Back to Port

Port Security

Last verified: July 11, 2026 How we verify →

Disclosure: We may earn a commission if you purchase through this link, at no extra cost to you. Learn more.

View Port Security Documentation

Review Port's compliance certifications, audit logs, access controls, and security architecture.

View Port Security Documentation

Enterprise-grade security.

Port Security Overview

Port provides built-in security features including SSO/SCIM, RBAC, audit logging, and encryption. As a SaaS platform, Port manages infrastructure security; customers configure access controls and compliance settings.

Identity and Access

SAML 2.0 and OIDC for SSO (Okta, Azure AD, Google Workspace, OneLogin, custom IdP). SCIM 2.0 for automated provisioning. JIT provisioning on first login. Attribute mapping for groups/roles. Session timeout and concurrent session limits.

Authorization

Built-in RBAC with Admin, Editor, Viewer roles. Team-based permissions for blueprints, entities, and actions. Custom roles via API. Resource-level permissions for self-service actions. API tokens with scopes for automation.

Data Protection

Encryption at rest (AES-256) and in transit (TLS 1.2+). AWS hosting with SOC 2, ISO 27001. Data residency options (US, EU). Automated backups with encryption. Customer-managed keys (Enterprise).

Audit and Compliance

Audit log captures all user and API actions (Enterprise). Export to SIEM (Splunk, Datadog, Elastic). SOC 2 Type II certified. GDPR/CCPA compliance with data subject request portal. DPA available.

Application Security

Regular penetration testing and bug bounty. SAST/DAST in CI/CD. Dependency scanning. WAF and DDoS protection. Secure SDLC with code review gates. No customer data in logs.

Compare Port with Alternatives

See how Port stacks up against competitors across features, pricing, and user reviews.

Trusted by thousands of DevOps teams. Read verified reviews before you buy.

Related Links