Cookies for anonymous analytics (Microsoft Clarity). Privacy
Legal · Trust
SOC 2 readiness & controls · Last updated 8 July 2026
Download the PDF overviewImportant — please read
This page is a self-assessment prepared by PortLens describing our current security controls, presented against the AICPA SOC 2 Trust Services Criteria. It is not an independent SOC 2 examination and carries no auditor's opinion. PortLens has not yet completed a SOC 2 audit by a licensed CPA firm; a formal SOC 2 Type II examination is on our roadmap. Until then, this is an honest, transparent view of how we protect data today.
PortLens (ABN 59 498 934 467) is a portfolio-risk copilot for ASX-listed and global securities. It helps investors understand the risk exposures in a portfolio they enter — it does not execute trades, hold client money, or access brokerage accounts. Below we describe the controls that protect customer information, organised by the SOC 2 Trust Services Criteria.
This overview covers the PortLens web application, its API and supporting cloud infrastructure, against three criteria commonly requested of fintech vendors:
We process account data (email, name, bcrypt-hashed password), portfolio data (tickers, quantities, cost bases, option positions) and consent-gated aggregated analytics. Billing identifiers are held by Stripe. You may request access, correction or deletion of your data. Full detail is in our Privacy Policy and Cookie Policy.
PortLens relies on these reputable providers, each bound by its own security commitments:
Planned enhancements, not yet in place, include: multi-factor authentication; rate limiting & brute-force protection; a documented policy suite; independent penetration testing and scheduled vulnerability scanning; backup-restoration & disaster-recovery testing; and engagement of a licensed CPA firm for an independent SOC 2 Type II examination.
We're happy to answer security questionnaires and share detail under a mutual NDA. For security matters or vendor due-diligence, email security@portlens.com.au. See also our ISO 27001 alignment.