records, contracts, payment history, internal process. This page sets out where that data lives, who can reach it, what we commit to in writing, and what we don't claim. If your security review needs something that isn't here, ask and we'll answer in writing.
Is a Softr and Airtable portal secure enough for client data?
For most professional-services, agency and operations use cases, yes. Airtable is SOC 2 Type 2 certified and encrypts data at rest and in transit; Softr provides authentication, SSO on higher plans, and granular role permissions. The security of any individual portal depends more on how permissions are modelled than on the platform, which is why row-level access is a standard part of every build we ship rather than an add-on.
Where your data lives and who can reach it
- Where your data actually lives
- Portal data sits in your Airtable base and, where a build needs file storage, in the storage bucket attached to it. Airtable holds SOC 2 Type 2 certification and encrypts data at rest and in transit. HIPAA support is an Airtable Enterprise feature — if you need it, you need that plan, and we'll say so during scoping rather than after.
- Who can sign in, and what they see
- Softr handles authentication. Every portal we build is role-based, and row-level permissions mean each account only ever loads the records assigned to it — that's a requirement on every build, not an upgrade. Softr also supports SSO and custom domains on its higher plans, so your users never authenticate against a third-party-branded screen.
- The automation layer
- Make, Zapier and any direct API integrations run under credentials held in your own accounts wherever the tool allows it. That means access travels with your subscription, not with us, and revoking it is something you can do without asking anyone.
- What we can't certify
- Portalcrafter is a three-person studio and does not hold SOC 2, ISO 27001 or HIPAA certification in its own name. What we can do is build on platforms that do, structure the data model to your compliance requirements from day one, and put our own handling commitments in the contract. Any agency of this size telling you otherwise is describing its vendors' certifications as its own.
What we commit to
- A mutual NDA, signed within 24 hours of you asking — before scoping, not after.
- You own the Airtable base, the Softr app and everything else we build, on completion. Ownership transfers to your accounts, not a licence from ours.
- We work in your accounts where the platform allows it, so there is no shadow copy of your data in ours.
- Access is scoped to the people actually building — never the whole team by default — and removed at handover unless you keep us on a retainer.
- Production data is not copied into test environments. Where a build needs realistic test data, we generate it.
- We don't sell, share or train on your data, and we don't use identifiable client data in marketing without written permission.
- A written Data Processing Agreement is available on request for engagements that need one.
Who you're contracting with
Portalcrafter operates from Flower Mound, Texas and has shipped 125+ portals since 2023. If your procurement or legal team needs the registered entity details, insurance position, or a signed DPA before contracting, ask us and we'll send them the same day.
Security questions we get asked
Can you build something HIPAA-compliant?
We can structure a build to meet HIPAA requirements, but the compliance itself comes from your Airtable plan — HIPAA support and a BAA are Airtable Enterprise features. We'll tell you during scoping whether your use case needs that plan. We do not claim HIPAA certification for Portalcrafter.
Will you sign an NDA?
Yes, and a mutual one. Ask at any point, including before the first call, and it's signed within 24 hours.
Do you offer a Data Processing Agreement?
Yes, on request. If your legal or procurement team needs a DPA in place before work starts, tell us at scoping and we'll have it ready before kickoff.
What happens to our data when the project ends?
It stays where it always was — in your accounts. On completion, ownership of the Airtable base and the Softr app transfers to you, and our access is removed unless you've kept us on a support retainer. Anything we held for the build (credentials, exports, working files) is deleted.
Who exactly will have access to our systems?
Named individuals from a three-person team, listed on our about page with public profiles. Access is granted to the people actually building your portal, not to the studio as a whole, and it comes off at handover.
Related
- How we structure permissions on a client portal build.
- Our privacy policy and terms.
- The three named builders who would have access.
Have a security review to get through?
Send us the questionnaire. We answer in writing, and we'll tell you plainly where the answer is "our vendors do, we don't".
.png&w=384&q=75)