Back to home

Security Policy

Last updated: July 16, 2026

1. Our Commitment

Security is core to portwarp ("the Service"). We build and operate our tunneling infrastructure with the goal of protecting your data, your connections, and the services you expose. This policy describes the measures we take and how you can responsibly report issues.

2. Data Protection

  • All traffic between the desktop client and our relay nodes is encrypted in transit using TLS.
  • We do not inspect, log, or store the content of traffic passing through your tunnels.
  • Account passwords are hashed with industry-standard algorithms and never stored in plaintext.
  • Connection metadata (timestamps, bandwidth) is retained only as needed to operate the Service.

3. Account Security

  • Two-factor authentication (2FA) is available to protect your account and is mandatory for admin access.
  • API tokens are scoped to your account and can be revoked at any time from your settings.
  • We recommend using a unique, strong password and enabling 2FA.

4. Infrastructure

Our relay nodes and application servers are kept up to date with security patches. Access to production systems is restricted and audited. We follow the principle of least privilege for internal access to infrastructure and data.

5. Reporting a Vulnerability

If you discover a security vulnerability in the Service, we encourage you to report it responsibly. Email [email protected] with:

  • A clear description of the issue and its potential impact.
  • Steps to reproduce, including any proof-of-concept where applicable.
  • The affected component, URL, or version.

We aim to acknowledge reports within a reasonable time and will work with you to understand and address the issue.

6. Responsible Disclosure

We ask that you give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly. Please do not:

  • Access, modify, or delete data that does not belong to you.
  • Degrade, disrupt, or overload the Service (for example, through denial-of-service testing).
  • Exploit a vulnerability beyond what is necessary to demonstrate it.

Good-faith research conducted in line with this policy will not be pursued as a violation of our Terms of Service.

7. Contact

Security questions or reports? Email [email protected]. For abuse or copyright matters, see our DMCA Policy.