Security and data requirements for a proposed agency pilot
PortfolioDesk currently provides an illustrative website preview with fictional sample data. Any production application, agency data access, security control, reporting workflow, or future AI functionality must be separately scoped, reviewed, implemented, and verified.
Security requirements to scope
An agency pilot should begin by identifying the actual security controls its reviewers require:
- Encryption requirements. Define and verify protection of any approved agency data before it is transferred or stored.
- Access requirements. Agree which agency users, permissions, authentication methods, and review roles a pilot would require.
- Review-record requirements. Identify project decisions, source records, approvals, and retention periods requiring documentation.
- Data minimization. Determine the minimum project, budget, schedule, and status information the agency approves for review.
No third-party security certification, completed security assessment, existing agency deployment, or implemented production control is held out as available. Your agency determines what evidence is required before any real data is processed.
Illustrative preview and possible future AI boundaries
The website preview contains fictional sample records and has no deployed AI, operational portfolio application, or agency-connected data source.
If an agency proposes future AI-assisted functionality, its scope must be separately reviewed and approved:
- Source review. Agency reviewers would need to verify any value against an approved source record.
- Human decisions. Project priorities, escalations, and reports remain decisions for authorized agency personnel.
- Data and model terms. Any provider, permitted data use, retention, and model-training restrictions require explicit agency approval.
Data ownership and retention terms to agree
An approved pilot should explicitly document the agency's requirements before real records are accepted:
- Ownership, permitted uses, approved project fields, and authorized reviewers.
- Any required export formats, retention periods, and agreed deletion process.
- The agency's security review, implementation validation, and purchasing approvals.
How we handle personal information is covered in our Privacy Policy, and the data terms are in our Terms of Service.
Implementation requirements to validate
Any operational workflow requires an agreed implementation and independent verification:
- The source records, data permissions, and proposed review cadence.
- Any separately scoped data mapping, reporting format, hosting, or monitoring.
- The agency staff responsible for reviewing outcomes and approving decisions.
Agency purchasing and security review
Your purchasing and security teams determine the requirements for an approved pilot:
- The proposed fixed-price scope and illustrative website preview.
- The agency's own purchasing process and required approval steps.
- Agency-defined data handling and security review requirements.
- Any proposed implementation work requiring independent verification.
To discuss the requirements your agency actually identifies, write to hello@getportfoliodesk.com.
About the company
PortfolioDesk is offered by JS Technology Solutions, Inc.. Questions about the illustrative preview or proposed pilot can be sent to hello@getportfoliodesk.com.
Bring your security questions to the demo
A short walkthrough of the proposed pilot and sample workflow, with trust and procurement questions answered in the same call.
Request a demo