1 · Upload

A clinician uploads a file.
Security & Operations
One of our largest, most regulated customers called us "the most technological vendor we have" - after their security and IT teams testified that we're easy to work with. We treat that as an obligation. We started by protecting our own core capabilities; today Portium protects the institution's whole interaction with the internet, with nothing to install - only approved sites are reachable through our proxy, and every file users upload is governed by the policy you set.



On this page
Portium doesn't only let the right people in - it inspects everything that moves, in both directions. Every file a user uploads or downloads is gated before it passes: Data Loss Prevention (DLP) keeps sensitive information from leaving, while Content Disarm and Reconstruction (CDR) rebuilds incoming files clean, stripping hidden threats. It all runs as a managed secure web gateway, under your institution's policy.

The DLP flow, step by step - a file carrying sensitive data never leaves the organization without approval.
1 · Upload

A clinician uploads a file.
2 · Scan

"Please wait, we scan."
3 · Routed

"Some sensitive information was found. Your request and file were sent to the security department, and we'll update you once it's approved."
Uploaded and downloaded traffic is monitored in both directions; sensitive data is gated before it can leave the institution.
Incoming files are rebuilt clean - active content and hidden threats are stripped, so what reaches the user is safe, after filtering and scanning.
All web traffic runs through a managed gateway that filters destinations and blocks malicious sites and downloads.
Decide which websites and actions are permitted, and enforce it consistently across the organization.
A central panel to manage endpoint protection and policy for every user from one place.
Full role-based and rule-based (group-based) access control - each user and group gets exactly the permissions your policy defines.
Good to know
It's held before it ever leaves the institution. Portium routes the upload and the file to your security department for review, and the user is told their request was received and will be approved once it's cleared - nothing leaves the institution until then.
Every action - across the proxy, identity, authentication and admin layers - is written to the system log with its timestamp, severity, component, module, function, user and IP. When an alert comes in, filter the logs by the source IP and the whole trail is right there. No function is left without a log.

Good to know
Every action across the proxy, identity, authentication and admin layers - each entry carries a timestamp, severity, component, module, function, the user, and the source IP. No function runs without a log.
Trusted, audited, compliant
Trust is the threshold for our work. A hospital won't route its access through someone it doesn't trust one hundred percent. So for us, security isn't just another feature - it's the whole way we work: transparent, measured, and updated against every new threat. Everything we build we certify against the world's strictest standards, so you can understand exactly how we work - and stay in control.




ISO 27001 · HIPAA · SOC 2 Type II - audited by KPMG.
Customers can request access to our certifications and reports, and may obtain documents relating to our certifications under certain conditions.
We authorise audits carried out by a third party, for the purpose of certifying all relevant parties. During the security and procurement process we can coordinate the type of service required.
From the first vendor-assessment meeting to the way we build and run the product - security is the whole engagement, not a single feature.
We come to the table: live security-review meetings, every document and questionnaire your team needs, and vendor-assessment spreadsheets filled in with you - whatever procurement and security need to say yes.

Good to know
Yes. We come to the table with live security-review meetings and fill in your vendor-assessment questionnaires and spreadsheets with you, so procurement and security get everything they need to approve.
Identity and access is the kind of system that should never be improvised - and it's what Portium already runs for your institution every day. The full lifecycle of every identity is automated: people are onboarded, moved and offboarded straight from your authoritative systems, provisioned into your directories, and signed in through standards-based single sign-on and MFA - so access is never late and never lingers. Roles and attributes hold everyone at least-privilege, certification campaigns prove access stays appropriate, and every action is written to a revision-safe audit trail. It's ready for the regulators (ISO, SOC and local regulations in EU, US and Japan, encrypted end to end - and it's built to your principles: Portium answers to your institution, with no backdoors and your data kept where your policy and region require. And it's easy, because it's managed: we tailor the deployment, the connectors and the role model to your institution in the onboarding agreement, then run it for you. Everything an institution's identity and access platform must do, in one place:

Good to know
A complete Identity & Access Management (IAM) and Identity Governance & Administration (IGA) platform. Beyond connecting your users to research resources, it governs identity for the whole institution - lifecycle, provisioning, SSO and MFA, role- and attribute-based access, certification and audit - in one managed system.
Explore Portium for every team