Data Handling

How monthly-close files move through PortalLess.

This page explains the lifecycle from close request through upload, firm review, replacement, retention, and deletion planning.

Last updated August 19, 2026

01

Purpose

PortalLess is designed to collect client files for a specific firm request. The product should not collect more information than the firm needs for that request.

02

Data handled by PortalLess

  • Firm workspace records, including firm name and authorized users.
  • Client records created by the firm, including contact details needed for requests.
  • Close-cycle records, including closing period, due date, checklist state, assignment, expiration, and delivery metadata.
  • Uploaded document files and metadata, including storage path, original file name, detected content type, checksum, size, upload time, client, firm, and close cycle.
  • Review decisions and request events used to record receipt, acceptance, replacement requests, processing, readiness, and close completion.

03

Upload flow

  • A firm creates a monthly close with the files it needs from a client.
  • PortalLess creates a secure upload link for that request.
  • The client opens the link without creating an account and uploads files.
  • The file enters private quarantine, passes server-side file checks, and must receive a clean malware result before it reaches private final storage for firm review.
  • Receipt moves an item to bookkeeper review; it does not make the item accepted or the cycle close-ready.
  • A rejected item reopens the same upload slot with a client-visible replacement reason.

04

Retention model

  • PortalLess retains uploaded files only for the firm workflow and the configured post-close period.
  • Each firm records a default retention window of 30, 60, 90, 180, or 365 days in firm settings.
  • The retention clock starts when the request becomes closed, archived, or expired; active monthly closes do not expire merely because the file was uploaded earlier.
  • The automatic deletion path removes due storage objects, redacts sensitive file metadata, preserves a minimal audit tombstone, and records failures for operator action.
  • A firm owner or admin can also permanently remove files from a closed cycle through the same storage-removal and metadata-redaction boundary.
  • Provider backups and operational logs may persist after user-facing deletion according to separately reviewed provider lifecycles; PortalLess does not promise backup erasure before that evidence is complete.

05

Firm obligations

  • Firms remain responsible for professional obligations tied to client records and sensitive documents.
  • Firms should avoid requesting unnecessary sensitive information.
  • Firms should download, route, or archive files according to their own document management policy.
  • Firms should limit workspace access to staff who need it.

06

Launch checklist

  • Verify the production scanner provider and data-processing terms.
  • Verify the configured retention default and automatic deletion path for closed, archived, and expired requests.
  • Complete cross-firm negative-access, expired-link, rate-limit, duplicate-upload, and service-key boundary tests in the deployed environment.
  • Complete an incident-response rehearsal and approve the controlled-pilot data restrictions and provider terms.
  • Restrict controlled live use to explicitly allowlisted firms and an expiration date; disable uploads for firms outside both the sanitized-walkthrough and live-pilot allowlists.
  • Obtain independent application-security and legal/privacy approval and establish a separate backup operator before general availability—or sooner when a customer, document type, contract, or jurisdiction requires it.