What a government buyer should know before trusting us with portfolio data
PortfolioDesk holds project, budget, and schedule data for public agencies. That is a responsibility we take at face value. This page describes, in plain language, how the system is designed to protect that data, exactly where AI sits and where it does not, and what happens to your data when the engagement ends.
Security overview
PortfolioDesk is designed around the controls an agency IT-security review looks for first:
- Encryption in transit and at rest. Data moving between your users and the service is encrypted in transit, and stored data is encrypted at rest.
- Role-based access. Access is designed on least-privilege roles, so intake staff, project managers, approvers, and executives each see only what their role requires. Single sign-on is supported where configured for your agency.
- Audit logging. Intake decisions, score changes, status updates, approvals, and report exports are logged, so a portfolio decision can be traced back to who made it and on what evidence.
- Data minimization. The system is designed to hold the portfolio data needed to do its job, project records, budgets, schedules, risks, and status, and not more. We do not ask for data the product does not use.
We describe these controls as they are designed and operated. We do not claim third-party certifications we do not hold; our vendor security assessment, available on request, states plainly what is in place today.
Where AI sits, and where it does not
AI in PortfolioDesk has a narrow, defined job: it ingests the status updates your teams already write, flags projects drifting toward risk, and drafts the executive and board reporting a person then reviews and approves.
The boundary around that job is hard:
- It never invents a number. Every figure in an AI-drafted summary traces to a source record in your workspace. If the data is not there, the draft says so instead of filling the gap.
- Portfolio decisions belong to leadership. The AI does not approve, escalate, prioritize, or publish anything on its own. A named person reviews and approves every output before it counts.
- Your data never trains models. Customer data is used solely to provide the service to you. It is not used to train shared or third-party AI models.
Data ownership and export
The agency owns its data. Full stop.
- You can export your complete portfolio data in standard formats, such as CSV, at any time, without asking permission and without an export fee.
- At contract end, we follow a defined disposal process: you receive a full export, and your data is then deleted from the service on a documented schedule.
- Nothing about the service is designed to lock you in. If you leave, you take everything with you.
How we handle personal information is covered in our Privacy Policy, and the data terms are in our Terms of Service.
Reliability
A portfolio system is only useful if the numbers on it are current. PortfolioDesk is designed so that staleness is visible, never silent:
- Every submitted update is acknowledged and tracked, so an update that did not land is known, not assumed.
- Import and integration pipelines are monitored with alerting.
- A failed sync is a ticket, never a silently stale dashboard. If a data feed breaks, the system flags it rather than presenting old data as current.
Vendor packet
Procurement and InfoSec should never be a surprise late in the process. On request, we provide the packet your process needs:
- Vendor security assessment
- W-9
- Certificates of insurance
- References
Email hello@getportfoliodesk.com and we will send it, or raise it on a demo call and we will bring the paperwork to the conversation.
About the company
PortfolioDesk is offered by JS Technology Solutions, Inc., an Illinois-registered technology firm with hands-on experience operating inside large public-sector IT and finance environments. Questions about anything on this page go to hello@getportfoliodesk.com and get answered by the team responsible for the proposed pilot.
Bring your security questions to the demo
A short walkthrough of the proposed pilot and sample workflow, with trust and procurement questions answered in the same call.
Request a demo