Porticus

Industries / Technology

Assurance built around the way your security and privacy work actually connects.

Security and privacy programmes rarely live in one place. They sit across client questionnaires, workforce practices, vendor controls, and product or operational procedures.

Every enterprise request can become a new manual evidence exercise. Porticus learns the programme you already run, maps it to the requirements that apply, and keeps the evidence connected as buyers ask again.

Connected assurance work across security, privacy, buyer obligations, and workforce controls

The operational problem

The gap is between what the team does and what it has to show for it.

An access control, a security review, a vendor check, each is worked once and then re-explained differently to each buyer, each questionnaire, each audit.

Because the underlying procedures and records sit apart from the client-facing responses, a change in one area is hard to trace to the other controls it affects. The team answers requests rather than applying one connected assurance position.

What Porticus learns

Your assurance programme starts with the controls you already run.

Security and privacy policies
Access, vendor, and access-review procedures
Client and platform requirements
Evidence, audit responses, and workforce responsibilities
Product or service context

It is not a generic framework catalogue. It reads your current policies, procedures, controls, and evidence in the context of the way you operate and the commitments you have made.

Assurance answers grounded in your current QMS

What is the approved process for this access request?

Follow the Access Management Procedure steps for request, approval, and provisioning; review the owner and last review date.

Source: Access Management Procedure v5.0

Answers are grounded in your current QMS. Your team remains responsible for review and action.

Connected work

One assurance programme. Fewer repeated evidence exercises.

Access control across assurance

An access-control procedure and its review record may support security, privacy, buyer assurance, and workforce responsibilities. Porticus shows which area a change in that procedure touches so the team updates them together.

Vendor reviews

A vendor-review process may support security, privacy, procurement, and buyer due-diligence requirements. Porticus keeps that process and its records connected to every obligation that relies on them.

Relevant compliance areas in scope

Information securityPrivacyBuyer assurance and questionnairesWorkforce and access controlsInternal governance

Porticus supplements, and does not replace, security, privacy, legal, or technical assurance expertise.

Standards our AI has already processed for technology companies - and any others you bring.

Cybersecurity

  • ISO 27001 (Global)
  • SOC 2 (US/Global)
  • Cyber Essentials (UK)
  • National frameworks (Global)
  • NIST CSF (US)

Data Privacy

  • Privacy Act 2020 (NZ)
  • Australian Privacy Act 1988 (AU)
  • GDPR (EU)
  • National privacy laws (Global)
  • CCPA/CPRA (US)

Employment

  • Employment Relations Act 2000 (NZ)
  • Fair Work Act 2009 (AU)
  • Multi-country employment (NZ/AU/Global)
  • Pay transparency (Global)
  • AI hiring regulations (Global)
  • Leave policies (NZ/AU/Global)

Customer Requirements

  • Security questionnaires
  • DPAs
  • Custom audit requirements

Workplace Safety

  • Health and Safety at Work Act 2015 / WorkSafe NZ (NZ)
  • Work Health and Safety Act / Safe Work Australia (AU)
  • ISO 45001 (Global)
  • Ergonomics (Global)
  • Emergency action plans (Global)

Industry-Specific

  • Privacy Act 2020 (healthtech/edtech, NZ)
  • PCI DSS (fintech, Global)
  • ISO 27001 (govtech, Global)
  • HIPAA (healthtech, US)
  • National/sectoral frameworks (Global)

Your standard or certification scheme isn't listed? Our AI reads the source text of any standard, regulation, or certification scheme and builds a complete, connected programme. We add it before you go live.

For consultants

Keep the programme you build connected to the client’s day-to-day operation.

Use Porticus to produce reviewed gap reports, deliver changes faster, and support clients between formal engagements.

For Compliance Consultants

Keep your clients' compliance programmes working between visits.

Porticus reduces re-setup work, preserves the knowledge you create, and helps you serve more clients or focus on higher-value advice.

Choose a white-label, managed service, or referral partnership.

See how Porticus fits your assurance programme.