🔑

Account Management

We provide full control over your account lifecycle. You can create, modify, suspend, or permanently delete your account at any time via the client portal.

Account Creation & Verification

  • Email verification is required within 24 hours of registration.
  • Business accounts require additional KYC verification for enterprise billing.
  • Role-based access control (RBAC) is available for team accounts.

Account Modification

  • Update personal details, billing information, and notification preferences.
  • Change email address requires re-verification of the new address.
  • Team member invitations expire after 48 hours if not accepted.
🛡️

Authentication & Two-Factor Authentication

Security starts with strong authentication. We enforce industry-standard practices to protect your credentials and session data.

✓ AES-256 Encryption ✓ TOTP Support ✓ Hardware Key (WebAuthn) ⚡ Adaptive Session Timeout

Password Requirements

  • Minimum 12 characters
  • Must include uppercase, lowercase, number, and special character
  • Cannot match previous 5 passwords
  • Checked against known breach databases in real-time

Two-Factor Authentication (2FA)

2FA is strongly recommended and required for all admin roles. Supported methods include authenticator apps (Time-based OTP), SMS fallback (deprecated but available), and FIDO2 security keys.

🔒

Data Privacy & Compliance

We are committed to protecting your data in accordance with global privacy regulations. All data is processed transparently and securely.

Regulatory Compliance

  • GDPR: Right to access, rectification, erasure, and data portability.
  • CCPA/CPRA: Opt-out of data sale, clear disclosure notices.
  • SOC 2 Type II: Annual audits, continuous monitoring.

Data Handling & Retention

  • All data at rest is encrypted using AES-256.
  • Data in transit uses TLS 1.3 exclusively.
  • Logs are retained for 90 days; user data is deleted permanently within 30 days of account closure.
  • Backups are geo-redundant and encrypted with customer-managed keys (CMK) for enterprise plans.
⚠️

Security Best Practices

To maximize account safety, we recommend the following practices:

  • Enable 2FA immediately after account creation.
  • Use a password manager to generate unique, complex passwords.
  • Review active sessions regularly and terminate unrecognized devices.
  • Keep recovery emails and phone numbers up to date.
  • Be vigilant against phishing emails pretending to be from Professional Portfolio.

🚨 Suspected Compromise?

If you believe your account has been compromised, act immediately:

  1. Change your password from a trusted device.
  2. Revoke all active sessions via Security Settings.
  3. Enable 2FA if not already active.
  4. Contact our security team immediately using the details below.

Frequently Asked Questions

Click "Forgot Password" on the login page. Enter your registered email, and we'll send a secure, time-limited reset link. The link expires in 15 minutes for security. If you don't receive it, check your spam folder or contact support.
Yes. Admins and billing managers can assign roles (Admin, Editor, Viewer, Billing) to team members via the Team Dashboard. Changes take effect instantly. Audit logs track all permission modifications.
Upon deletion, all personal data is permanently purged from active systems within 24 hours. Backup copies are anonymized and excluded from restoration pools. Financial records are retained for 7 years as required by law, but stripped of personally identifiable information (PII).
We only share data with vetted service providers necessary to operate our platform (hosting, payment processing, analytics). All partners are bound by strict data processing agreements (DPA). We never sell or rent your personal data.
📞

Contact Security Team

For urgent security incidents, vulnerability reports, or account recovery assistance, our dedicated security team is available 24/7.

📧 Security & Support Email

Response time: < 2 hours for critical incidents | < 24 hours for general inquiries