Portupine

For security and risk leaders

Make software assurance an internal capability.

Self-hosted. Self-defended.

Portupine is delivered as source code and deployed inside infrastructure you govern. Security teams can evaluate the application, enforce existing controls, and keep operational data out of a required vendor data path.

Your infrastructure, your rules.

Portupine is deployed on-premise. Your network, your storage, your backups, your access policies. Nothing is sent to us — there is no "us" in your data path.

Full source access.

Every customer receives the complete source code. Audit it line by line, run your own SAST/DAST tooling against it, and verify exactly what the platform does before it touches production.

Granular access control.

Role-based permissions with a default-deny gateway, plus field-level control — decide per role who can even see sensitive fields like salary, enforced centrally so no single module can leak around it.

Strong authentication.

TOTP two-factor authentication with recovery codes, brute-force throttling, active session management with per-device revocation.

A security audit trail.

Authentication events and permission changes are logged in a dedicated, filterable audit log — evidence your auditors can actually use.

AI that stays home.

Connect the AI provider you approve — including fully local models via Ollama. AI features with zero bytes leaving your network. More on private AI →

Compliance-ready architecture.

Audit logging, RBAC, encrypted secrets, and tenant isolation are built in — the controls your ISO 27001 / SOC 2 audits expect, running where your existing certifications already apply.

In the product

Role and permission matrix

Administrators configure role permissions with a field-level access legend.

app.portupine.com/admin/roles

In the product

Filtered security audit log

A searchable audit trail records security-relevant actions with filtering for investigation.

app.portupine.com/admin/audit

Scope the platform around your organization.

Discuss the systems you want to consolidate, deployment boundaries, rollout priorities, and support requirements.