Security and Compliance
A practical overview of how Porfal approaches workspace isolation, provider operations, customer responsibilities, and enterprise controls.
Last updated: June 30, 2026
Overview
Porfal is designed as an AI compute platform for dedicated GPU workspaces. This page summarizes the security, privacy, and operational controls we design around.
This page is an overview, not a certification report. Formal compliance commitments are provided only in signed enterprise agreements or published attestations.
Infrastructure model
- Dedicated GPU workspace model for customer workloads.
- Provider abstraction designed to support cloud GPU providers, private capacity, and custom enterprise providers.
- Workspace lifecycle controls for provisioning, running, stopping, expiration, and cleanup.
- Separation between customer dashboard, backoffice administration, API services, databases, queues, and provider adapters.
Security controls
- Role-based access patterns for customer and administrative surfaces.
- JWT-based authentication for application access.
- Event logging for workspace lifecycle changes and operational investigation.
- Provider credential handling designed to avoid exposing infrastructure secrets to customers.
- Network and workspace isolation controls appropriate to the selected provider and deployment model.
- Operational monitoring and health checks for workspace status and provider availability.
Customer responsibilities
Customers remain responsible for the security of code, datasets, models, credentials, SSH keys, exposed services, dependencies, and access policies inside their workspaces.
Data protection
- Porfal collects only the operational, account, billing, and workspace metadata needed to run the platform.
- Customer content remains customer-controlled and is processed to provide workspace functionality.
- Payment card details are handled by payment processors rather than stored directly by Porfal.
- Retention and deletion depend on workspace lifecycle, storage configuration, backups, legal obligations, and customer actions.
Enterprise options
- Private cloud or dedicated provider integrations.
- Reserved GPU capacity for predictable workloads.
- SSO and stronger organization controls where available by plan.
- API-driven provisioning for internal platforms.
- Dedicated support and security review channels.
- Custom data processing and security terms for enterprise customers.
Abuse prevention
Porfal may monitor operational signals, billing events, and platform telemetry to prevent abuse, protect infrastructure, investigate security incidents, and enforce acceptable use requirements.
Roadmap
As Porfal matures, we expect to expand formal controls around audit logging, provider credential encryption, observability, incident response, SSO, enterprise administration, and compliance documentation.
Questions
For legal, privacy, security, or enterprise compliance questions, contact the Porfal team.