Security
Portfara holds a complete picture of your finances. The architecture is built around a single principle: hold as little power, and as few secrets, as the product can function with.
Read-only by design
Portfara reads balances and positions. It cannot place a trade, transfer a balance or initiate a withdrawal, and no code path exists that could.
When you connect an exchange, the API key is inspected before it is stored. A key carrying trading or withdrawal permission is rejected outright rather than accepted with a warning. A key is stored only when the exchange's own permissions response shows it cannot trade or withdraw. If that response cannot be read, the key is treated as unproven and refused.
- Five exchanges supported, each verified through its own permissions endpoint.
- Over-permissioned connections are flagged in the interface until replaced.
- Brokerage connections are read-only reporting feeds, not trading sessions.
Encrypted credentials
The keys and tokens you give Portfara to connect exchanges and your brokerage are encrypted at rest, with a key derived from a high-entropy secret held outside the database. Database access alone does not yield your connections. Your password is never stored, only an argon2 hash of it.
Accounts are isolated at the query layer rather than by convention. Scoping is applied centrally, so your holdings, statements and history are separated from every other account by construction.
European infrastructure
Portfara runs on Hetzner cloud infrastructure in Helsinki, inside the EU. The database is not reachable from the internet, and the attack surface is deliberately narrow: only the ports required to serve the application are open, enforced at the network edge rather than only on the host.
- HTTPS only, with automatically renewed certificates and strict transport security.
- A strict content security policy. The only third-party content the application loads is TradingView’s charts, on holding and currency pages, and only after you choose to load one.
- Fonts and application assets are served from our own infrastructure, not a CDN.
Backups we cannot read
Backups run automatically and are encrypted with public-key cryptography. The server holds only the public half of the key pair: it can produce an encrypted backup and is mathematically unable to open one. The private key is held offline and has never been on the machine.
Each backup is checked for integrity before encryption, in memory, so an unencrypted copy of the database is never written to disk.
No analytics, no advertising
There is no analytics product in Portfara. No page-view tracking, no session recording, no advertising pixels, and no third-party crash-reporting service. Your data is not sold.
A few parties do receive something because a feature needs them, and they are named here. Anthropic receives what the AI features you turn on send (see below). TradingView’s charts are embedded on holding and currency pages: when one loads, TradingView receives your IP address and the symbol shown, and may set its own cookies. The exchanges and brokerage you connect are queried with your read-only keys. Prices and news are fetched by our server from market-data and news sources using asset names and tickers, never anything that identifies you.
Security-relevant events such as sign-ins and failed attempts are recorded on our own infrastructure, where they stay.
AI on your terms
Four features send data about you to a language model: the assistant, the written daily brief, statement categorisation, and looking up an unfamiliar ticker you add to your news watchlist. All four are off until you turn them on in Settings, after a notice that states what each one sends. They use Claude, provided by Anthropic, and requests are processed in the United States.
- Leave AI features off and nothing about you or your portfolio is sent to a model. Statements are then categorised on our server by rules alone.
- Holding summaries are not about you. Each is written once per asset from public news, is the same for everyone who holds it, and names only the asset.
- Anthropic’s commercial terms do not allow training its models on data sent through its API.
- Usage is recorded per account, and turning AI features off stops the sending immediately.
Account security
Authentication is handled by Portfara directly rather than delegated to a third-party identity provider, so your account details do not sit in another company’s system. Passwords are stored using argon2.
Sessions are server-side records rather than self-contained tokens, which means signing out genuinely revokes the session on the server. The session cookie is inaccessible to JavaScript, and repeated failed sign-in attempts are rate limited.
Responsible disclosure
If you believe you have found a security issue, please report it to contact@portfara.com before disclosing it publicly. Reports are acknowledged and taken seriously.
Last reviewed 16 September 2026.