Cookies for anonymous analytics (Microsoft Clarity). Privacy

Legal · Information security

ISO/IEC 27001 Alignment

ISMS readiness overview · Last updated 8 July 2026

Download the PDF overview

Important — please read

This page is a self-assessment prepared by PortLens describing how our practices align to ISO/IEC 27001:2022. PortLens is not ISO/IEC 27001 certified. A certificate can only be issued by an accredited certification body after a formal audit of an Information Security Management System (ISMS); no such certificate has been issued to PortLens. Certification is on our roadmap. Each Annex A theme below is marked In place, Partial or Planned.

1. Our information-security approach (ISMS)

ISO 27001 is built around a management system rather than a fixed feature list. PortLens (ABN 59 498 934 467) operates a lightweight ISMS appropriate to a sole-trader business, following Plan-Do-Check-Act: we identify the information assets we hold, assess risks, apply proportionate controls, and review and improve them as the product and threat landscape evolve. Formal ISMS artefacts (policy suite, risk register, Statement of Applicability, internal-audit and management-review records) are in development ahead of a future audit.

2. Scope

The intended scope is the development and operation of the PortLens cloud-based web application, its API and supporting cloud infrastructure, operated by a single owner-operator in Australia. Physical data-centre security is inherited from our cloud sub-processors.

3. Risk management

We identify principal information assets — customer account data, user-entered portfolio data, authentication secrets and source code — and the threats to them (data breach, credential theft, cloud outage, ransomware, operator-device loss). Each is treated with proportionate controls. A formally documented, version-controlled risk register is being established.

4. Annex A — organizational controls

  • Policies for information security. Core practices applied; a signed policy suite is being written.Partial
  • Roles & responsibilities. Security ownership rests with the owner-operator.In place
  • Supplier management. Reputable providers used & listed publicly; formal vendor-risk process being documented.Partial
  • Asset management. Key assets identified; maintained register planned.Partial
  • Access control policy. Least-privilege enforced technically; written policy + periodic reviews planned.Partial
  • Incident management. Documented incident-response plan with severities/timelines planned.Planned

5. Annex A — people controls

  • Security awareness. Owner-operator maintains current security knowledge.In place
  • Screening / joiner-leaver. N/A for a single operator; formalised upon hiring.N/A
  • Confidentiality / acceptable use. Obligations honoured; written agreements introduced with any contractor.Partial

6. Annex A — physical controls

  • Data-centre security. Inherited from certified cloud sub-processors.In place
  • Endpoint / office security. No corporate office; operator device patched & protected; formal policy planned.Partial

7. Annex A — technological controls

  • Encryption in transit. HTTPS/TLS via a hardened edge (Cloudflare).In place
  • Authentication. Signed JWTs with automatic session expiry.In place
  • Credential protection. bcrypt-hashed, salted passwords.In place
  • Secrets management. Keys held only in server-side environment config.In place
  • Secure development. Inputs validated; changes reviewed before release.In place
  • Logging & monitoring. Events logged; internal metrics dashboard.Partial
  • Backup. Managed DB redundancy; documented restoration testing planned.Partial
  • Multi-factor authentication. Not yet available; planned.Planned
  • Vulnerability management. Independent pen testing & scheduled scanning planned.Planned
  • Payment data isolation. Card data handled entirely by Stripe (PCI-DSS L1).In place

8. Roadmap to certification

Complete the documented ISMS (policy suite, risk & asset registers, Statement of Applicability); introduce MFA, rate limiting and access reviews; establish incident-response, business-continuity and disaster-recovery plans with tested evidence; commission penetration testing and continuous scanning; run an internal audit and management review; then engage an accredited certification body for a Stage 1 / Stage 2 ISO/IEC 27001:2022 audit.

9. Requesting more information

For security questionnaires or due-diligence (under mutual NDA), email security@portlens.com.au. See also our Security & SOC 2 overview.